求助:通过Terraform部署SentinelOne LinuxExtension的配置方法
通过Terraform部署SentinelOne Azure VM扩展的解决方案
不少用户已经成功通过Terraform部署SentinelOne代理,核心是正确配置settings和protected_settings块,以下是具体实现细节:
完整Terraform配置示例
修正原代码的命名问题,并补充必填配置块:
resource "azurerm_virtual_machine_extension" "sentinelone_agent" { name = "sentinelone-agent" virtual_machine_id = azurerm_virtual_machine.example.id publisher = "SentinelOne.LinuxExtension" type = "LinuxExtension" type_handler_version = "1.0" # 非敏感配置项 settings = jsonencode({ TenantId = "你的SentinelOne租户ID" # 可选:指定目标站点ID(若需分配到特定站点) # SiteId = "你的站点ID" }) # 敏感配置项(会被Azure加密存储) protected_settings = jsonencode({ Token = "你的SentinelOne部署令牌" }) }
关键配置字段说明
- TenantId:从SentinelOne管理控制台获取,对应你的租户唯一标识
- Token:SentinelOne的部署令牌,用于代理注册认证,需从控制台的代理部署页面复制(属于敏感信息,必须放在
protected_settings中) - SiteId(可选):如果需要将代理分配到特定站点,添加该字段并填入对应站点ID
额外注意事项
- 若部署Windows代理,只需将
publisher改为SentinelOne.WindowsExtension,type改为WindowsExtension,配置字段与Linux一致 - 确保目标VM的网络可以访问SentinelOne云端服务端点(如
*.sentinelone.net),否则代理无法完成注册
内容的提问来源于stack exchange,提问作者Tfair
相关产品推荐
相关产品推荐

