使用Terraform构建Azure Policy自定义seccomp模板报错如何解决
问题原因
两个报错的核心诱因是policy_rule中then.details的结构不符合Azure Kubernetes策略的参数传递规范:
所有自定义参数(比如你定义的excludedNamespaces)不能直接放在details根层级下,必须嵌套到values字段中才能被约束模板正确识别。你之前的写法导致服务端无法解析effect的details属性,触发第一个解析错误;调整字段时触发了参数未被引用的校验规则,才出现第二个参数未使用的报错。
修正方案
把policy_rule中的excludedNamespaces移动到details.values下即可,修正后的完整代码如下:
resource "azurerm_policy_definition" "k8s_seccomp_governance" { name = "k8s_seccomp_governance" description = "Kubernetes cluster containers should only use allowed seccomp profiles" policy_type = "Custom" mode = "All" display_name = "AMPS K8s Seccomp Governance" metadata = <<METADATA { "category": "Kubernetes", "version": "1.0.0" } METADATA policy_rule = <<POLICY_RULE { "if": { "field": "type", "in": [ "AKS Engine", "Microsoft.Kubernetes/connectedClusters", "Microsoft.ContainerService/managedClusters" ] }, "then": { "effect": "[parameters('effect')]", "details": { "constraintTemplate": "https://store.policy.core.windows.net/kubernetes/allowed-seccomp-profiles/v2/template.yaml", "constraint": "https://store.policy.core.windows.net/kubernetes/allowed-seccomp-profiles/v2/constraint.yaml", "values": { "excludedNamespaces": "[parameters('excludedNamespaces')]" } } } } POLICY_RULE parameters = <<PARAMETERS { "effect": { "type": "String", "metadata": { "displayName": "Effect", "description": "'audit'允许非合规资源创建/更新但标记为非合规,'deny'阻止非合规资源创建/更新,'disabled'关闭策略。" }, "allowedValues": ["audit", "deny","disabled"], "defaultValue": "audit" }, "excludedNamespaces": { "type": "Array", "metadata": { "displayName": "排除的命名空间", "description": "策略评估时需要排除的Kubernetes命名空间列表" }, "defaultValue": ["kube-system", "gatekeeper-system", "azure-arc"] } } PARAMETERS }
注意事项
后续如果要添加更多策略参数(比如允许的seccomp配置文件列表allowedProfiles),都需要放在values字段下,不要直接挂载到details根层级。同时注意HEREDOC块中的JSON格式不要有多余的前导缩进,避免JSON解析异常。
内容的提问来源于stack exchange,提问作者Branden
相关产品推荐
相关产品推荐

