Terraform 可讓您定義、預覽和部署雲端基礎結構。 使用 Terraform 時,你可以用 HCL 語法建立設定檔。 HCL 語法可讓您指定雲端提供者 (例如 Azure) 和構成雲端基礎結構的元素。 建立組態檔之後,您會建立一個 執行計劃 ,讓您在部署基礎結構變更之前先預覽這些變更。 驗證變更之後,您可以套用執行計畫來部署基礎結構。
使用 azapi_resource_action 作為受管理的 Terraform 資源,對Azure資源執行命令式的狀態變更操作。 在這個例子中,你建立一個 Azure 儲存帳號,然後輪換它的存取金鑰。
azapi_resource_action 有兩種用法形式:
-
資源:在 期間
terraform apply執行狀態變更操作。 Terraform 會追蹤狀態中的動作,並可選擇性地在terraform destroy上反轉它。 - 資料來源:在規劃過程中執行唯讀操作。 請參閱 資源操作資料來源快速入門 以了解該情境。
當你需要 Terraform 執行非基於標準建立/讀取/更新/刪除生命週期的 Azure 操作時,請使用資源表單——例如輪換憑證、啟動或停止虛擬機,或觸發故障轉移。
- 在 AzureRM 供應商建立一個儲存帳號
- 將儲存帳號存取金鑰旋轉為
azapi_resource_action
先決條件
- Azure 訂用帳戶:如果您沒有 Azure 訂用帳戶,請在開始前建立免費帳戶。
設定 Terraform:如果您尚未這麼做,請使用下列其中一個選項來設定 Terraform:
當您使用Microsoft帳戶登入 Azure 入口網站時,會使用該帳戶的預設 Azure 訂用帳戶。
Terraform 會自動使用預設 Azure 訂用帳戶中的資訊進行驗證。
執行 az account show 以確認目前的Microsoft帳戶和 Azure 訂用帳戶。
az account show
您透過 Terraform 所做的任何變更都會顯示在顯示的 Azure 訂用帳戶上。 如果是您想要的,請略過本文的其餘部分。
實作 Terraform 程式碼
建立目錄,然後在目錄中測試範例 Terraform 程式碼,並將其設為目前的目錄。
建立名為
providers.tf的檔案,並插入下列程式碼:terraform { required_providers { azapi = { source = "Azure/azapi" version = "~> 2.0" } azurerm = { source = "hashicorp/azurerm" version = "~> 4.0" } random = { source = "hashicorp/random" version = "~> 3.0" } } } provider "azurerm" { features {} } provider "azapi" {}建立名為
variables.tf的檔案,並插入下列程式碼:variable "resource_group_location" { type = string default = "eastus" description = "Location of the resource group." } variable "resource_group_name_prefix" { type = string default = "rg" description = "Prefix of the resource group name that's combined with a random value to create a unique name." } variable "storage_account_name_prefix" { type = string default = "st" description = "Prefix of the storage account name that's combined with a random value to create a unique name." }建立名為
main.tf的檔案,並插入下列程式碼:resource "random_pet" "rg_name" { prefix = var.resource_group_name_prefix } resource "random_string" "storage_suffix" { length = 8 upper = false special = false } resource "azurerm_resource_group" "example" { location = var.resource_group_location name = random_pet.rg_name.id } resource "azurerm_storage_account" "example" { name = "${var.storage_account_name_prefix}${random_string.storage_suffix.result}" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location account_tier = "Standard" account_replication_type = "LRS" } resource "azapi_resource_action" "regenerate_key" { type = "Microsoft.Storage/storageAccounts@2023-01-01" resource_id = azurerm_storage_account.example.id action = "regenerateKey" method = "POST" body = { keyName = "key1" } }關於使用
azapi_resource_action作為資源的關鍵點:- 欄位
action指定要執行的 ARM 操作。 儲存帳戶金鑰輪換時,請使用regenerateKey。 - 欄位
method指定 HTTP 方法。 大多數命令式動作使用POST。 - 屬性
body會將資料傳遞給動作。 對於金鑰再生,請指定要旋轉哪個金鑰key1(或key2)。 - 動作在
terraform apply期間執行並在 Terraform 狀態中追蹤。
- 欄位
建立名為
outputs.tf的檔案,並插入下列程式碼:output "resource_group_name" { value = azurerm_resource_group.example.name } output "storage_account_name" { value = azurerm_storage_account.example.name }
執行 terraform init 來初始化 Terraform 部署。 此命令會下載管理 Azure 資源所需的 Azure 提供者。
terraform init -upgrade
關鍵點:
- 參數
-upgrade會將必要的提供者插件升級到符合配置版本限制的最新版本。
執行 terraform plan 以建立執行計畫。
terraform plan -out main.tfplan
關鍵點:
-
terraform plan命令會建立執行計劃,但不會執行它。 相反地,系統會決定需要執行哪些動作,來創建您在設定檔中指定的設定。 此模式可讓您在對實際資源進行任何變更之前,先確認執行方案是否符合您的預期。 - 選用的
-out參數可讓您指定計畫的輸出檔。 使用該-out參數可確保您檢視的計畫與實際應用的方案完全相同。
執行terraform apply指令將執行計劃套用至您的雲端基礎設施。
terraform apply main.tfplan
關鍵點:
- 範例
terraform apply命令假設您之前已執行過terraform plan -out main.tfplan。 - 如果您為
-out參數指定了不同的檔案名,請在呼叫terraform apply時使用相同的檔案名。 - 如果你沒有使用
-out參數,則呼叫terraform apply時請不要使用任何參數。
驗證結果
完成 terraform apply 之後,儲存帳戶金鑰已被輪換。 你可以透過 Azure 裡的儲存帳號金鑰來驗證金鑰輪換。
執行 az 儲存帳戶金鑰清單 以查看儲存帳戶金鑰。
az storage account keys list \
--resource-group <resource_group_name> \
--account-name <storage_account_name>
value 欄位會顯示目前的金鑰。
其他資源行動範例
azapi_resource_action 資源可與許多 Azure 操作合作。 以下是常見的例子:
-
虛擬機器:
deallocate,start,restart,powerOff,reimage -
金鑰保險庫:
purge(用於軟刪除的保險庫)、rotate(用於管理金鑰) -
應用程式服務:
swap(用於部署時段),restart -
資料庫:
failover,promote - Compute resources:由 Azure REST API 暴露的任何操作,該操作修改狀態而不建立或銷毀資源
清理資源
當您不再需要透過 Terraform 建立的資源時,請執行下列步驟:
執行 terraform plan 並指定
destroy旗標。terraform plan -destroy -out main.destroy.tfplan關鍵點:
-
terraform plan命令會建立執行計劃,但不會執行它。 相反地,系統會決定需要執行哪些動作,來創建您在設定檔中指定的設定。 此模式可讓您在對實際資源進行任何變更之前,先確認執行方案是否符合您的預期。 - 選用的
-out參數可讓您指定計畫的輸出檔。 使用該-out參數可確保您檢視的計畫與實際應用的方案完全相同。
-
執行 terraform apply 來應用執行計劃。
terraform apply main.destroy.tfplan
針對 Azure 上的 Terraform 進行故障排除
針對在 Azure 上使用 Terraform 時的常見問題進行疑難解答