You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

嵌套模板循环动态获取Key Vault密钥名实现多VM部署问题

解决ARM模板循环调用Key Vault不同密钥创建VM的问题

原代码存在的核心问题

  • JSON语法错误:
    • name字段末尾缺少逗号,导致JSON解析失败
    • concat函数内字符串拼接逻辑错误,原代码引号嵌套混乱且逗号位置错误,正确写法应为concat('DynamicSecret-', copyIndex('VMsLoop'))
  • 资源类型不符:原模板创建的是SQL Server(Microsoft.Sql/servers),而非需求中的VM(Microsoft.Compute/virtualMachines)
  • 循环索引引用:嵌套参数中copyIndex('VMsLoop')的作用域需确保能正确关联外层循环名称

修正后的完整模板

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "location": {
      "type": "string",
      "defaultValue": "[resourceGroup().location]",
      "metadata": {
        "description": "资源部署位置"
      }
    },
    "vaultName": {
      "type": "string",
      "metadata": {
        "description": "包含密钥的Key Vault名称"
      }
    },
    "secretPrefix": {
      "type": "string",
      "defaultValue": "Secrets",
      "metadata": {
        "description": "密钥名称前缀,最终密钥名为Secrets0-Secrets4"
      }
    },
    "vaultResourceGroupName": {
      "type": "string",
      "metadata": {
        "description": "Key Vault所在的资源组名称"
      }
    },
    "vaultSubscription": {
      "type": "string",
      "defaultValue": "[subscription().subscriptionId]",
      "metadata": {
        "description": "Key Vault所在的订阅ID"
      }
    },
    "vmSize": {
      "type": "string",
      "defaultValue": "Standard_D2s_v3",
      "metadata": {
        "description": "VM实例大小"
      }
    },
    "adminUsername": {
      "type": "string",
      "metadata": {
        "description": "VM管理员用户名"
      }
    },
    "virtualNetworkName": {
      "type": "string",
      "metadata": {
        "description": "现有虚拟网络名称"
      }
    },
    "subnetName": {
      "type": "string",
      "metadata": {
        "description": "现有子网名称"
      }
    }
  },
  "resources": [
    {
      "type": "Microsoft.Resources/deployments",
      "apiVersion": "2020-10-01",
      "name": "[concat('VMDeployment-', copyIndex('VMsLoop'))]",
      "copy": {
        "name": "VMsLoop",
        "count": 5,
        "mode": "Serial",
        "batchSize": 1
      },
      "properties": {
        "mode": "Incremental",
        "expressionEvaluationOptions": {
          "scope": "inner"
        },
        "template": {
          "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
          "contentVersion": "1.0.0.0",
          "parameters": {
            "location": {
              "type": "string"
            },
            "adminUsername": {
              "type": "string"
            },
            "adminPassword": {
              "type": "securestring"
            },
            "vmSize": {
              "type": "string"
            },
            "vmName": {
              "type": "string"
            },
            "vnetId": {
              "type": "string"
            },
            "subnetId": {
              "type": "string"
            }
          },
          "resources": [
            {
              "type": "Microsoft.Compute/virtualMachines",
              "apiVersion": "2023-07-01",
              "name": "[parameters('vmName')]",
              "location": "[parameters('location')]",
              "properties": {
                "hardwareProfile": {
                  "vmSize": "[parameters('vmSize')]"
                },
                "osProfile": {
                  "computerName": "[parameters('vmName')]",
                  "adminUsername": "[parameters('adminUsername')]",
                  "adminPassword": "[parameters('adminPassword')]"
                },
                "storageProfile": {
                  "imageReference": {
                    "publisher": "MicrosoftWindowsServer",
                    "offer": "WindowsServer",
                    "sku": "2022-Datacenter",
                    "version": "latest"
                  },
                  "osDisk": {
                    "caching": "ReadWrite",
                    "managedDisk": {
                      "storageAccountType": "Premium_LRS"
                    },
                    "name": "[concat(parameters('vmName'), '_OSDisk')]"
                  }
                },
                "networkProfile": {
                  "networkInterfaces": [
                    {
                      "id": "[resourceId('Microsoft.Network/networkInterfaces', concat(parameters('vmName'), '-nic'))]"
                    }
                  ]
                }
              }
            },
            {
              "type": "Microsoft.Network/networkInterfaces",
              "apiVersion": "2023-05-01",
              "name": "[concat(parameters('vmName'), '-nic')]",
              "location": "[parameters('location')]",
              "properties": {
                "ipConfigurations": [
                  {
                    "name": "ipconfig1",
                    "properties": {
                      "subnet": {
                        "id": "[parameters('subnetId')]"
                      },
                      "privateIPAllocationMethod": "Dynamic"
                    }
                  }
                ]
              },
              "dependsOn": []
            }
          ]
        },
        "parameters": {
          "location": {
            "value": "[parameters('location')]"
          },
          "adminUsername": {
            "value": "[parameters('adminUsername')]"
          },
          "adminPassword": {
            "reference": {
              "keyVault": {
                "id": "[resourceId(parameters('vaultSubscription'), parameters('vaultResourceGroupName'), 'Microsoft.KeyVault/vaults', parameters('vaultName'))]"
              },
              "secretName": "[concat(parameters('secretPrefix'), copyIndex('VMsLoop'))]"
            }
          },
          "vmSize": {
            "value": "[parameters('vmSize')]"
          },
          "vmName": {
            "value": "[concat('vm-', copyIndex('VMsLoop'))]"
          },
          "vnetId": {
            "value": "[resourceId('Microsoft.Network/virtualNetworks', parameters('virtualNetworkName'))]"
          },
          "subnetId": {
            "value": "[concat(resourceId('Microsoft.Network/virtualNetworks', parameters('virtualNetworkName')), '/subnets/', parameters('subnetName'))]"
          }
        }
      }
    }
  ],
  "outputs": {}
}

关键配置说明

  1. 循环逻辑:通过外层Microsoft.Resources/deployments的copy循环创建5次嵌套部署,每次循环使用copyIndex('VMsLoop')获取0-4的索引,拼接成对应的密钥名称(Secrets0-Secrets4)
  2. Key Vault引用:在嵌套部署的adminPassword参数中,通过reference方式动态获取对应索引的密钥,确保每台VM使用不同密码
  3. 资源依赖:模板包含VM和对应的网卡资源,确保网卡先于VM创建

前置条件

  • Key Vault已创建,且包含Secrets0至Secrets4共5个密钥
  • Key Vault已启用允许模板部署访问(在Key Vault的"访问配置"中设置)
  • 执行部署的主体拥有Key Vault的Secret/Get权限
  • 已存在可用的虚拟网络和子网

内容的提问来源于stack exchange,提问作者Korman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 16:05:48