You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform创建Azure允许位置策略报错:listOfAllowedLocations参数缺失值

解决Azure订阅级Terraform策略分配的400错误(PolicyParametersMissingValue)

问题场景

作为Terraform初学者,创建Azure订阅级策略分配时触发400错误,提示PolicyParametersMissingValue: The policy parameters 'listOfAllowedLocations' are missing a value。相关代码及报错信息如下:

原Terraform代码

provider "azurerm" {
  features {}
}

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = ">= 2.96.0"
    }
  }
}

resource "azurerm_subscription_policy_assignment" "Allowedlocations2" {
  name                 = "Allowed locations"
  subscription_id      = var.cust_scope
  policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e56962a6-4747-49cd-b67b-bf8b01975c4c"
  description          = "This policy enables you to restrict the locations your organization can specify when deploying resources."
  display_name         = "Allowed locations"
  metadata = <<METADATA
  {
    "category": "General"
  }
METADATA

  parameters = <<PARAMETERS
  {
      "listOfAllowedLocations": {
        "type": "Array",
        "metadata": {
          "description": "The list of locations that can be specified when deploying resources.",
          "strongType": "location",
          "displayName": "Allowed locations",
          "strongType": "location"
        },
        "defaultValue": [
          "eastus"
        ],
        "allowedValues": [
          "eastus",
          "eastus2"
        ]
      }
    }
PARAMETERS
}

完整报错信息

azurerm_subscription_policy_assignment.Allowedlocations2: Creating...
╷
│ Error: creating Scoped Policy Assignment (Scope: "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
│ Policy Assignment Name: "Allowed locations"): unexpected status 400 with error: **PolicyParametersMissingValue: The policy parameters 'listOfAllowedLocations' are missing a value.**
│
│   with azurerm_subscription_policy_assignment.Allowedlocations2,
│   on main.tf line 65, in resource "azurerm_subscription_policy_assignment" "Allowedlocations2":
│   65:   resource "azurerm_subscription_policy_assignment" "Allowedlocations2" {
│
│ creating Scoped Policy Assignment (Scope: "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
│ Policy Assignment Name: "Allowed locations"): unexpected status 400 with error: PolicyParametersMissingValue: The policy parameters 'listOfAllowedLocations' are missing a value.
╵

错误原因

原代码中parameters块写法错误:误将策略参数定义结构(包含type、metadata、allowedValues等)当成了策略分配的参数赋值结构。Azure策略分配时,只需传递参数的实际取值——参数的定义信息已经存在于引用的内置策略(policy_definition_id指向的资源)中,无需重复声明。

修正后的代码

将parameters部分修改为仅传递参数值的格式:

provider "azurerm" {
  features {}
}

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = ">= 2.96.0"
    }
  }
}

resource "azurerm_subscription_policy_assignment" "Allowedlocations2" {
  name                 = "Allowed locations"
  subscription_id      = var.cust_scope
  policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e56962a6-4747-49cd-b67b-bf8b01975c4c"
  description          = "This policy enables you to restrict the locations your organization can specify when deploying resources."
  display_name         = "Allowed locations"
  metadata = <<METADATA
  {
    "category": "General"
  }
METADATA

  parameters = <<PARAMETERS
  {
    "listOfAllowedLocations": {
      "value": ["eastus"]
    }
  }
PARAMETERS
}

若需指定多个允许位置,扩展数组即可:

parameters = <<PARAMETERS
{
  "listOfAllowedLocations": {
    "value": ["eastus", "eastus2"]
  }
}
PARAMETERS

验证说明

修正后执行terraform apply,策略分配将成功创建,Azure会使用指定的listOfAllowedLocations值约束资源部署位置。

内容的提问来源于stack exchange,提问作者uiiueree

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 04:16:04