我试过了
{
"apiVersion": "2016-07-01",
"name": "[concat(resourceGroup().name,'/Microsoft.Authorization/',variables('principalId'))]",
"type": "Microsoft.Authorization/roleAssignments",
"properties": {
"roleDefinitionId": "[variables('owner')]",
"principalId": "[parameters('msi').principalId]",
"scope": "[concat('/subscriptions/',subscription().subscriptionId,'/resourceGroups/',resourceGroup().name)]"
}
},
但它会出现以下错误
部署模板验证失败:'模板资源 'sf-gateway / Microsoft.Authorization / 5e60879d-b9c0-4e11-9548-9d92ed244eef'代表'Microsoft.Authorization / roleAssignments'在'1'行, 列'3432'具有不正确的段长度。嵌套资源类型 必须具有与其资源名称相同的段数。一个根 资源类型的段长度必须大于其资源 名称。有关用法,请参阅https://aka.ms/arm-template/#resources 细节。'。 (代码:InvalidTemplate)
我不完全明白需要改变什么。
我想给予资源组的主要所有权
答案 0 :(得分:1)
我想给予资源组的主要所有权
您可以从此link获取模板演示代码。如果使用VS创建模板,则可以直接从模板中获取该模板。它适用于我。
{
"$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"principalId": {
"type": "string",
"metadata": {
"description": "The principal to assign the role to"
}
},
"builtInRoleType": {
"type": "string",
"allowedValues": [
"Owner",
"Contributor",
"Reader"
],
"metadata": {
"description": "Built-in role to assign"
}
},
"roleNameGuid": {
"type": "string",
"metadata": {
"description": "A new GUID used to identify the role"
}
}
},
"variables": {
"Owner": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', '8e3af657-a8ff-443c-a75c-2fe8c4bcb635')]",
"Contributor": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', 'b24988ac-6180-42a0-ab88-20f7382dd24c')]",
"Reader": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', 'acdd72a7-3385-48ef-bd42-f606fba81ae7')]",
"scope": "[resourceGroup().id]"
},
"resources": [
{
"type": "Microsoft.Authorization/roleAssignments",
"apiVersion": "2017-05-01",
"name": "[parameters('roleNameGuid')]",
"properties": {
"roleDefinitionId": "[variables(parameters('builtInRoleType'))]",
"principalId": "[parameters('principalId')]",
"scope": "[variables('scope')]"
}
}
]
}
<强> azuredeploy.parameters.json 强>
{
"$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"principalId": {
"value": "principalId"
},
"builtInRoleType": {
"value": "Owner"
},
"roleNameGuid": {
"value": "Guid name"
}
}
}
测试结果:
答案 1 :(得分:0)
错误正在发生,因为名称中有更多的段,即用斜杠划分的组件,而不是类型,详见下文Resolve errors for invalid template。
有一个相关的讨论here;如果您可以获取资源的GUID并将其传递给name,则它将具有比该类型更少的段。