Bicep创建Azure MCA订阅报InvalidSubCreationScope错误如何解决
错误原因及修正方案
- 模板语法错误
你的Bicep模板中name属性重复声明了标识符,当前写为name: name: guid(spokeSubscriptionName, tenant().tenantId),需要删掉多余的name:,修正为:
name: guid(spokeSubscriptionName, tenant().tenantId)
- 核心报错
InvalidSubCreationScope的根因
你使用的Microsoft Customer Agreement(MCA)类型计费账户,创建订阅时的计费范围不能仅到计费账户根层级,必须定位到**计费配置文件(Billing Profile)或发票科目(Invoice Section)**层级,你当前填写的/providers/Microsoft.Billing/billingAccounts/foo:bar不符合MCA的计费范围要求。
具体操作步骤
- 先执行命令获取你的计费账户下的计费配置文件完整ID:
返回结果中的az billing profile list --account-name <你之前获取的计费账户ID,即foo:bar> --query "[].{id:id, displayName:displayName}" -o tableid字段就是符合要求的计费范围路径,格式类似/providers/Microsoft.Billing/billingAccounts/foo:bar/billingProfiles/xxxxxx。 - 如果需要更细粒度的计费归属,可以继续获取发票科目ID,格式为
/providers/Microsoft.Billing/billingAccounts/foo:bar/billingProfiles/xxxxxx/invoiceSections/yyyyyy。 - 确认你的账号在对应计费配置文件/发票科目上拥有Azure订阅创建者计费权限,该权限和Azure租户根目录的Owner权限相互独立,缺少该权限也会触发范围无效报错。
修正后的完整模板示例
targetScope = 'tenant' var spokeSubscriptionName = 'Test Sub' resource spokeSubscription 'Microsoft.Subscription/aliases@2020-09-01' = { scope: tenant() name: guid(spokeSubscriptionName, tenant().tenantId) properties: { displayName: spokeSubscriptionName // 替换为你获取到的计费配置文件/发票科目完整路径 billingScope: '/providers/Microsoft.Billing/billingAccounts/foo:bar/billingProfiles/xxxxxx' workload: 'Production' } }
Bicep完全支持MCA类型计费账户创建订阅,不存在适配问题,完成上述修正后即可正常部署。
内容的提问来源于stack exchange,提问作者jamiecon
相关产品推荐
相关产品推荐

