You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署Azure堡垒机模块报错:子网ID格式无效

Terraform部署Azure Bastion Host时的无效URI错误排查与解决

问题背景

正在基于Terraform构建Azure Landing Zone,已实现Resource_Groups、Storage_Accounts、Virtual_Networks三个模块。新增Bastion_Host模块后执行terraform plan,触发以下错误:

Planning failed. Terraform encountered an error while generating this plan.

╷
│ Error: parsing "AzureBastionSubnet": parsing Azure ID: parse "AzureBastionSubnet": invalid URI for request
│
│ with module.Azure_Module_BH.azurerm_bastion_host.bastion,
│ on modules\Bastion_Host\main.tf line 19, in resource "azurerm_bastion_host" "bastion":
│ 19: subnet_id = var.subnet_id

经排查,错误源于Bastion_Host模块的subnet_id变量默认值设为子网名称AzureBastionSubnet,而非Azure要求的完整子网资源ID。

故障原因

  1. 参数类型不匹配:azurerm_bastion_host资源的subnet_id参数必须接收完整的Azure子网资源ID(格式类似/subscriptions/{subscription-id}/resourceGroups/{rg-name}/providers/Microsoft.Network/virtualNetworks/{vnet-name}/subnets/{subnet-name}),但当前传入的是子网名称,不符合URI格式要求。
  2. 变量定义错误:subnet_id变量的描述字段错误标注为"the name of the vnet",容易造成混淆。
  3. 模块间依赖传递缺失:根模块未从Virtual_Networks模块获取正确的子网ID,而是使用了模块内的错误默认值。

解决方案

1. 修正Bastion_Host模块的变量定义

更新variables.tf,修正描述并移除错误的默认值:

variable "resourcegroup_name" {
  type        = string
  description = "The name of the resource group"
  default     = "Networking-CC-RG"
}

variable "location" {
  type        = string
  description = "The region for the deployment"
  default     = "canadacentral"
}

variable "tags" {
  type        = map(string)
  description = "Tags used for the deployment"
  default = {
    "Environment"   = "Development"
    "Owner"         = "OwnerEmail"
    "CreatedBy"     = "JNuaman@outlook.com"
  }
}

variable "vnet_name" {
  type        = string
  description = "The name of the virtual network"
  default     = "VNET-Hub-CC-Prod-01"
}

variable "subnet_id" {
  type        = string
  description = "The full resource ID of the AzureBastionSubnet"
  # 移除错误的默认值,强制从根模块传入正确ID
}

variable "bastionhost_name" {
  type        = string
  description = "The name of the bastion host"
  default     = "VNET-Hub-CC-Prod-01-BH-01"
}

2. 在Virtual_Networks模块中输出子网ID

在Virtual_Networks模块的outputs.tf中添加AzureBastionSubnet的资源ID输出(假设子网在该模块中定义为azurerm_subnet.bastion):

output "bastion_subnet_id" {
  type        = string
  description = "Resource ID of the AzureBastionSubnet"
  value       = azurerm_subnet.bastion.id
}

3. 根模块传递正确的子网ID到Bastion_Host模块

修改根模块代码,将Virtual_Networks模块输出的子网ID传递给Bastion_Host模块:

module "Azure_Module_RG" {
  source = "./Modules/Resource_Groups"
}

module "Azure_Module_SA" {
  source = "./Modules/Storage_Accounts"
  depends_on = [ module.Azure_Module_RG ]
}

module "Azure_Module_VNET" {
  source = "./Modules/Virtual_Networks"
}

module "Azure_Module_BH" {
  source = "./modules/Bastion_Host"
  subnet_id = module.Azure_Module_VNET.bastion_subnet_id
  # 若需要覆盖其他默认变量,也可在此传递,比如resourcegroup_name等
  depends_on = [ module.Azure_Module_VNET ]
}

验证执行

完成上述修改后,重新执行:

terraform init
terraform plan

此时subnet_id将传入正确的子网资源ID,错误即可解决。


内容的提问来源于stack exchange,提问作者P for Tech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 23:17:06