如何通过Terraform实现现有Azure存储账户Blob的ACL自动化创建与修改?
基于Terraform管理Azure ADLS Gen2存储账户Blob及ACL解决方案
操作前置要求:使用3.0及以上版本的AzureRM Terraform Provider,该版本对ADLS Gen2的ACL相关资源支持已稳定
1. 读取现有存储账户及已存资源信息
通过Terraform的data源即可直接读取已有存储账户、容器、Blob的信息,该操作不会改动原有存储账户内的任何资源、访问策略和数据,示例代码如下:
# 读取现有ADLS Gen2存储账户信息 data "azurerm_storage_account" "existing_adls" { name = "你的现有存储账户名称" resource_group_name = "存储账户所属资源组名称" } # 读取存储账户下已有的容器信息 data "azurerm_storage_container" "existing_container" { name = "目标容器名称" storage_account_name = data.azurerm_storage_account.existing_adls.name } # 读取需要修改ACL的现有Blob信息(按需配置) data "azurerm_storage_blob" "existing_blob" { name = "目标现有Blob名称" storage_account_name = data.azurerm_storage_account.existing_adls.name storage_container_name = data.azurerm_storage_container.existing_container.name }
2. 创建新Blob并分配服务主体ACL
先创建新的Blob资源,再通过azurerm_storage_data_lake_gen2_path资源(专门用于管理ADLS Gen2分层命名空间下的路径、文件及对应ACL)为指定服务主体配置权限,示例代码如下:
# 在目标容器内创建新Blob resource "azurerm_storage_blob" "new_blob" { name = "新建Blob的名称" storage_account_name = data.azurerm_storage_account.existing_adls.name storage_container_name = data.azurerm_storage_container.existing_container.name type = "Block" # 可以通过source参数指定本地文件路径上传,也可以通过content参数直接写入文本内容 source = "./本地待上传文件路径" } # 为新Blob配置多服务主体的ACL权限 resource "azurerm_storage_data_lake_gen2_path" "new_blob_acl" { path = azurerm_storage_blob.new_blob.name file_system_name = data.azurerm_storage_container.existing_container.name storage_account_id = data.azurerm_storage_account.existing_adls.id resource = "file" # 若配置的是文件夹权限,此处填directory # 配置第一个服务主体的读权限 ace { scope = "access" type = "user" id = "第一个服务主体的Object ID" permissions = "r" } # 配置第二个服务主体的读写权限 ace { scope = "access" type = "user" id = "第二个服务主体的Object ID" permissions = "rw" } # 保留系统默认mask配置,避免覆盖存储账户原有默认权限 ace { scope = "access" type = "mask" permissions = "rwx" } }
权限字段说明:读对应r、写对应w、执行对应x,多权限直接拼接即可,例如读写执行权限为rwx
3. 修改现有Blob的ACL
直接通过azurerm_storage_data_lake_gen2_path关联已有Blob路径即可调整ACL,该操作仅修改权限配置,不会改动Blob本身的内容,示例代码如下:
# 修改目标现有Blob的ACL resource "azurerm_storage_data_lake_gen2_path" "existing_blob_acl" { path = data.azurerm_storage_blob.existing_blob.name file_system_name = data.azurerm_storage_container.existing_container.name storage_account_id = data.azurerm_storage_account.existing_adls.id resource = "file" # 新增/修改指定服务主体的读写权限 ace { scope = "access" type = "user" id = "目标服务主体的Object ID" permissions = "rw" } # 需要移除某服务主体的权限,直接删除对应的ace块即可 ace { scope = "access" type = "mask" permissions = "rwx" } }
注意:正式执行配置前建议先运行terraform plan查看变更清单,确认仅会修改你预期调整的ACL配置,不会影响现有Blob数据和其他原有配置
内容的提问来源于stack exchange,提问作者Vowneee
相关产品推荐
相关产品推荐

