使用Terraform为Azure App Service配置多IP限制时动态调整优先级咨询
解决方案
方案1:自动按列表顺序生成递增优先级
如果只需要规则按列表顺序依次分配优先级,无需单独自定义,可通过index函数获取列表元素的下标计算优先级:
site_config { dynamic "ip_restriction" { for_each = var.ip_address_list content { ip_address = cidrhost(ip_restriction.value, 0) action = "Allow" priority = 100 + index(var.ip_address_list, ip_restriction.value) } } }
配置后列表第一个IP规则优先级为100,第二个为101,依次自动递增。注意:如果列表中有重复IP,index函数会出现匹配异常,该场景建议使用方案2。
方案2:自定义每个IP的优先级
如果需要灵活配置每个IP的差异化优先级,可将变量改为对象列表类型,每个元素单独指定IP和优先级:
variable "ip_address_list" { type = list(object({ ip_cidr = string priority = number })) default = [ { ip_cidr = "20.20.20.3/32" priority = 100 }, { ip_cidr = "10.10.10.2/32" priority = 200 } ] }
对应的dynamic块调整为:
site_config { dynamic "ip_restriction" { for_each = var.ip_address_list content { ip_address = cidrhost(ip_restriction.value.ip_cidr, 0) action = "Allow" priority = ip_restriction.value.priority } } }
该方案可完全满足任意优先级差异化配置需求。
内容的提问来源于stack exchange,提问作者Igor
相关产品推荐
相关产品推荐

