如何用Terraform创建含默认源组的Azure CDN多源端点?
解决Azure CDN端点与源组的循环依赖问题
方案一:使用AzureRM Provider原生资源(推荐)
AzureRM提供了专门的CDN资源类型,能更顺畅地处理资源间的依赖关系,避免手动维护父子ID时的循环问题。以下是完整示例:
resource "azurerm_resource_group" "main" { name = "example-resources" location = "West Europe" } resource "azurerm_cdn_profile" "profile" { name = "MyProfile2" location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name sku_name = "Standard_Microsoft" } # 先创建基础端点,暂不绑定默认源组 resource "azurerm_cdn_endpoint" "endpoint" { name = "MyEndpoint2" profile_name = azurerm_cdn_profile.profile.name location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name } # 创建CDN源 resource "azurerm_cdn_origin" "origin" { name = "MyOrigin2" cdn_endpoint_id = azurerm_cdn_endpoint.endpoint.id host_name = "contoso.com" http_port = 80 https_port = 443 origin_host_header = "www.contoso.com" enabled = true } # 创建源组并关联上面的源 resource "azurerm_cdn_origin_group" "origin_group" { name = "MyOriginGroup2" cdn_endpoint_id = azurerm_cdn_endpoint.endpoint.id session_affinity_enabled = false origin { id = azurerm_cdn_origin.origin.id } } # 更新端点,绑定默认源组 resource "azurerm_cdn_endpoint" "endpoint_with_default_group" { name = azurerm_cdn_endpoint.endpoint.name profile_name = azurerm_cdn_profile.profile.name location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name default_origin_group_id = azurerm_cdn_origin_group.origin_group.id lifecycle { replace_triggered_by = [azurerm_cdn_origin_group.origin_group.id] } }
这个方案的核心是分两步处理端点:先创建不带默认源组的基础端点,等源和源组创建完成后,再更新端点绑定默认源组,彻底避开循环依赖。
方案二:使用AzAPI Provider分阶段处理
如果必须使用AzAPI,可以通过azapi_update_resource来后期更新端点配置,打破循环:
resource "azurerm_resource_group" "main" { name = "example-resources" location = "West Europe" } resource "azapi_resource" "profile" { type = "Microsoft.Cdn/profiles@2022-11-01-preview" name = "MyProfile2" location = azurerm_resource_group.main.location parent_id = azurerm_resource_group.main.id body = jsonencode({ sku = { name = "Standard_Microsoft" } }) } # 第一步:创建端点,不设置defaultOriginGroup resource "azapi_resource" "endpoint" { type = "Microsoft.Cdn/profiles/endpoints@2022-11-01-preview" name = "MyEndpoint2" location = azurerm_resource_group.main.location parent_id = azapi_resource.profile.id body = jsonencode({ properties = { origins = [{ name = "DefaultOrigin" properties = { enabled = true hostName = "contoso.com" httpPort = 80 httpsPort = 443 } }] } }) } # 创建自定义源 resource "azapi_resource" "origin" { type = "Microsoft.Cdn/profiles/endpoints/origins@2022-11-01-preview" name = "MyOrigin2" parent_id = azapi_resource.endpoint.id body = jsonencode({ properties = { enabled = true hostName = "contoso.com" httpPort = 80 httpsPort = 443 originHostHeader = "www.contoso.com" } }) } # 创建源组并关联自定义源 resource "azapi_resource" "originGroup" { type = "Microsoft.Cdn/profiles/endpoints/originGroups@2022-11-01-preview" name = "MyOriginGroup2" parent_id = azapi_resource.endpoint.id body = jsonencode({ origins = [{ id = azapi_resource.origin.id }] }) } # 第二步:更新端点,设置默认源组 resource "azapi_update_resource" "endpoint_update" { type = "Microsoft.Cdn/profiles/endpoints@2022-11-01-preview" resource_id = azapi_resource.endpoint.id body = jsonencode({ properties = { defaultOriginGroup = { id = azapi_resource.originGroup.id } } }) }
这里先用azapi_resource创建不带默认源组的端点,等源和源组创建完成后,再通过azapi_update_resource给端点添加默认源组配置,解决循环依赖问题。
内容的提问来源于stack exchange,提问作者bazsibazsi
相关产品推荐
相关产品推荐

