通过Terraform创建PAT Token销毁时遇API版本格式错误问题
问题解决:Terraform销毁Azure DevOps PAT Token时API版本错误
问题描述
使用Terraform的restapi_object资源创建Azure DevOps PAT Token可正常执行,但销毁时报错:
Error: unexpected response code '500': {"$id":"1","innerException":null,"message":"Invalid api version string: \"7.0-preview.1/PAT_CWF\". Api version string must be in the format: {Major}.{Minor}[-preview[.{ResourceVersion}]].","typeName":"Microsoft.VisualStudio.Services.WebApi.VssInvalidApiResourceVersionException, Microsoft.VisualStudio.Services.WebApi","typeKey":"VssInvalidApiResourceVersionException","errorCode":0,"eventId":3000}
原因分析
原配置中id_attribute = "patToken/displayName",Terraform在销毁资源时会将displayName的值(如PAT_CWF)拼接到API路径的版本参数后,导致请求URL变为/_apis/tokens/pats/pats?api-version=7.0-preview.1/PAT_CWF,违反了API版本的格式要求。
Azure DevOps的PAT删除API需要通过tokenId而非displayName定位资源,因此需要调整配置以使用正确的标识和销毁路径。
解决方案
修改restapi_object资源配置,使用tokenId作为资源标识,并指定正确的销毁路径和方法:
resource "restapi_object" "pat_token_ado_creation" { path = "/_apis/tokens/pats/pats?api-version=7.0-preview.1" data = jsonencode({ displayName = "PAT_${var.organisation}" scope = "vso.project_write" validTo = timeadd(timestamp(), "1h") allOrgs = false }) id_attribute = "tokenId" update_method = "PUT" # 指定销毁时的正确路径,使用tokenId定位资源 destroy_path = "/_apis/tokens/pats/${self.id}?api-version=7.0-preview.1" destroy_method = "DELETE" }
关键调整说明
id_attribute = "tokenId":改用PAT创建接口返回的tokenId作为资源唯一标识,避免使用displayName导致路径拼接错误。destroy_path:明确指定销毁请求的路径,通过${self.id}引用tokenId,构造符合Azure DevOps API要求的删除URL。destroy_method = "DELETE":PAT删除接口需要使用DELETE方法,补充该参数确保请求方法正确。
内容的提问来源于stack exchange,提问作者chaotic
相关产品推荐
相关产品推荐

