如何通过Azure CLI或Terraform创建指定目标VM的Azure LB入站NAT规则?
Azure Load Balancer入站NAT规则:CLI与Terraform实现门户一致配置
完全可以通过Azure CLI或Terraform实现和Azure门户完全一致的入站NAT规则配置——门户中选择目标VM的操作,本质是自动将NAT规则关联到VM对应的网络接口IP配置,CLI和Terraform只需直接指定该关联关系即可。
Azure CLI实现
使用az network lb inbound-nat-rule create命令,通过--backend-ip-config参数直接指定目标VM的网络接口及IP配置(格式为<网卡名称>/<IP配置名称>),无需额外步骤。示例命令:
az network lb inbound-nat-rule create \ --resource-group your-resource-group \ --lb-name your-loadbalancer \ --name ssh-nat-rule \ --frontend-ip-name your-frontend-ip \ --protocol TCP \ --frontend-port 2222 \ --backend-port 22 \ --backend-ip-config your-vm-nic/your-vm-ip-config
注:若VM使用默认网卡配置,IP配置名称通常为
ipconfig1,可通过az network nic show命令查看。
Terraform实现
无需单独创建绑定资源,直接在azurerm_lb_inbound_nat_rule资源中通过backend_ip_configuration_id参数引用VM网络接口的IP配置ID即可。示例代码:
# 定义资源组 resource "azurerm_resource_group" "example" { name = "example-resources" location = "East US" } # 定义子网与虚拟网络 resource "azurerm_virtual_network" "example" { name = "example-network" address_space = ["10.0.0.0/16"] location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name } resource "azurerm_subnet" "example" { name = "example-subnet" resource_group_name = azurerm_resource_group.example.name virtual_network_name = azurerm_virtual_network.example.name address_prefixes = ["10.0.1.0/24"] } # 定义VM的网络接口 resource "azurerm_network_interface" "vm_nic" { name = "example-vm-nic" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name ip_configuration { name = "internal" subnet_id = azurerm_subnet.example.id private_ip_address_allocation = "Dynamic" } } # 定义负载均衡器 resource "azurerm_lb" "example" { name = "example-lb" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name frontend_ip_configuration { name = "example-frontend-ip" public_ip_address_id = azurerm_public_ip.example.id } } resource "azurerm_public_ip" "example" { name = "example-pip" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name allocation_method = "Static" } # 定义入站NAT规则,直接关联VM网卡IP配置 resource "azurerm_lb_inbound_nat_rule" "ssh_rule" { name = "ssh-nat-rule" resource_group_name = azurerm_resource_group.example.name loadbalancer_id = azurerm_lb.example.id frontend_ip_configuration_id = azurerm_lb.example.frontend_ip_configuration[0].id protocol = "Tcp" frontend_port = 2222 backend_port = 22 backend_ip_configuration_id = azurerm_network_interface.vm_nic.ip_configuration[0].id }
注:若之前尝试单独绑定未生效,通常是因为错误使用了非直接关联的资源(如单独的关联资源),直接在NAT规则资源中指定
backend_ip_configuration_id才是和门户逻辑一致的正确方式。
内容的提问来源于stack exchange,提问作者Petro Kolosov
相关产品推荐
相关产品推荐

