如何通过单个Terraform random_uuid资源生成多个Sentinel自动化规则UUID
问题描述
我正在用Terraform部署Azure Sentinel的自动化规则,由于规则名称要求是UUID,现在每个规则都单独用一个random_uuid资源生成UUID,代码如下:
resource "random_uuid" "automation_rule_1" {} resource "azurerm_sentinel_automation_rule" "automation_rule_1" { name = random_uuid.automation_rule_1.result log_analytics_workspace_id = var.log_analytics_workspace_id display_name = "Automation Rule 1" order = 1 triggers_on = "Incidents" triggers_when = "Created" enabled = true action_playbook { logic_app_id = var.logic_app_id order = 1 tenant_id = var.tenant_id } } resource "random_uuid" "automation_rule_2" {} resource "azurerm_sentinel_automation_rule" "automation_rule_2" { name = random_uuid.automation_rule_2.result log_analytics_workspace_id = var.log_analytics_workspace_id display_name = "Automation Rule 2" order = 1 triggers_on = "Incidents" triggers_when = "Created" enabled = true condition_json = jsonencode( [ { conditionProperties = { operator = "Contains" propertyName = "IncidentRelatedAnalyticRuleIds" propertyValues = [ var.sentinel_alert_rule_scheduled_id ] } conditionType = "Property" } ] ) action_incident { order = 1 status = "Closed" classification = "BenignPositive_SuspiciousButExpected" classification_comment = "Sample Comment Goes Here" owner_id = var.automation_rule_owner_id } }
我想实现类似下面的效果,用单个random_uuid资源生成多个规则的UUID,请问是否可行?
resource "random_uuid" "automation_rule_ids" { keepers = { "rule_1_id" = "dont know what to put here", "rule_2_id" = "dont know what to put here" } }
解决方案
完全可以实现,但不需要用keepers参数(该参数用于依赖值变化时重新生成UUID,而非生成多实例UUID),推荐用for_each来让单个random_uuid资源生成多个UUID实例,同时结合配置批量创建规则,减少重复代码。
方法一:批量生成UUID+批量创建规则
先定义所有自动化规则的配置映射,再基于这个映射生成UUID和规则:
# 定义所有自动化规则的配置 locals { automation_rules = { rule_1 = { display_name = "Automation Rule 1" order = 1 triggers_on = "Incidents" triggers_when = "Created" enabled = true actions = { playbook = { logic_app_id = var.logic_app_id order = 1 tenant_id = var.tenant_id } } } rule_2 = { display_name = "Automation Rule 2" order = 1 triggers_on = "Incidents" triggers_when = "Created" enabled = true condition_json = jsonencode( [ { conditionProperties = { operator = "Contains" propertyName = "IncidentRelatedAnalyticRuleIds" propertyValues = [ var.sentinel_alert_rule_scheduled_id ] } conditionType = "Property" } ] ) actions = { incident = { order = 1 status = "Closed" classification = "BenignPositive_SuspiciousButExpected" classification_comment = "Sample Comment Goes Here" owner_id = var.automation_rule_owner_id } } } } } # 为每个规则生成唯一UUID resource "random_uuid" "automation_rule_ids" { for_each = local.automation_rules } # 批量创建Azure Sentinel自动化规则 resource "azurerm_sentinel_automation_rule" "rules" { for_each = local.automation_rules name = random_uuid.automation_rule_ids[each.key].result log_analytics_workspace_id = var.log_analytics_workspace_id display_name = each.value.display_name order = each.value.order triggers_on = each.value.triggers_on triggers_when = each.value.triggers_when enabled = each.value.enabled # 动态生成playbook动作 dynamic "action_playbook" { for_each = lookup(each.value.actions, "playbook", {}) != {} ? [each.value.actions.playbook] : [] content { logic_app_id = action_playbook.value.logic_app_id order = action_playbook.value.order tenant_id = action_playbook.value.tenant_id } } # 动态生成incident动作 dynamic "action_incident" { for_each = lookup(each.value.actions, "incident", {}) != {} ? [each.value.actions.incident] : [] content { order = action_incident.value.order status = action_incident.value.status classification = action_incident.value.classification classification_comment = action_incident.value.classification_comment owner_id = action_incident.value.owner_id } } # 绑定条件(无则设为null) condition_json = lookup(each.value, "condition_json", null) }
方法二:仅集中生成UUID(保留原有规则定义)
如果不想批量创建规则,只想集中生成UUID,可直接遍历规则名称列表:
locals { rule_keys = ["rule_1", "rule_2"] } # 生成多个UUID实例 resource "random_uuid" "automation_rule_ids" { for_each = toset(local.rule_keys) } # 引用UUID创建规则 resource "azurerm_sentinel_automation_rule" "automation_rule_1" { name = random_uuid.automation_rule_ids["rule_1"].result # 其他配置保持不变... } resource "azurerm_sentinel_automation_rule" "automation_rule_2" { name = random_uuid.automation_rule_ids["rule_2"].result # 其他配置保持不变... }
关键说明
keepers参数不适合你的场景,它的作用是当键值对变化时触发UUID重新生成,无法生成多个独立的UUID实例。- 使用
for_each的优势在于配置集中管理,避免重复代码,且每个UUID与规则一一对应,便于后续维护。
内容的提问来源于stack exchange,提问作者Akila Induranga
相关产品推荐
相关产品推荐

