使用Terraform创建Azure自定义策略集时遇listOfAllowedLocations参数缺失问题
问题:Terraform创建Azure自定义策略集时listOfAllowedLocations参数缺失错误
我正在编写代码通过代码应用CIS策略集来跟踪变更,目标是创建包含CIS Microsoft Azure Foundation Benchmark v1.4.0计划定义中策略的自定义策略集。使用Terraform的azurerm_policy_set_definition资源,但反复遇到listOfAllowedLocations相关问题。
现有代码
data "azurerm_management_group" "Standard" { display_name = "Standard" } resource "azurerm_policy_set_definition" "cis_benchmark" { name = var.cis_policy_name policy_type = "Custom" display_name = var.cis_display_name lifecycle { create_before_destroy = true } parameters = local.parameters metadata = local.metadata policy_definition_reference { policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e765b5de-1225-4ba3-bd56-1ac6695af988" parameter_values = <<VALUE { "allowedLocation": {"value": ["eastus"]} } VALUE } }
错误信息
Error: creating Policy Set Definition "CIS Benchmark v1.4.0": policy.SetDefinitionsClient#CreateOrUpdate: Failure responding to request: StatusCode=400 -- Original Error: autorest/azure: Service returned an error. Status=400 Code="MissingPolicyParameter" Message="The policy set definition 'CIS Benchmark v1.4.0' is missing the parameter(s) 'listOfAllowedLocations' as defined in the policy definition 'e765b5de-1225-4ba3-bd56-1ac6695af988'." │ │ with azurerm_policy_set_definition.cis_benchmark, │ on cisbenchmark.tf line 22, in resource "azurerm_policy_set_definition" "cis_benchmark": │ 22: resource "azurerm_policy_set_definition" "cis_benchmark" {
解决方案
核心问题
你在parameter_values中使用的参数名allowedLocation与目标策略定义要求的listOfAllowedLocations不匹配,导致参数缺失报错。
修正方案1:直接在引用中指定参数值
修改policy_definition_reference中的参数名称为正确的listOfAllowedLocations:
policy_definition_reference { policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e765b5de-1225-4ba3-bd56-1ac6695af988" parameter_values = <<VALUE { "listOfAllowedLocations": {"value": ["eastus"]} } VALUE }
修正方案2:从策略集层面传递参数(更灵活)
如果需要将参数配置提升到策略集级别,可先在local.parameters中声明该参数:
local { parameters = jsonencode({ listOfAllowedLocations = { type = "Array" metadata = { displayName = "Allowed Locations" description = "指定资源允许创建的区域列表" } } }) }
然后在策略引用中引用策略集的参数:
policy_definition_reference { policy_definition_id = "/providers/Microsoft.Authorization/policyDefinitions/e765b5de-1225-4ba3-bd56-1ac6695af988" parameter_values = <<VALUE { "listOfAllowedLocations": {"value": "[parameters('listOfAllowedLocations')]"} } VALUE }
内容的提问来源于stack exchange,提问作者bshah1976
相关产品推荐
相关产品推荐

