You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建Azure订阅失败,请求排查问题

问题:Terraform创建Azure订阅报错InvalidSubCreationScope

问题代码

用户尝试通过以下Terraform代码创建Azure订阅并分配到管理组,但执行失败:

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "3.56.0"
    }   
}
}

# Configure the Microsoft Azure Provider
provider "azurerm" {
  features {}
  skip_provider_registration = "true"
  
}


data "azurerm_billing_enrollment_account_scope" "example" {
  billing_account_name    = "account name"
  enrollment_account_name = "account name"
}

resource "azurerm_subscription" "example" {
  subscription_name = "My Example EA Subscription2"
  billing_scope_id  = data.azurerm_billing_enrollment_account_scope.example.id
}


data "azurerm_subscription" "current" {
}

resource "azurerm_management_group" "example_parent" {
  display_name = "ParentGroup"

  subscription_ids = []
}

resource "azurerm_management_group" "example_child" {
  display_name               = "ChildGroup"
  parent_management_group_id = azurerm_management_group.example_parent.id

  subscription_ids = []
  # other subscription IDs can go here
}

错误信息

执行时触发如下错误:

Plan: 1 to add, 0 to change, 0 to destroy.
azurerm_subscription.example: Creating...

╷
│ Error: creating new Subscription (Alias "6c92cfef-64f7-4ee4-b6b6-427501d2eab5"): subscriptions.SubscriptionsClient#AliasCreate: Failure sending request: StatusCode=0 -- Original Error: Code="InvalidSubCreationScope" Message="Not a valid subscription creation scope"
│ 
│   with azurerm_subscription.example,
│   on main.tf line 23, in resource "azurerm_subscription" "example":
│   23: resource "azurerm_subscription" "example" {

问题分析

  1. 核心原因:data "azurerm_billing_enrollment_account_scope" "example"中的billing_account_name和enrollment_account_name使用了占位符"account name",导致生成的billing_scope_id无效,Azure无法识别合法的计费范围,因此抛出InvalidSubCreationScope错误。
  2. 额外问题:当前代码中的管理组未关联新创建的订阅,无法实现“创建订阅并分配到管理组”的需求。

解决方案

1. 获取合法的计费账户和注册账户信息

  • 登录Azure门户,进入「成本管理 + 计费」
  • 定位到你的企业协议(EA)对应的计费账户,复制其名称(格式通常为xxxx-xxxx-xxxx-xxxx)
  • 在该计费账户下找到目标注册账户,复制其名称(可为显示名称或GUID)

2. 修正后的Terraform代码

替换占位符,并将新订阅关联到管理组:

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "3.56.0"
    }   
  }
}

provider "azurerm" {
  features {}
  # 仅测试环境建议保留,生产环境请移除该配置
  skip_provider_registration = true
}

# 替换为实际的计费账户和注册账户名称
data "azurerm_billing_enrollment_account_scope" "example" {
  billing_account_name    = "xxxx-xxxx-xxxx-xxxx"
  enrollment_account_name = "你的注册账户名称"
}

# 创建Azure订阅
resource "azurerm_subscription" "example" {
  subscription_name = "My Example EA Subscription2"
  billing_scope_id  = data.azurerm_billing_enrollment_account_scope.example.id
}

# 创建父管理组并关联新订阅
resource "azurerm_management_group" "example_parent" {
  display_name = "ParentGroup"
  subscription_ids = [azurerm_subscription.example.id]
}

# 创建子管理组(可选,若需将订阅移至子组可修改subscription_ids)
resource "azurerm_management_group" "example_child" {
  display_name               = "ChildGroup"
  parent_management_group_id = azurerm_management_group.example_parent.id
  subscription_ids = []
}

3. 验证执行权限

确保运行Terraform的身份(用户/服务主体)拥有:

  • 计费账户/注册账户上的订阅创建者角色
  • 目标管理组上的管理组参与者或所有者角色

内容的提问来源于stack exchange,提问作者GoneCase123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 22:02:16