You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Terraform实现Azure资源的创建与关联

Terraform实现Azure APIM与Application Insights、Key Vault、Log Analytics自动关联

以下是完整的Terraform配置,可一次性创建所有目标资源并完成自动关联,无需手动操作:

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.0.2"
    }
  }
  required_version = ">= 1.1.0"
}

provider "azurerm" {
  features {}
}

data "azurerm_client_config" "current" {}

# 资源组
resource "azurerm_resource_group" "dev" {
  name     = "TerraformPOC-DevResourceGroup"
  location = "WestEurope"
}

# Application Insights
resource "azurerm_application_insights" "ai" {
  name                = "TerraformPOC-Application-Insights"
  location            = azurerm_resource_group.dev.location
  resource_group_name = azurerm_resource_group.dev.name
  application_type    = "other"
}

# Log Analytics 工作区
resource "azurerm_log_analytics_workspace" "law" {
  name                = "TerraformPOC-Log-Analytics"
  location            = azurerm_resource_group.dev.location
  resource_group_name = azurerm_resource_group.dev.name
  retention_in_days   = 30
}

# Key Vault
resource "azurerm_key_vault" "kv" {
  name                       = "TerraformPOC-KeyVault"
  location                   = azurerm_resource_group.dev.location
  resource_group_name        = azurerm_resource_group.dev.name
  tenant_id                  = data.azurerm_client_config.current.tenant_id
  soft_delete_retention_days = 7
  purge_protection_enabled   = false

  # 授予APIM访问Key Vault秘密的权限
  access_policy {
    tenant_id = data.azurerm_client_config.current.tenant_id
    object_id = azurerm_api_management.apim.identity[0].principal_id

    secret_permissions = [
      "Get",
      "List"
    ]
  }
}

# 示例Key Vault秘密(按需修改或删除)
resource "azurerm_key_vault_secret" "example" {
  name         = "example-secret"
  value        = "demo-value"
  key_vault_id = azurerm_key_vault.kv.id
}

# APIM资源,内置Application Insights关联配置
resource "azurerm_api_management" "apim" {
  name                = "TerraformPOC-APIManagement"
  location            = azurerm_resource_group.dev.location
  resource_group_name = azurerm_resource_group.dev.name
  publisher_name      = "TestDemo"
  publisher_email     = "pradeep.mathada@amadeus.com"
  sku_name            = "Developer_1"

  # 启用系统分配身份,用于访问Key Vault
  identity {
    type = "SystemAssigned"
  }

  # 自动关联Application Insights,配置请求采样比例
  application_insights {
    instrumentation_key = azurerm_application_insights.ai.instrumentation_key
    sampling_percentage = 100
  }
}

# 配置APIM诊断日志流向Log Analytics
resource "azurerm_monitor_diagnostic_setting" "apim_diagnostic" {
  name               = "APIM-To-LogAnalytics"
  target_resource_id = azurerm_api_management.apim.id
  log_analytics_workspace_id = azurerm_log_analytics_workspace.law.id

  log {
    category = "GatewayLogs"
    enabled  = true

    retention_policy {
      enabled = false
    }
  }

  metric {
    category = "AllMetrics"
    enabled  = true

    retention_policy {
      enabled = false
    }
  }
}

# 创建APIM命名值,关联Key Vault中的秘密
resource "azurerm_api_management_named_value" "kv_secret" {
  name                = "ExampleSecretFromKV"
  resource_group_name = azurerm_resource_group.dev.name
  api_management_name = azurerm_api_management.apim.name
  secret              = true
  key_vault_secret_id = azurerm_key_vault_secret.example.id
}

关联逻辑说明

  • APIM ↔ Application Insights:通过azurerm_api_management内的application_insights块直接绑定,APIM会自动将API请求的监控数据发送到指定的Application Insights实例。
  • APIM ↔ Log Analytics:借助azurerm_monitor_diagnostic_setting将APIM的网关日志、指标推送至Log Analytics工作区,可根据业务需求调整日志类别和保留策略。
  • APIM ↔ Key Vault:给APIM启用系统分配身份,在Key Vault中配置访问策略授权APIM读取秘密,再通过azurerm_api_management_named_value将Key Vault秘密映射为APIM可直接使用的命名值,实现密钥的安全托管与调用。

内容的提问来源于stack exchange,提问作者Pradeep K M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 20:20:36