使用Terraform创建无公网访问的Azure Storage Gen2账户遇403错误
问题描述
需要通过Terraform创建无公网访问的Azure Storage Account Gen2,要求仅允许Private Link访问,配置了allow_nested_items_to_be_public = false和public_network_access_enabled = false,但执行时创建文件系统出现403错误:
│ Error: checking for existence of existing File System "rawdata" (Account "formuleinsstorage"): datalakestore.Client#GetProperties: Failure responding to request: StatusCode=403 -- Original Error: autorest/azure: error response cannot be parsed: {"" '\x00' '\x00'} error: EOF │ │ with module.storage_account.azurerm_storage_data_lake_gen2_filesystem.data_lake_storage, │ on modules\storage-account\storage_account.tf line 14, in resource "azurerm_storage_data_lake_gen2_filesystem" "data_lake_storage": │ 14: resource "azurerm_storage_data_lake_gen2_filesystem" "data_lake_storage" { │ ╵ ╷ │ Error: checking for existence of existing File System "processeddata" (Account "formuleinsstorage"): datalakestore.Client#GetProperties: Failure responding to request: StatusCode=403 -- Original Error: autorest/azure: error response cannot be parsed: {"" '\x00' '\x00'} error: EOF │ │ with module.storage_account.azurerm_storage_data_lake_gen2_filesystem.processed_data_storage, │ on modules\storage-account\storage_account.tf line 19, in resource "azurerm_storage_data_lake_gen2_filesystem" "processed_data_storage": │ 19: resource "azurerm_storage_data_lake_gen2_filesystem" "processed_data_storage" {
错误原因
当public_network_access_enabled = false时,Terraform运行环境(本地/CI机器)无法通过公网访问存储账户,而默认情况下Azurerm Provider会尝试通过公网验证文件系统的存在性,因此被存储账户拒绝,返回403。
同时原配置中is_hns_enabled设置为字符串"true",不符合Terraform Azurerm Provider的参数要求(应为布尔值true),这也是潜在的配置问题。
解决方法
方法一:临时开启公网访问完成资源创建
- 修改存储账户资源,将
public_network_access_enabled改为true:
resource "azurerm_storage_account" "storage_account" { # 其他参数保持不变 public_network_access_enabled = true }
- 执行
terraform apply,完成存储账户和文件系统的创建。 - 将
public_network_access_enabled改回false,再次执行terraform apply关闭公网访问。
方法二:配置Provider通过存储账户密钥访问(无需临时开启公网)
修改代码,为文件系统资源指定存储账户访问密钥,让Terraform直接通过密钥验证资源,无需依赖公网访问:
resource "azurerm_storage_account" "storage_account" { name = var.storage_account_name resource_group_name = var.resource_group_name location = var.resource_group_location account_tier = "Standard" account_replication_type = "LRS" account_kind = "StorageV2" is_hns_enabled = true # 修正为布尔值 allow_nested_items_to_be_public = false public_network_access_enabled = false } resource "azurerm_storage_data_lake_gen2_filesystem" "data_lake_storage" { name = "rawdata" storage_account_id = azurerm_storage_account.storage_account.id account_key = azurerm_storage_account.storage_account.primary_access_key # 添加账户密钥参数 } resource "azurerm_storage_data_lake_gen2_filesystem" "processed_data_storage" { name = "processeddata" storage_account_id = azurerm_storage_account.storage_account.id account_key = azurerm_storage_account.storage_account.primary_access_key # 添加账户密钥参数 }
执行terraform apply即可完成创建,此方法无需临时开启公网访问。
方法三:通过Private Link访问(适用于Terraform运行环境在Azure VNet内)
如果Terraform运行环境部署在Azure VNet中,可提前为存储账户创建Private Endpoint,并确保VNet与Private Endpoint关联。此时Azurerm Provider会自动通过Private Link访问存储账户,无需额外配置密钥或临时开启公网。
内容的提问来源于stack exchange,提问作者Jeff
相关产品推荐
相关产品推荐

