You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建Azure自定义策略集时遇listOfAllowedLocations参数缺失问题

问题:Terraform创建Azure自定义策略集时listOfAllowedLocations参数缺失错误

我正在编写代码通过代码应用CIS策略集来跟踪变更,目标是创建包含CIS Microsoft Azure Foundation Benchmark v1.4.0计划定义中策略的自定义策略集。使用Terraform的azurerm_policy_set_definition资源,但反复遇到listOfAllowedLocations相关问题。

现有代码

data "azurerm_management_group" "Standard" {
  display_name = "Standard"
}

resource "azurerm_policy_set_definition" "cis_benchmark" {
  name         = var.cis_policy_name
  policy_type  = "Custom"
  display_name = var.cis_display_name


  lifecycle {
    create_before_destroy = true
  }

  parameters = local.parameters
  metadata   = local.metadata

 policy_definition_reference {
    policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e765b5de-1225-4ba3-bd56-1ac6695af988"
    parameter_values     = <<VALUE
    {
      "allowedLocation": {"value": ["eastus"]}
    }
    VALUE
  }
}

错误信息

Error: creating Policy Set Definition "CIS Benchmark v1.4.0": policy.SetDefinitionsClient#CreateOrUpdate: Failure responding to request: StatusCode=400 -- Original Error: autorest/azure: Service returned an error. Status=400 Code="MissingPolicyParameter" Message="The policy set definition 'CIS Benchmark v1.4.0' is missing the parameter(s) 'listOfAllowedLocations' as defined in the policy definition 'e765b5de-1225-4ba3-bd56-1ac6695af988'."
│
│   with azurerm_policy_set_definition.cis_benchmark,
│   on cisbenchmark.tf line 22, in resource "azurerm_policy_set_definition" "cis_benchmark":
│   22: resource "azurerm_policy_set_definition" "cis_benchmark" {

解决方案

核心问题

你在parameter_values中使用的参数名allowedLocation与目标策略定义要求的listOfAllowedLocations不匹配,导致参数缺失报错。

修正方案1:直接在引用中指定参数值

修改policy_definition_reference中的参数名称为正确的listOfAllowedLocations:

policy_definition_reference {
    policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e765b5de-1225-4ba3-bd56-1ac6695af988"
    parameter_values     = <<VALUE
    {
      "listOfAllowedLocations": {"value": ["eastus"]}
    }
    VALUE
}

修正方案2:从策略集层面传递参数(更灵活)

如果需要将参数配置提升到策略集级别,可先在local.parameters中声明该参数:

local {
  parameters = jsonencode({
    listOfAllowedLocations = {
      type = "Array"
      metadata = {
        displayName = "Allowed Locations"
        description = "指定资源允许创建的区域列表"
      }
    }
  })
}

然后在策略引用中引用策略集的参数:

policy_definition_reference {
    policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e765b5de-1225-4ba3-bd56-1ac6695af988"
    parameter_values     = <<VALUE
    {
      "listOfAllowedLocations": {"value": "[parameters('listOfAllowedLocations')]"}
    }
    VALUE
}

内容的提问来源于stack exchange,提问作者bshah1976

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 13:05:29