You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Terraform获取Azure Synapse Workspace的系统分配标识?

获取Azure Synapse Workspace系统分配托管标识的Terraform方法

你的Terraform代码已经正确配置了Synapse Workspace的系统分配托管标识(通过identity { type = "SystemAssigned" }块),要获取这个标识的相关信息,直接通过资源对象的identity属性引用即可:

  • 获取主体ID(Principal ID):azurerm_synapse_workspace.synapsews.identity[0].principal_id
  • 获取租户ID(Tenant ID):azurerm_synapse_workspace.synapsews.identity[0].tenant_id

示例用法

比如要将这个标识赋予存储账户的权限,可以这样写:

resource "azurerm_role_assignment" "synapse_storage_access" {
  scope                = azurerm_storage_account.datalake.id
  role_definition_name = "Storage Blob Data Contributor"
  principal_id         = azurerm_synapse_workspace.synapsews.identity[0].principal_id
}

说明

  • 因为identity是列表类型(即使仅配置了一个系统分配标识),所以需要用[0]索引访问其内部属性
  • 部署完成后,Terraform会自动从Azure同步这些标识属性,无需额外配置

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 23:45:42