能否通过Terraform获取Azure文件共享的挂载代码?
Absolutely! You can definitely retrieve the mount command/code for your Azure File Share using Terraform—no need to manually copy it from the Azure portal. Here's a straightforward approach covering both scenarios where you're creating the share with Terraform or referencing an existing one.
Scenario 1: Creating Storage Account & File Share with Terraform
If you're provisioning the resources directly in your Terraform config, you can extract all required values from resource attributes to build the mount command automatically.
Example Configuration
# Create an Azure resource group resource "azurerm_resource_group" "example" { name = "example-resources" location = "West Europe" } # Provision a storage account resource "azurerm_storage_account" "example" { name = "examplestorageacc" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location account_tier = "Standard" account_replication_type = "LRS" } # Create the file share resource "azurerm_storage_share" "example" { name = "example-fileshare" storage_account_name = azurerm_storage_account.example.name quota = 50 # Quota in GB } # Fetch the storage account's primary access key data "azurerm_storage_account_primary_access_key" "example" { storage_account_name = azurerm_storage_account.example.name resource_group_name = azurerm_resource_group.example.name } # Output Linux mount command output "linux_mount_command" { value = <<-EOT sudo mkdir -p /mnt/azurefileshare sudo mount -t cifs //${azurerm_storage_account.example.name}.file.core.windows.net/${azurerm_storage_share.example.name} /mnt/azurefileshare -o username=${azurerm_storage_account.example.name},password=${data.azurerm_storage_account_primary_access_key.example.key},serverino,nosharesock,actimeo=30 EOT sensitive = false # Set to true to hide the access key in plain output } # Output Windows mount command output "windows_mount_command" { value = <<-EOT net use Z: \\\\${azurerm_storage_account.example.name}.file.core.windows.net\\${azurerm_storage_share.example.name} /user:AZURE\\\\${azurerm_storage_account.example.name} ${data.azurerm_storage_account_primary_access_key.example.key} EOT sensitive = false }
How it works:
- We use Terraform resources to spin up the resource group, storage account, and file share.
- The
azurerm_storage_account_primary_access_keydata source pulls the account's access key (required for authentication to the share). - We interpolate all dynamic values (account name, share name, access key) into pre-built mount commands for both Linux and Windows.
Scenario 2: Referencing Existing Storage Account & File Share
If your resources already exist in Azure, use Terraform data sources to fetch their details instead of creating new ones:
Example Configuration
# Reference existing resource group data "azurerm_resource_group" "example" { name = "example-resources" } # Reference existing storage account data "azurerm_storage_account" "example" { name = "examplestorageacc" resource_group_name = data.azurerm_resource_group.example.name } # Reference existing file share data "azurerm_storage_share" "example" { name = "example-fileshare" storage_account_name = data.azurerm_storage_account.example.name } # Fetch access key for the existing account data "azurerm_storage_account_primary_access_key" "example" { storage_account_name = data.azurerm_storage_account.example.name resource_group_name = data.azurerm_resource_group.example.name } # Output mount commands (same format as Scenario 1) output "linux_mount_command" { value = <<-EOT sudo mkdir -p /mnt/azurefileshare sudo mount -t cifs //${data.azurerm_storage_account.example.name}.file.core.windows.net/${data.azurerm_storage_share.example.name} /mnt/azurefileshare -o username=${data.azurerm_storage_account.example.name},password=${data.azurerm_storage_account_primary_access_key.example.key},serverino,nosharesock,actimeo=30 EOT }
Key Notes
- Sensitive Data: The storage account access key is sensitive. If you don't want it visible in regular Terraform output, set
sensitive = trueon the output blocks. You can still retrieve it withterraform output -raw linux_mount_commandwhen needed. - Linux Prerequisite: For Linux systems, make sure the
cifs-utilspackage is installed first (runsudo apt-get install cifs-utilson Debian/Ubuntu orsudo yum install cifs-utilson RHEL/CentOS). - SAS Token Alternative: If you prefer using SAS tokens instead of account keys, you can generate them via the
azurerm_storage_account_sasdata source and adjust the mount command to use the token instead of the password.
内容的提问来源于stack exchange,提问作者doc_noob
相关产品推荐
相关产品推荐

