You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署Azure时Key Vault object_id无效UUID错误求助

问题:Key Vault Access Policy Object ID 格式错误

执行terraform plan -var-file="variables.tfvars"时触发以下错误:

Error: expected "access_policy.0.object_id" to be a valid UUID, got /subscriptions/xxxxxxxx/resourceGroups/xxxxxxxxx/providers/Microsoft.ManagedIdentity/userAssignedIdentities/agw-user-signed-id
│
│   with azurerm_key_vault.kv,
│   on main.tf line 344, in resource "azurerm_key_vault" "kv":
│  344:     object_id    = module.agw_user_assigned_identity.id

原因

Azure Key Vault的access_policy要求object_id参数必须是UUID格式的对象ID,但当前传入的是用户分配托管身份的资源ID(完整资源路径),两者格式不匹配导致验证失败。

解决方案

1. 调整用户分配身份模块的输出

在../modules/resources-blocks/user_assigned_identity模块的outputs.tf中,添加对象ID的输出:

output "object_id" {
  type        = string
  description = "Principal/Object ID of the user-assigned managed identity"
  value       = azurerm_user_assigned_identity.this.principal_id
}

注意:如果模块内的用户分配身份资源名称不是this,替换为实际的资源名称。

2. 更新Key Vault模块的参数传递

在根模块的Key Vault调用代码中,将object_id参数从资源ID改为对象ID:

module "key_vault" {
  source = "../modules/resources/key_vault"

  key_vault_name              = local.key_vault_name
  resource_group_location     = module.resource_group.location
  resource_group_name         = module.resource_group.name
  tenant_id                   = data.azurerm_client_config.current.tenant_id
  object_id                   = module.agw_user_assigned_identity.object_id  # 修改此处
  soft_delete_retention_days  = 90
  log_analytics_workspace_id  = module.log_analytics_workspace.id
  enable_diagnostic_setting   = true
}

3. 额外验证(可选)

确保应用网关模块正确接收用户分配身份的资源ID:

  • 应用网关模块内的azurerm_application_gateway资源中,identity_ids使用的是资源ID,这部分当前代码是正确的,无需修改。

内容的提问来源于stack exchange,提问作者Gregory

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 23:20:39