You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置Azure PostgreSQL Flexible Server角色报错求助

解决Azure PostgreSQL Flexible Server Terraform角色权限配置报错问题

问题背景

已通过Terraform部署Azure PostgreSQL Flexible Server(PaaS服务),尝试用Terraform创建数据库角色并分配对应权限时,触发Provider查询报错。

报错信息

Error: Failed to query available provider packages

Could not retrieve the list of available versions for provider hashicorp/postgresql: provider registry registry.terraform.io does not have a provider named registry.terraform.io/hashicorp/postgresql
Did you intend to use cyrilgdn/postgresql? If so, you must specify that source address in each module which requires that provider. To see which modules are currently depending on hashicorp/postgresql, run the following command:
terraform provider

报错原因

  1. 官方hashicorp/postgresql Provider已停止维护,当前主流使用社区维护的cyrilgdn/postgresql
  2. 配置中存在隐性引用hashicorp/postgresql的模块/资源,或Provider连接参数不符合Azure PostgreSQL的要求
  3. Azure PostgreSQL Flexible Server的连接用户名格式、Host地址配置错误

修正后的完整Terraform配置

1. 核心Provider配置

terraform {
  required_version = ">= 1.1.6"
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = ">=3.20.0"
    }

    postgresql = { 
      source  = "cyrilgdn/postgresql"
      version = "1.15.0"
      # 若有子模块引用该Provider,需添加configuration_aliases或在模块内指定source
      # configuration_aliases = [postgresql.default]
    }
  }
}

# Azure Provider基础配置(若未配置需补充)
provider "azurerm" {
  features {}
}

# PostgreSQL Provider连接配置(适配Azure Flexible Server)
provider "postgresql" {
  # 引用服务器的FQDN,需从模块输出中提取对应属性
  host            = module.az_pssql_flex.fqdn
  port            = 5432
  # 连接默认postgres数据库即可,后续针对目标数据库分配权限
  database        = "postgres"
  # Azure PostgreSQL管理员用户名格式:<admin账号>@<服务器名称>
  username        = "${var.admin_username}@${module.az_pssql_flex.name}"
  password        = var.admin_password
  sslmode         = "require"
  connect_timeout = 120
  # Azure PostgreSQL管理员无超级用户权限,必须设为false
  superuser       = false
}

2. 角色创建与权限分配示例

# 创建只读角色
resource "postgresql_role" "readonly" {
  name     = "readonly_user"
  login    = true
  password = var.readonly_password
}

# 给只读角色分配指定数据库的表查询权限
resource "postgresql_grant" "readonly_access" {
  database    = var.target_database
  role        = postgresql_role.readonly.name
  schema      = "public"
  privileges  = ["SELECT"]
  object_type = "table"
}

# 创建读写角色
resource "postgresql_role" "readwrite" {
  name     = "readwrite_user"
  login    = true
  password = var.readwrite_password
}

# 给读写角色分配指定数据库的增删改查权限
resource "postgresql_grant" "readwrite_access" {
  database    = var.target_database
  role        = postgresql_role.readwrite.name
  schema      = "public"
  privileges  = ["SELECT", "INSERT", "UPDATE", "DELETE"]
  object_type = "table"
}

关键注意事项

  • 检查所有使用PostgreSQL Provider的子模块,确保模块内的required_providers也指定source = "cyrilgdn/postgresql",避免隐性引用废弃的官方Provider
  • 确保Terraform运行环境的IP已加入Azure PostgreSQL Flexible Server的防火墙白名单,否则无法建立连接
  • 角色密码需符合Azure PostgreSQL的复杂度要求(至少8字符,包含大小写字母、数字、特殊字符)

内容的提问来源于stack exchange,提问作者Ikteaja hsan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 01:36:01