Terraform创建Azure允许位置策略报错:listOfAllowedLocations参数缺失值
解决Azure订阅级Terraform策略分配的400错误(PolicyParametersMissingValue)
问题场景
作为Terraform初学者,创建Azure订阅级策略分配时触发400错误,提示PolicyParametersMissingValue: The policy parameters 'listOfAllowedLocations' are missing a value。相关代码及报错信息如下:
原Terraform代码
provider "azurerm" { features {} } terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = ">= 2.96.0" } } } resource "azurerm_subscription_policy_assignment" "Allowedlocations2" { name = "Allowed locations" subscription_id = var.cust_scope policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e56962a6-4747-49cd-b67b-bf8b01975c4c" description = "This policy enables you to restrict the locations your organization can specify when deploying resources." display_name = "Allowed locations" metadata = <<METADATA { "category": "General" } METADATA parameters = <<PARAMETERS { "listOfAllowedLocations": { "type": "Array", "metadata": { "description": "The list of locations that can be specified when deploying resources.", "strongType": "location", "displayName": "Allowed locations", "strongType": "location" }, "defaultValue": [ "eastus" ], "allowedValues": [ "eastus", "eastus2" ] } } PARAMETERS }
完整报错信息
azurerm_subscription_policy_assignment.Allowedlocations2: Creating... ╷ │ Error: creating Scoped Policy Assignment (Scope: "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" │ Policy Assignment Name: "Allowed locations"): unexpected status 400 with error: **PolicyParametersMissingValue: The policy parameters 'listOfAllowedLocations' are missing a value.** │ │ with azurerm_subscription_policy_assignment.Allowedlocations2, │ on main.tf line 65, in resource "azurerm_subscription_policy_assignment" "Allowedlocations2": │ 65: resource "azurerm_subscription_policy_assignment" "Allowedlocations2" { │ │ creating Scoped Policy Assignment (Scope: "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" │ Policy Assignment Name: "Allowed locations"): unexpected status 400 with error: PolicyParametersMissingValue: The policy parameters 'listOfAllowedLocations' are missing a value. ╵
错误原因
原代码中parameters块写法错误:误将策略参数定义结构(包含type、metadata、allowedValues等)当成了策略分配的参数赋值结构。Azure策略分配时,只需传递参数的实际取值——参数的定义信息已经存在于引用的内置策略(policy_definition_id指向的资源)中,无需重复声明。
修正后的代码
将parameters部分修改为仅传递参数值的格式:
provider "azurerm" { features {} } terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = ">= 2.96.0" } } } resource "azurerm_subscription_policy_assignment" "Allowedlocations2" { name = "Allowed locations" subscription_id = var.cust_scope policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e56962a6-4747-49cd-b67b-bf8b01975c4c" description = "This policy enables you to restrict the locations your organization can specify when deploying resources." display_name = "Allowed locations" metadata = <<METADATA { "category": "General" } METADATA parameters = <<PARAMETERS { "listOfAllowedLocations": { "value": ["eastus"] } } PARAMETERS }
若需指定多个允许位置,扩展数组即可:
parameters = <<PARAMETERS { "listOfAllowedLocations": { "value": ["eastus", "eastus2"] } } PARAMETERS
验证说明
修正后执行terraform apply,策略分配将成功创建,Azure会使用指定的listOfAllowedLocations值约束资源部署位置。
内容的提问来源于stack exchange,提问作者uiiueree
相关产品推荐
相关产品推荐

