Azure DeployIfNotExists策略无法创建资源组策略分配问题
问题:Azure订阅级DeployIfNotExists策略执行成功但未创建资源组级策略分配
我定义了如下资源白名单策略(直接分配到资源组时可正常工作):
{ "properties": { "displayName": "Deny resource creation if not in whitelist", "policyType": "Custom", "mode": "Indexed", "description": "This policy denies the creation resources which are not allowed in the whitelist.", "policyRule": { "if": { "not": { "field": "type", "in": [ "Microsoft.KeyVault/vaults", "Microsoft.Storage/storageAccounts" ] } }, "then": { "effect": "Deny" } } }, "id": "<POLICYDEFINITIONID>", "type": "Microsoft.Authorization/policyDefinitions", "name": "Deny_resource_creation_if_not_in_whitelist", }
我还创建了一个订阅级的DeployIfNotExists策略,用于将上述白名单策略部署到名称以rg-*开头的资源组:
{ "properties": { "displayName": "Deploy resource whitelist policy", "policyType": "Custom", "mode": "All", "description": "This policy assigns the resource whitelist policy to resource groups starting with rg-*.", "policyRule": { "if": { "allOf": [ { "equals": "Microsoft.Resources/subscriptions/resourceGroups", "field": "type" }, { "field": "name", "like": "rg-*" } ] }, "then": { "details": { "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "apiVersion": "2022-06-01", "name": "[guid('<POLICYDEFINITIONID>', resourceGroup().name)]", "properties": { "displayName": "Deny resource creation if not in whitelist", "enforcementMode": "Default", "policyDefinitionId": "<POLICYDEFINITIONID>" }, "type": "Microsoft.Authorization/policyAssignments" } ] } } }, "evaluationDelay": "AfterProvisioning", "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/8e3af657-a8ff-443c-a75c-2fe8c4bcb635" ], "type": "Microsoft.Authorization/policyAssignments" }, "effect": "DeployIfNotExists" } } }, "id": "", "type": "Microsoft.Authorization/policyDefinitions", "name": "Deploy_resource_whitelist_policy", }
当前问题:该订阅级策略已完成评估,且显示DeployIfNotExists事件执行成功,但实际上并未创建策略分配。
补充信息:
- 已成功从Azure门户手动部署该策略分配的ARM模板
- 将该ARM模板替换为简单的存储账户模板时,可正常在资源组中创建存储账户
解决方案
1. 指定部署目标资源组
订阅级DeployIfNotExists策略默认会将模板部署到订阅范围,而策略分配需要针对具体资源组。需要在deployment配置中添加resourceGroup参数,明确指向匹配的目标资源组:
"deployment": { "properties": { "mode": "incremental", "resourceGroup": "[field('name')]", // 新增此行,指定部署到当前匹配的资源组 "template": { // 原模板内容保持不变 } } }
2. 修正策略定义ID引用
确保模板中的<POLICYDEFINITIONID>替换为完整的ARM资源ID,格式为:/subscriptions/{你的订阅ID}/providers/Microsoft.Authorization/policyDefinitions/Deny_resource_creation_if_not_in_whitelist
3. 优化策略分配名称(可选)
原模板中用guid生成名称可能导致存在性检查异常,可改为固定名称或结合资源组名称的规则:
"name": "[concat('Deny-Whitelist-', resourceGroup().name)]"
4. 添加存在性检查条件(可选)
为了让DeployIfNotExists更精准判断是否需要创建分配,可在details节点下添加existenceCondition:
"existenceCondition": { "allOf": [ { "field": "Microsoft.Authorization/policyAssignments/policyDefinitionId", "equals": "<POLICYDEFINITIONID>" }, { "field": "name", "equals": "[concat('Deny-Whitelist-', resourceGroup().name)]" } ] }
5. 验证权限配置
虽然使用了8e3af657-a8ff-443c-a75c-2fe8c4bcb635(资源策略参与者角色),仍需确认策略分配的主体拥有在目标资源组创建策略分配的权限,可通过Azure门户的权限检查功能验证。
内容的提问来源于stack exchange,提问作者Chris
相关产品推荐
相关产品推荐

