azure - for 循环中的 Terraform for 循环

标签 azure loops for-loop terraform flatten

我的 terraform 模块中有以下 Azure AD 服务主体。

module "test_app" {
  source = "../../../../../my-adapplication/"
  app_owners     = ["<a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="f3819a989681b3979c9e929a9ddd909c9e" rel="noreferrer noopener nofollow">[email protected]</a>","<a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="c8b8a1aba9baac88aca7a5a9a1a6e6aba7a5" rel="noreferrer noopener nofollow">[email protected]</a>"]
  app_roles      = [
    {
      allowed_member_types = [
        "User"
      ]
      description = "Read access to Test app"
      display_name = "Test App Read"
      is_enabled   = true
      value        = "TestApp.Read"
      id           = random_uuid.test_app_read.result
    },
    {
      allowed_member_types = [
        "User"
      ]
      description = "Write access to Test app"
      display_name = "Test App Write"
      is_enabled   = true
      value        = "TestApp.Write"
      id           = random_uuid.test_app_write.result
    },
    {
      allowed_member_types = [
        "User"
      ]
      description = "Admin access to Test app"
      display_name = "Test App Admin"
      is_enabled   = true
      value        = "TestApp.Admin"
      id           = random_uuid.test_app_admin.result
    }
  ]

 


  app_role_assignments = [
    {
       app_role_id        = random_uuid.test_app_read.result #"TestApp.Read"
       principal_object_id = data.azuread_group.group_role_read.object_id 
    },
    {
       app_role_id        = random_uuid.test_app_write.result #"TestApp.Write"
       principal_object_id = data.azuread_group.group_role_write.object_id
    },
    {
       app_role_id        = random_uuid.test_app_admin.result #"TestApp.Admin"
       principal_object_id = data.azuread_group.group_role_write.object_id
    }
  ]
   

}

resource "random_uuid" "test_app_read" {
}

resource "random_uuid" "test_app_write" {
}

resource "random_uuid" "test_app_admin" {
}

data "azuread_group" "group_role_read" {
  display_name = "group-role-read"
}

data "azuread_group" "group2_role_read" {
  display_name = "group2-role-read"
}

data "azuread_group" "group_role_write" {
  display_name = "group-role-write"
}

data "azuread_group" "group_role_admin" {
  display_name = "group-role-admin"
}

my-adapplication 模块文件如下所示:

resource "azuread_application" "app" {
  ...
  ...
  dynamic "app_role" {
    for_each = var.app_roles
    content {
      id                   = app_role.value["id"]
      allowed_member_types = app_role.value["allowed_member_types"]
      description          = app_role.value["description"]
      display_name         = app_role.value["display_name"]
      enabled              = app_role.value["is_enabled"]
      value                = app_role.value["value"]
    }
  }
}

resource "azuread_service_principal" "sp" {
  application_id               = azuread_application.app.application_id
}


resource "azuread_app_role_assignment" "role" {
  for_each            = { for a in var.app_role_assignments : a.app_role_id => a }
  app_role_id         = each.value["app_role_id"]
  principal_object_id = each.value["principal_object_id"]
  resource_object_id  = azuread_service_principal.sp.object_id


}

我遇到的问题与 app_role_assignments 有关。如果我只传入一个 principal_object_id ,它就可以工作。但是,如果我传入多个principal_object_id,它就不起作用。例如下面的 TestApp.Read:

app_role_assignments = [
    {
       app_role_id        = random_uuid.test_app_read.result #"TestApp.Read"
       principal_object_id = [data.azuread_group.group_role_read.object_id,data.azuread_group.group2_role_read.object_id]
    },
    {
       app_role_id        = random_uuid.test_app_write.result #"TestApp.Write"
       principal_object_id = data.azuread_group.group_role_write.object_id
    },
    {
       app_role_id        = random_uuid.test_app_admin.result #"TestApp.Admin"
       principal_object_id = data.azuread_group.group_role_write.object_id
    }
  ]

收到的错误是:

Error: Incorrect attribute value type
│ 
│   on .terraform/modules/test_app/main.tf line 116, in resource "azuread_app_role_assignment" "role":
│  116:   principal_object_id = each.value["principal_object_id"]
│     ├────────────────
│     │ each.value["principal_object_id"] is tuple with 2 elements
│ 
│ Inappropriate value for attribute "principal_object_id": string required.
╵

如何让 terraform 循环遍历此 principal_object_id 列表?我想我是在循环内循环。有没有比我上面的方法更好的方法?

是否可以使用for_each来做到这一点,这样如果我使用count/for,我就不会遇到列表顺序更改的问题.

提前非常感谢。

最佳答案

您必须重新组织您的app_role_assignments,然后扁平化它。如果您希望 principal_object_id 具有多个值,则它应该始终是一个列表,即使对于单个元素也是如此:

app_role_assignments = [
    {
       app_role_id        = random_uuid.test_app_read.result #"TestApp.Read"
       principal_object_id = [data.azuread_group.group_role_read.object_id,data.azuread_group.group2_role_read.object_id]
    },
    {
       app_role_id        = random_uuid.test_app_write.result #"TestApp.Write"
       principal_object_id = [data.azuread_group.group_role_write.object_id]
    },
    {
       app_role_id        = random_uuid.test_app_admin.result #"TestApp.Admin"
       principal_object_id = [data.azuread_group.group_role_write.object_id]
    }
  ]

然后你可以压平如下:

locals {
  app_role_assignments_flat = merge([
      for val in var.app_role_assignments: {
        for principal_object_id in val["principal_object_id"]: 
            "${val.app_role_id}-${principal_object_id}" => {
                app_role_id = val.app_role_id
                principal_object_id = principal_object_id
          }
      }
    ]...) # please do NOT remove the dots
}

然后

resource "azuread_app_role_assignment" "role" {
  for_each            = local.app_role_assignments_flat
  app_role_id         = each.value["app_role_id"]
  principal_object_id = each.value["principal_object_id"]
  resource_object_id  = azuread_service_principal.sp.object_id
}

关于azure - for 循环中的 Terraform for 循环,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/71425779/

相关文章:

azure - rbac 角色在 azure 中可以如何嵌套?特别是使用 ADLS GEN2 存储容器的存储帐户?

.net - Azure 服务总线主题中的基础 IOException

r - 通过随机样本增加加权平均值

javascript - 尝试在对象中使用带有 if else 语句的 for 循环

Azure AD 与 Azure AD B2C 与 Azure AD B2B

java Clip 循环不工作

javascript - for循环不会进入,不知道为什么

python - 单独使用 while 循环的素数生成器的逻辑错误

ruby-on-rails - 更新嵌套哈希参数。更新 Action ,ruby on rails

azure - 我已通过身份验证,但 "Please sign up before you can sign in"