【发布时间】:2021-06-17 11:43:37
【问题描述】:
我尝试将策略分配给现有存储帐户的 Azure Key Vault。问题是找不到如何获取分配策略所需的帐户的 UUID(principal_id)。我试图为数据找到正确的属性,但它看起来对于数据对象不存在。那么问题是如何为现有存储帐户分配 Key Vault 访问策略?
resource "azurerm_key_vault_access_policy" "storage2" {
key_vault_id = azurerm_key_vault.keyvault.id
tenant_id = data.azurerm_client_config.current.tenant_id
object_id = data.azurerm_storage_account.example.identity.0.principal_id
key_permissions = ["get", "create", "list", "restore", "recover", "unwrapkey", "wrapkey", "purge", "encrypt", "decrypt", "sign", "verify"]
secret_permissions = ["get"]
}
【问题讨论】:
标签: azure azure-keyvault azure-storage-account azure-rm