Terraform部署Azure Windows虚拟机时,通过变量传递敏感用户名/密码出现密码合规性报错的问题排查
Let's break down the mistakes in your configuration and fix them step by step:
1. Incorrect Variable Reference in main.tf
The biggest issue here is that you've wrapped your variable references in quotes, which means Terraform is treating them as literal strings instead of evaluating the actual variable values.
Wrong code:
admin_username = "var.admin_username" admin_password = "var.admin_password"
Fixed code:
admin_username = var.admin_username admin_password = var.admin_password
Without the quotes, Terraform will pull the credential values you defined instead of passing the string "var.admin_password" (which obviously fails Azure's password complexity checks).
2. Misnamed terraform.tfvars File
Your file is named terrafrom.tfvars (note the missing 'r' in "terraform"). Terraform automatically loads files named terraform.tfvars or *.auto.tfvars, so it's not picking up your credential values at all right now. Rename the file to terraform.tfvars to fix this.
3. Invalid Variable Names in terraform.tfvars
You're using the TF_VAR_ prefix in your tfvars file—this prefix is reserved for environment variables, not variables defined in tfvars files. Remove the prefix to match the variable names you declared in variables.tf.
Wrong code:
TF_VAR_admin_username = "adminuser" TF_VAR_admin_password = "OurP@**w0rd1998#"
Fixed code:
admin_username = "adminuser" admin_password = "OurP@**w0rd1998#"
4. Bonus: Enhance Security with Sensitive Variables
To keep your password hidden from Terraform's plan/apply output, mark your password variable as sensitive in variables.tf:
variable "admin_password" { type = string sensitive = true }
After making all these changes, run terraform init, terraform plan, and terraform apply—your VM should deploy successfully with credentials passed securely via variables.
内容的提问来源于stack exchange,提问作者alexis19apl

