You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure策略问题:阻止名称以DEMO开头且标签缺失的资源组创建

问题排查:Azure Policy无法拦截不符合标签要求的DEMO开头资源组
  • 核心错误点:策略中使用[resourceGroup().name]匹配资源组名称的方式不正确。针对Microsoft.Resources/subscriptions/resourceGroups类型的资源组本身,应该直接通过field属性访问其name字段,resourceGroup()函数多用于在子资源级别引用所属资源组的属性,不适合直接评估资源组自身。

  • 修正后的完整策略代码:

{
    "mode": "All",
    "parameters": {},
    "policyRule": {
        "if": {
            "allOf": [
                {
                    "field": "type",
                    "equals": "Microsoft.Resources/subscriptions/resourceGroups"
                },
                {
                    "field": "name",
                    "like": "DEMO*"
                },
                {
                    "anyOf": [
                        {
                            "field": "tags['ApplicationName']",
                            "exists": false
                        },
                        {
                            "field": "tags['ManagedBy']",
                            "exists": false
                        },
                        {
                            "field": "tags['Classification']",
                            "exists": false
                        }
                    ]
                }
            ]
        },
        "then": {
            "effect": "deny"
        }
    }
}
  • 补充说明:标签校验的两种写法(exists: false或反向使用containsKey)本身都是有效的,本次失效的根本原因是资源组名称匹配逻辑错误。修正后,创建名称以DEMO开头且缺少ApplicationName/ManagedBy/Classification任意一个标签的资源组时,策略会正确触发拒绝动作。

内容的提问来源于stack exchange,提问作者Aurélien BOURDOIS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 02:06:25