You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure Bicep创建跨资源组VNet Peering遇BCP165错误求助

解决Azure Bicep跨资源组VNet对等的BCP165错误

BCP165错误的核心原因是:不能在当前作用域的Bicep文件中直接创建其他资源组下的资源,必须通过模块并指定scope参数来实现跨资源组部署。针对你的双向VNet对等需求,拆分模块分别处理两个方向的 peering 即可解决问题。

解决方案步骤

1. 拆分Peering模块

创建两个独立的子模块,分别处理本地VNet到远程VNet、远程VNet到本地VNet的对等配置:

子模块1:local-to-remote-peering.bicep(本地RG的VNet对等)
param vnetId string
param remoteVnetId string
param peeringName string

resource localVnet 'Microsoft.Network/virtualNetworks@2023-09-01' existing = {
  id: vnetId
}

resource localToRemotePeering 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-09-01' = {
  parent: localVnet
  name: peeringName
  properties: {
    allowVirtualNetworkAccess: true
    allowForwardedTraffic: false
    allowGatewayTransit: false
    useRemoteGateway: false
    remoteVirtualNetwork: {
      id: remoteVnetId
    }
  }
}
子模块2:remote-to-local-peering.bicep(远程RG的VNet对等)
param remoteVnetId string
param localVnetId string
param peeringName string

resource remoteVnet 'Microsoft.Network/virtualNetworks@2023-09-01' existing = {
  id: remoteVnetId
}

resource remoteToLocalPeering 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-09-01' = {
  parent: remoteVnet
  name: peeringName
  properties: {
    allowVirtualNetworkAccess: true
    allowForwardedTraffic: false
    allowGatewayTransit: false
    useRemoteGateway: false
    remoteVirtualNetwork: {
      id: localVnetId
    }
  }
}

2. 修改主Peering模块

在原vnetpeering.bicep中调用上述两个子模块,为远程方向的模块指定APIM所在资源组的作用域:

metadata description = {
  description: 'This template configure vnet peerings between two vnets.'
}

param location string = resourceGroup().location
param vnetName string
param environment string
param application string = 'xxx-yyy'
param tags object
param vnetId string

var localToRemotePeering = '${application}-to-apim-peering-${environment}'
var remoteToLocalPeering = 'apim-to-${application}-peering-${environment}'
var apimResourceGroup = 'rg-rds-apim-${location}-${environment}'
var remoteVnetName = 'vnet-apim-eastus-${environment}'

// 引用APIM所在资源组的VNet
resource rdsVnet 'Microsoft.Network/virtualNetworks@2023-05-01' existing = {
  name: remoteVnetName
  scope: resourceGroup(apimResourceGroup)
}

// 部署本地VNet到远程VNet的对等(当前资源组)
module localPeering './local-to-remote-peering.bicep' = {
  name: 'local-to-remote-peering'
  params: {
    vnetId: vnetId
    remoteVnetId: rdsVnet.id
    peeringName: localToRemotePeering
  }
}

// 部署远程VNet到本地VNet的对等(指定APIM资源组作用域)
module remotePeering './remote-to-local-peering.bicep' = {
  name: 'remote-to-local-peering'
  scope: resourceGroup(apimResourceGroup)
  params: {
    remoteVnetId: rdsVnet.id
    localVnetId: vnetId
    peeringName: remoteToLocalPeering
  }
}

关键说明

  • 每个模块仅负责单一方向的对等配置,避免跨作用域资源创建冲突。
  • 远程方向的模块通过scope: resourceGroup(apimResourceGroup)明确指定部署目标资源组,符合Bicep的作用域规则。
  • 确保部署账号拥有两个资源组的网络资源写入权限,否则会出现权限报错。

内容的提问来源于stack exchange,提问作者Bheema

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 14:40:57