基于storage_queue_endpoint创建Azure Event Grid订阅失败求助
尝试通过storage_queue_endpoint创建Azure Event Grid订阅,已成功创建存储账户及队列,但创建订阅时触发以下Endpoint validation错误:
╷
│ Error: waiting for Event Subscription: (Name "evengridtest01" / Scope "/subscriptions//resourceGroups/"): Code="Endpoint validation" Message="Destination endpoint not found. Resource details: resourceId: /subscriptions//resourceGroups//providers/Microsoft.Storage/storageAccounts/tfteststgacc009. Resource should pre-exist before attempting this operation. Activity id:7a4d548e-53ba-4530-a93e-8c2d48aad183, timestamp: 2/17/2023 3:54:27 PM (UTC)."
│
│ with azurerm_eventgrid_event_subscription.default["evengridtest01"],
│ on main.tf line 50, in resource "azurerm_eventgrid_event_subscription" "default":
│ 50: resource "azurerm_eventgrid_event_subscription" "default" {
│
╵
对应的Terraform代码如下:
terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = "<= 3.30.0" } } required_version = ">= 0.13" } provider "azurerm" { features {} } data "azurerm_subscription" "current" { subscription_id = var.subscription_id } data "azurerm_resource_group" "current" { name = var.resource_group } #data "azurerm_storage_account" "default"{ # name=var.storage_account_name # resource_group_name=var.storage_account_resource_group #} #resource "azurerm_storage_queue" "default" { #name=var.storage_queue_name #storage_account_name=data.azurerm_storage_account.default.name #} module "storage-account" { source = "git@github.com:procter-gamble/terraform-azure-storage-account.git?ref=v4.0.0" count = var.existing_storage_account ? 0 : 1 subscription_id = data.azurerm_subscription.current.subscription_id resource_group = data.azurerm_resource_group.current.name resource_name = var.storage_account_name access_groups = [] resource_tags = var.resource_tags account_tier = var.storage_account_tier access_tier = var.storage_access_tier replication_type = var.storage_replication_type virtual_network_subnet_ids = var.storage_virtual_network_subnet_ids create_private_dns = false enable_private_endpoint = false queues = var.queues ip_rules = var.ip_rules } resource "azurerm_eventgrid_event_subscription" "default" { for_each = { for event in var.event_grid : event.name => event } name = each.value.name event_delivery_schema = lookup(each.value, "event_delivery_schema", null) advanced_filtering_on_arrays_enabled = lookup(each.value, "advanced_filtering_on_arrays_enabled", null) scope = data.azurerm_resource_group.current.id dynamic "storage_queue_endpoint" { for_each = lookup(each.value, "storage_queue_endpoint", "false") == "true" ? [1] : [] content { storage_account_id = join(",",[module.storage-account[0].id]) queue_name = "test" queue_message_time_to_live_in_seconds = lookup(each.value, "queue_message_time_to_live_in_seconds", null) } } depends_on=[module.storage-account] }
1. 修复存储账户ID引用冗余
代码中用join(",",[module.storage-account[0].id])拼接存储账户ID属于多余操作,直接引用module.storage-account[0].id即可。多余的拼接会导致存储账户ID格式错误,Event Grid无法识别正确的存储资源。
修改storage_queue_endpoint块中的storage_account_id:
storage_account_id = module.storage-account[0].id
2. 确保队列名称与实际创建的一致
- 检查
var.queues变量是否包含名为test的队列,因为代码中硬编码了queue_name = "test",如果模块创建的队列名称不匹配,Event Grid会找不到目标队列。 - 如果
var.queues是动态定义的,可改为引用模块输出的队列名称,示例如下(需根据模块实际输出结构调整):queue_name = module.storage-account[0].queues["test"].name
3. 增强依赖关系确保资源就绪
虽然已添加depends_on=[module.storage-account],但如果模块内部创建队列的逻辑存在延迟,可通过引用队列的具体输出增强依赖,确保队列完全创建后再创建Event Grid订阅:
depends_on = [ module.storage-account, module.storage-account[0].queues["test"].id ]
4. 检查存储账户网络限制
如果存储账户配置了ip_rules或virtual_network_subnet_ids,需确保Event Grid服务的IP地址被允许访问。Event Grid需要访问存储队列完成端点验证,否则会返回找不到端点的错误。可临时移除网络限制测试,确认问题后再添加正确的允许规则。
5. 确认存储账户创建开关状态
确保var.existing_storage_account的值为false,否则模块不会创建新的存储账户,此时module.storage-account[0].id会引用不存在的资源,触发错误。
内容的提问来源于stack exchange,提问作者hari989

