You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform构建Azure Policy自定义seccomp模板报错如何解决

问题原因

两个报错的核心诱因是policy_rule中then.details的结构不符合Azure Kubernetes策略的参数传递规范:
所有自定义参数(比如你定义的excludedNamespaces)不能直接放在details根层级下,必须嵌套到values字段中才能被约束模板正确识别。你之前的写法导致服务端无法解析effect的details属性,触发第一个解析错误;调整字段时触发了参数未被引用的校验规则,才出现第二个参数未使用的报错。

修正方案

把policy_rule中的excludedNamespaces移动到details.values下即可,修正后的完整代码如下:

resource "azurerm_policy_definition" "k8s_seccomp_governance" {
  name         = "k8s_seccomp_governance"
  description  = "Kubernetes cluster containers should only use allowed seccomp profiles"
  policy_type  = "Custom"
  mode         = "All"
  display_name = "AMPS K8s Seccomp Governance"

  metadata = <<METADATA
{
  "category": "Kubernetes",
  "version": "1.0.0"
}
METADATA

  policy_rule = <<POLICY_RULE
{
  "if": {
    "field": "type",
    "in": [
      "AKS Engine",
      "Microsoft.Kubernetes/connectedClusters",
      "Microsoft.ContainerService/managedClusters"
    ]
  },
  "then": {
    "effect": "[parameters('effect')]",
    "details": {
      "constraintTemplate": "https://store.policy.core.windows.net/kubernetes/allowed-seccomp-profiles/v2/template.yaml",
      "constraint": "https://store.policy.core.windows.net/kubernetes/allowed-seccomp-profiles/v2/constraint.yaml",
      "values": {
        "excludedNamespaces": "[parameters('excludedNamespaces')]"
      }
    }
  }
}
POLICY_RULE

  parameters = <<PARAMETERS
{
  "effect": {
    "type": "String",
    "metadata": {
      "displayName": "Effect",
      "description": "'audit'允许非合规资源创建/更新但标记为非合规,'deny'阻止非合规资源创建/更新,'disabled'关闭策略。"
    },
    "allowedValues": ["audit", "deny","disabled"],
    "defaultValue": "audit"
  },
  "excludedNamespaces": {
    "type": "Array",
    "metadata": {
      "displayName": "排除的命名空间",
      "description": "策略评估时需要排除的Kubernetes命名空间列表"
    },
    "defaultValue": ["kube-system", "gatekeeper-system", "azure-arc"]
  }
}
PARAMETERS
}

注意事项

后续如果要添加更多策略参数(比如允许的seccomp配置文件列表allowedProfiles),都需要放在values字段下,不要直接挂载到details根层级。同时注意HEREDOC块中的JSON格式不要有多余的前导缩进,避免JSON解析异常。

内容的提问来源于stack exchange,提问作者Branden

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 23:27:03