使用Terraform配置Azure AD应用注册时Application ID URI报错问询
报错原因说明
该报错是新版Azure AD Provider(v2.0及以上版本)的校验规则变更导致的。
旧版Provider以及Azure门户手动配置时,对应用ID URI的格式校验宽松,允许直接使用非租户验证域名的HTTPS地址;但新版Provider对齐了Azure AD的底层API限制:自定义应用ID URI的域名部分必须是当前Azure AD租户下已完成所有权验证的自定义域名,azurewebsites.net属于Azure官方托管的公共域名,无法在个人租户下完成验证,因此触发配置报错。
「Expose an API」板块正确配置方案
方案1(推荐,无额外前置操作)
使用Azure AD默认的应用ID URI格式api://<应用注册客户端ID>,无需域名验证即可直接配置,对应的Terraform示例代码如下:
# 生成作用域唯一ID resource "random_uuid" "api_user_impersonation_scope" {} resource "azuread_application" "coalsa_api" { display_name = "Coalsa-API-App" # 配置默认格式的应用ID URI identifier_uris = ["api://${azuread_application.coalsa_api.client_id}"] # 配置暴露的API作用域 api { oauth2_permission_scope { admin_consent_description = "Allow full access to the Coalsa API" admin_consent_display_name = "Full access to Coalsa API" enabled = true id = random_uuid.api_user_impersonation_scope.result type = "User" user_consent_description = "Allow the application to access Coalsa API on your behalf" user_consent_display_name = "Access Coalsa API" value = "user_impersonation" } } }
方案2(适配自定义HTTPS URI需求)
如果业务必须使用HTTPS格式的应用ID URI,需要先完成以下前置操作再配置Terraform:
- 进入Azure AD租户的「自定义域名」板块,添加你要使用的URI对应的根域名(例如要使用
https://api.your-custom-domain.com,就添加your-custom-domain.com) - 按照Azure提示在你的域名解析服务商添加对应的TXT验证记录,完成域名所有权验证
- 再在Terraform的
identifier_uris参数中填写你的HTTPS格式URI即可通过校验。
临时兼容方案(不推荐长期使用)
如果需要对齐之前手动配置的https://app-coalsa-api.azurewebsites.net格式URI,可以将Azure AD Provider版本降级到1.6.0之前的版本,跳过新版校验规则,旧版本不再提供功能更新和安全补丁,仅可作为临时过渡使用。
内容的提问来源于stack exchange,提问作者Pallab
相关产品推荐
相关产品推荐

