Terraform结合lookup与splat语法:多Azure VM的MSI身份ID获取问题
解决Terraform部署多台带系统分配MSI的Azure VM及关联扩展的问题
刚好我之前处理过类似的场景,给你梳理下怎么调整代码来实现多台带系统分配MSI的Azure VM部署,同时搞定对应的VM扩展关联:
1. 修正虚拟机资源的配置
首先你原来的代码里有两个小问题:count参数得是数字类型(不能用字符串"5"),而且虚拟机名称必须唯一,不然部署会失败。调整后的VM资源代码如下:
resource "azurerm_virtual_machine" "virtual_machine" { count = 5 # 这里改成数字,去掉引号 name = "test-${count.index}" # 给每台VM加索引后缀,确保名称唯一 location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name vm_size = "Standard_D2s_v3" # 以下是其他必填配置,根据你的实际情况补全 storage_os_disk { name = "osdisk-${count.index}" caching = "ReadWrite" create_option = "FromImage" managed_disk_type = "Premium_LRS" } storage_image_reference { publisher = "MicrosoftWindowsServer" offer = "WindowsServer" sku = "2019-Datacenter" version = "latest" } os_profile { computer_name = "test-vm-${count.index}" admin_username = "adminuser" admin_password = "P@ssw0rd1234!" } os_profile_windows_config { enable_automatic_upgrades = true provision_vm_agent = true } network_interface_ids = [azurerm_network_interface.example[count.index].id] # 系统分配MSI的配置,这个部分你原来的是对的 identity { type = "SystemAssigned" } }
2. 关联对应的虚拟机扩展
要给每台VM绑定对应的扩展,只需要把扩展的count和VM的count保持一致,然后通过count.index关联到对应的VM。如果是Windows VM,用ManagedIdentityExtensionForWindows,Linux的话换成ManagedIdentityExtensionForLinux:
resource "azurerm_virtual_machine_extension" "virtual_machine_extension" { count = azurerm_virtual_machine.virtual_machine.count # 和VM数量自动同步 name = "msi-extension-${count.index}" virtual_machine_id = azurerm_virtual_machine.virtual_machine[count.index].id publisher = "Microsoft.ManagedIdentity" type = "ManagedIdentityExtensionForWindows" # Linux替换为ManagedIdentityExtensionForLinux type_handler_version = "1.0" settings = jsonencode({ port = 50342 # MSI扩展默认监听端口 }) }
3. 获取每台VM的MSI身份ID
如果需要输出或者在其他资源中引用MSI的身份ID(也就是principal ID),可以添加一个output块,用循环遍历所有VM的identity信息:
output "all_vm_msi_principal_ids" { type = list(string) description = "Principal IDs of the system-assigned MSIs for each VM" value = [for vm in azurerm_virtual_machine.virtual_machine : vm.identity[0].principal_id] }
执行terraform apply之后,你就能在输出里看到每台VM对应的MSI身份ID了。
几个关键注意点
- count参数必须是数字类型:不能写成
count = "5",Terraform会报错 - 资源名称必须唯一:不管是VM、磁盘还是扩展,都要通过
count.index来区分名称,避免冲突 - 扩展与VM一一对应:一定要用
count.index关联到对应的VM ID,不然扩展会随机绑定VM,或者部署失败
内容的提问来源于stack exchange,提问作者user1198049
相关产品推荐
相关产品推荐

