You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署Azure Windows VM时additional_unattend_content参数报错

Azure Terraform部署Windows VM时additionalUnattendContent.content无效的解决方案

问题根源

错误提示windowsConfiguration.additionalUnattendContent.content无效,通常由以下原因导致:

  • AutoLogon的XML片段结构不符合unattend.xml规范
  • 密码包含XML特殊字符(如<>&")未转义
  • 传递的XML字符串格式错误(如未闭合标签、转义错误)

修复步骤

1. 构造合规的AutoLogon XML片段

AutoLogon的XML必须符合Microsoft-Windows-Shell-Setup组件的配置要求,完整结构如下:

<AutoLogon>
  <Password>
    <Value>你的密码</Value>
    <PlainText>true</PlainText>
  </Password>
  <Enabled>true</Enabled>
  <LogonCount>3</LogonCount>
  <Username>管理员用户名</Username>
</AutoLogon>

其中<PlainText>true</PlainText>表示密码以明文传递(Azure会在VM内部加密存储),<LogonCount>设置自动登录的次数。

2. 转义密码中的特殊字符

若密码包含<>&"等XML特殊字符,必须转义为对应的XML实体,避免API解析失败。使用Terraform的replace函数批量处理:

locals {
  # 转义密码中的XML特殊字符
  escaped_admin_password = replace(
    replace(
      replace(
        replace(var.windows_password, "&", "&amp;"),
        "<", "&lt;"
      ),
      ">", "&gt;"
    ),
    "\"", "&quot;"
  )

  # 构造AutoLogon的XML内容
  auto_logon_content = <<-EOF
  <AutoLogon>
    <Password>
      <Value>${local.escaped_admin_password}</Value>
      <PlainText>true</PlainText>
    </Password>
    <Enabled>true</Enabled>
    <LogonCount>3</LogonCount>
    <Username>${var.windows_username}</Username>
  </AutoLogon>
  EOF
}

3. 修正Terraform VM配置

将additional_unattend_content部分替换为处理后的XML内容:

resource "azurerm_windows_virtual_machine" "wks_win10" {
  count                           = var.number_of_win10_wks
  depends_on                      = [azurerm_network_interface.wks_nic_win10]
  name                            = "wks-win10-${count.index}" 
  location                        = var.location
  resource_group_name             = var.rg_name
  size                            = var.vm_size
  provision_vm_agent              = true
  computer_name                   = "wks-win10-${count.index}"
  admin_username                  = var.windows_username
  admin_password                  = var.windows_password
  network_interface_ids           = [element(azurerm_network_interface.wks_nic_win10.*.id, count.index)]
  
  os_disk {
    caching                       = "ReadWrite"
    name                          = "wks-win10-osdisk-${count.index}"
    disk_size_gb                  = 250
    storage_account_type          = "StandardSSD_LRS"
  }
  
  source_image_reference {
    publisher = "MicrosoftWindowsDesktop"
    offer     = "Windows-10"
    sku       = "win10-21h2-ent"
    version   = "latest"
  }
  
  additional_unattend_content {
    setting = "AutoLogon"
    content = local.auto_logon_content
  }

  winrm_listener {
    protocol = "Http"
  }

  tags = merge(var.tags, {
    "kind" = "workstation"
    "os"   = "windows"
  })
}

4. 补充WinRM网络访问规则

确保VM关联的网络安全组(NSG)添加入站规则,允许5985端口(WinRM Http):

resource "azurerm_network_security_rule" "winrm_http" {
  name                        = "Allow-WinRM-Http"
  priority                    = 1001
  direction                   = "Inbound"
  access                      = "Allow"
  protocol                    = "Tcp"
  source_port_range           = "*"
  destination_port_range      = "5985"
  source_address_prefix       = "*" # 建议限制为特定IP段,提升安全性
  destination_address_prefix  = "*"
  resource_group_name         = var.rg_name
  network_security_group_name = azurerm_network_security_group.wks_nsg.name
}

验证方法

  1. 部署完成后,远程登录VM,确认是否自动登录到管理员账户
  2. 在本地PowerShell中执行以下命令,验证WinRM连通性:
Test-WSMan -ComputerName "VM公网IP或FQDN" -Port 5985

内容的提问来源于stack exchange,提问作者Michael

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 23:31:12