使用Azure Bicep创建跨资源组VNet Peering遇BCP165错误求助
解决Azure Bicep跨资源组VNet对等的BCP165错误
BCP165错误的核心原因是:不能在当前作用域的Bicep文件中直接创建其他资源组下的资源,必须通过模块并指定scope参数来实现跨资源组部署。针对你的双向VNet对等需求,拆分模块分别处理两个方向的 peering 即可解决问题。
解决方案步骤
1. 拆分Peering模块
创建两个独立的子模块,分别处理本地VNet到远程VNet、远程VNet到本地VNet的对等配置:
子模块1:local-to-remote-peering.bicep(本地RG的VNet对等)
param vnetId string param remoteVnetId string param peeringName string resource localVnet 'Microsoft.Network/virtualNetworks@2023-09-01' existing = { id: vnetId } resource localToRemotePeering 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-09-01' = { parent: localVnet name: peeringName properties: { allowVirtualNetworkAccess: true allowForwardedTraffic: false allowGatewayTransit: false useRemoteGateway: false remoteVirtualNetwork: { id: remoteVnetId } } }
子模块2:remote-to-local-peering.bicep(远程RG的VNet对等)
param remoteVnetId string param localVnetId string param peeringName string resource remoteVnet 'Microsoft.Network/virtualNetworks@2023-09-01' existing = { id: remoteVnetId } resource remoteToLocalPeering 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-09-01' = { parent: remoteVnet name: peeringName properties: { allowVirtualNetworkAccess: true allowForwardedTraffic: false allowGatewayTransit: false useRemoteGateway: false remoteVirtualNetwork: { id: localVnetId } } }
2. 修改主Peering模块
在原vnetpeering.bicep中调用上述两个子模块,为远程方向的模块指定APIM所在资源组的作用域:
metadata description = { description: 'This template configure vnet peerings between two vnets.' } param location string = resourceGroup().location param vnetName string param environment string param application string = 'xxx-yyy' param tags object param vnetId string var localToRemotePeering = '${application}-to-apim-peering-${environment}' var remoteToLocalPeering = 'apim-to-${application}-peering-${environment}' var apimResourceGroup = 'rg-rds-apim-${location}-${environment}' var remoteVnetName = 'vnet-apim-eastus-${environment}' // 引用APIM所在资源组的VNet resource rdsVnet 'Microsoft.Network/virtualNetworks@2023-05-01' existing = { name: remoteVnetName scope: resourceGroup(apimResourceGroup) } // 部署本地VNet到远程VNet的对等(当前资源组) module localPeering './local-to-remote-peering.bicep' = { name: 'local-to-remote-peering' params: { vnetId: vnetId remoteVnetId: rdsVnet.id peeringName: localToRemotePeering } } // 部署远程VNet到本地VNet的对等(指定APIM资源组作用域) module remotePeering './remote-to-local-peering.bicep' = { name: 'remote-to-local-peering' scope: resourceGroup(apimResourceGroup) params: { remoteVnetId: rdsVnet.id localVnetId: vnetId peeringName: remoteToLocalPeering } }
关键说明
- 每个模块仅负责单一方向的对等配置,避免跨作用域资源创建冲突。
- 远程方向的模块通过
scope: resourceGroup(apimResourceGroup)明确指定部署目标资源组,符合Bicep的作用域规则。 - 确保部署账号拥有两个资源组的网络资源写入权限,否则会出现权限报错。
内容的提问来源于stack exchange,提问作者Bheema
相关产品推荐
相关产品推荐

