You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform构建Azure磁盘加密KeyEncryptionKeyURL失败求助

解决Azure磁盘加密扩展KeyEncryptionKeyURL获取问题

核心解决方案

直接使用Terraform azurerm_key_vault_key 资源内置的 key_uri_with_version 属性,它会直接返回包含版本号的密钥完整URL,无需手动拼接。

修正后的代码

将你当前settings块中的KeyEncryptionKeyURL行替换为以下内容:

"KeyEncryptionKeyURL": "${azurerm_key_vault_key.ade_key[count.index].key_uri_with_version}",

完整修正后的ext_ade资源示例:

resource "azurerm_virtual_machine_extension" "ext_ade" {
    depends_on = [azurerm_virtual_machine_extension.ext_domain_join, azurerm_virtual_machine_extension.ext_dsc]
    count = var.session_hosts.quantity
    name =  var.ext_ade.name
    virtual_machine_id = azurerm_windows_virtual_machine.vm.*.id[count.index]
    publisher = "Microsoft.Azure.Security"
    type = "AzureDiskEncryption"
    type_handler_version = "2.2"
    auto_upgrade_minor_version = true

    settings = <<SETTINGS
    {
        "EncryptionOperation": "EnableEncryption",
        "KeyVaultURL": "${data.azurerm_key_vault.key_vault.vault_uri}",
        "KeyVaultResourceId": "${data.azurerm_key_vault.key_vault.id}",
        "KeyEncryptionKeyURL": "${azurerm_key_vault_key.ade_key[count.index].key_uri_with_version}",
        "KeyEncryptionAlgorithm": "RSA-OAEP",
        "VolumeType": "All"
    }
    SETTINGS

    lifecycle {
      ignore_changes = [settings]
    }
}

补充说明

  1. 手动拼接失败通常是因为忽略了密钥保管库URI末尾的斜杠差异,或是版本号的格式问题,官方内置属性已经处理了这些细节,能避免手动拼接的错误。
  2. 原代码中重复了KeyVaultResourceId字段,修正版已移除重复项,不影响功能但更规范。

内容的提问来源于stack exchange,提问作者Jon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 09:05:24