You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过单个Terraform random_uuid资源生成多个Sentinel自动化规则UUID

问题描述

我正在用Terraform部署Azure Sentinel的自动化规则,由于规则名称要求是UUID,现在每个规则都单独用一个random_uuid资源生成UUID,代码如下:

resource "random_uuid" "automation_rule_1" {}

resource "azurerm_sentinel_automation_rule" "automation_rule_1" {
  name                       = random_uuid.automation_rule_1.result
  log_analytics_workspace_id = var.log_analytics_workspace_id
  display_name               = "Automation Rule 1"
  order                      = 1
  triggers_on                = "Incidents"
  triggers_when              = "Created"
  enabled                    = true
  action_playbook {
    logic_app_id = var.logic_app_id
    order        = 1
    tenant_id    = var.tenant_id
  }
}

resource "random_uuid" "automation_rule_2" {}


resource "azurerm_sentinel_automation_rule" "automation_rule_2" {
  name                       = random_uuid.automation_rule_2.result
  log_analytics_workspace_id = var.log_analytics_workspace_id
  display_name               = "Automation Rule 2"
  order                      = 1
  triggers_on                = "Incidents"
  triggers_when              = "Created"
  enabled                    = true
  condition_json = jsonencode(
    [
      {
        conditionProperties = {
          operator     = "Contains"
          propertyName = "IncidentRelatedAnalyticRuleIds"
          propertyValues = [ var.sentinel_alert_rule_scheduled_id ]
        }
        conditionType = "Property"
      }
    ]
  )
  action_incident {
    order                  = 1
    status                 = "Closed"
    classification         = "BenignPositive_SuspiciousButExpected"
    classification_comment = "Sample Comment Goes Here"
    owner_id               = var.automation_rule_owner_id
  }
}

我想实现类似下面的效果,用单个random_uuid资源生成多个规则的UUID,请问是否可行?

resource "random_uuid" "automation_rule_ids" {
  keepers = {
    "rule_1_id" = "dont know what to put here",
    "rule_2_id" = "dont know what to put here"
  }
}
解决方案

完全可以实现,但不需要用keepers参数(该参数用于依赖值变化时重新生成UUID,而非生成多实例UUID),推荐用for_each来让单个random_uuid资源生成多个UUID实例,同时结合配置批量创建规则,减少重复代码。

方法一:批量生成UUID+批量创建规则

先定义所有自动化规则的配置映射,再基于这个映射生成UUID和规则:

# 定义所有自动化规则的配置
locals {
  automation_rules = {
    rule_1 = {
      display_name  = "Automation Rule 1"
      order         = 1
      triggers_on   = "Incidents"
      triggers_when = "Created"
      enabled       = true
      actions = {
        playbook = {
          logic_app_id = var.logic_app_id
          order        = 1
          tenant_id    = var.tenant_id
        }
      }
    }
    rule_2 = {
      display_name  = "Automation Rule 2"
      order         = 1
      triggers_on   = "Incidents"
      triggers_when = "Created"
      enabled       = true
      condition_json = jsonencode(
        [
          {
            conditionProperties = {
              operator     = "Contains"
              propertyName = "IncidentRelatedAnalyticRuleIds"
              propertyValues = [ var.sentinel_alert_rule_scheduled_id ]
            }
            conditionType = "Property"
          }
        ]
      )
      actions = {
        incident = {
          order                  = 1
          status                 = "Closed"
          classification         = "BenignPositive_SuspiciousButExpected"
          classification_comment = "Sample Comment Goes Here"
          owner_id               = var.automation_rule_owner_id
        }
      }
    }
  }
}

# 为每个规则生成唯一UUID
resource "random_uuid" "automation_rule_ids" {
  for_each = local.automation_rules
}

# 批量创建Azure Sentinel自动化规则
resource "azurerm_sentinel_automation_rule" "rules" {
  for_each                   = local.automation_rules
  name                       = random_uuid.automation_rule_ids[each.key].result
  log_analytics_workspace_id = var.log_analytics_workspace_id
  display_name               = each.value.display_name
  order                      = each.value.order
  triggers_on                = each.value.triggers_on
  triggers_when              = each.value.triggers_when
  enabled                    = each.value.enabled

  # 动态生成playbook动作
  dynamic "action_playbook" {
    for_each = lookup(each.value.actions, "playbook", {}) != {} ? [each.value.actions.playbook] : []
    content {
      logic_app_id = action_playbook.value.logic_app_id
      order        = action_playbook.value.order
      tenant_id    = action_playbook.value.tenant_id
    }
  }

  # 动态生成incident动作
  dynamic "action_incident" {
    for_each = lookup(each.value.actions, "incident", {}) != {} ? [each.value.actions.incident] : []
    content {
      order                  = action_incident.value.order
      status                 = action_incident.value.status
      classification         = action_incident.value.classification
      classification_comment = action_incident.value.classification_comment
      owner_id               = action_incident.value.owner_id
    }
  }

  # 绑定条件(无则设为null)
  condition_json = lookup(each.value, "condition_json", null)
}

方法二:仅集中生成UUID(保留原有规则定义)

如果不想批量创建规则,只想集中生成UUID,可直接遍历规则名称列表:

locals {
  rule_keys = ["rule_1", "rule_2"]
}

# 生成多个UUID实例
resource "random_uuid" "automation_rule_ids" {
  for_each = toset(local.rule_keys)
}

# 引用UUID创建规则
resource "azurerm_sentinel_automation_rule" "automation_rule_1" {
  name                       = random_uuid.automation_rule_ids["rule_1"].result
  # 其他配置保持不变...
}

resource "azurerm_sentinel_automation_rule" "automation_rule_2" {
  name                       = random_uuid.automation_rule_ids["rule_2"].result
  # 其他配置保持不变...
}

关键说明

  • keepers参数不适合你的场景,它的作用是当键值对变化时触发UUID重新生成,无法生成多个独立的UUID实例。
  • 使用for_each的优势在于配置集中管理,避免重复代码,且每个UUID与规则一一对应,便于后续维护。

内容的提问来源于stack exchange,提问作者Akila Induranga

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 02:23:08