JSON 加密 ARM 模板循环中的虚拟机

JSON to encrypt vms in loop of ARM template

我有一个 JSON ARM 模板,它通过循环创建多个虚拟机,我想我可以在循环结束时添加 encryptvm,它会加密所有磁盘。

然而它总是失败并出现一个奇怪的错误

完整的 json 在这里: https://pastebin.com/embed_iframe/Lxmb7Y42

这两个参数我都用过。

, parameters('VMNames'), copyIndex(1))]",

, parameters('VMNames'))]"

但似乎都不起作用。

我所做的基本上就是在以下资源部分中添加:

      "resources": [
    {
      "name": "[concat(parameters('VMNames'),'UpdateEncryptionSettings)']",
      "type": "Microsoft.Resources/deployments",
      "apiVersion": "2015-01-01",
      "dependsOn": [
        "[concat('Microsoft.Compute/virtualMachines/', parameters('VMNames'))]"
      ],
      "properties": {
        "mode": "Incremental",
        "templateLink": {
          "uri": "[concat(parameters('_artifactsLocation'),'/nestedtemplates/encryptVm.json',parameters('_artifactsLocationSasToken'))]",
          "contentVersion": "1.0.0.0"
        },
        "parameters": {
          "vmName": {
            "value": "[parameters('VMNames')]"
          },
          "aadClientID": {
            "value": "[parameters('aadClientID')]"
          },
          "aadClientSecret": {
            "value": "[parameters('aadClientSecret')]"
          },
          "keyVaultName": {
            "value": "[parameters('keyVaultName')]"
          },
          "keyVaultResourceGroup": {
            "value": "[parameters('keyVaultResourceGroup')]"
          },
          "useExistingKek": {
            "value": "[parameters('useExistingKek')]"
          },
          "keyEncryptionKeyURL": {
            "value": "[parameters('keyEncryptionKeyURL')]"
          },
          "_artifactsLocation": {
            "value": "[parameters('_artifactsLocation')]"
          },
          "_artifactsLocationSasToken": {
            "value": "[parameters('_artifactsLocationSasToken')]"
          }
        }
      }
    },
    {
      "apiVersion": "2017-05-10",
      "name": "[concat(parameters('VMNames'),'recoveryServicesVault')]",
      "type": "Microsoft.Resources/deployments",
      "resourceGroup": "[parameters('recoveryServicesVaultResourceGroup')]",
      "dependsOn": [
        "[concat('Microsoft.Compute/virtualMachines/', parameters('VMNames'))]"
       // "[resourceId('Microsoft.Resources/deployments/', concat(parameters('VMNames'), copyIndex(1),'UpdateEncryptionSettings'))]"
      ],
      "properties": {
        "mode": "Incremental",
        "template": {
          "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
          "contentVersion": "1.0.0.0",
          "resources": [
            {
              "name": "[concat(parameters('recoveryServicesVaultName'), '/', 'Azure', '/', variables('rsvV2vm'), resourceGroup().name, ';', parameters('VMNames'))]",
              "apiVersion": "2017-07-01",
              "type": "Microsoft.RecoveryServices/vaults/backupFabrics/backupProtectionIntent",
              "properties": {
                "friendlyName": "[concat(parameters('VMNames'), copyIndex(1), 'BackupIntent')]",
                "protectionIntentItemType": "AzureResourceItem",
                "policyId": "[resourceId(parameters('recoveryServicesVaultResourceGroup'), 'Microsoft.RecoveryServices/vaults/backupPolicies', parameters('recoveryServicesVaultName'), parameters('recoveryServicesVaultBackupPolicyName'))]",
                "sourceResourceId": "[resourceId(resourceGroup().name, 'Microsoft.Compute/virtualMachines', parameters('VMNames'))]"
              }
            }
          ]
        }
      }
    }
  ]

看不出我哪里错了。也许我把它添加到了错误的地方,但是在线检查 JSON 验证器工具,一切似乎都很好。

此模板是因为您为每个虚拟机定义了一次部署,但您为每个部署指定了相同的名称:

"name": "[concat(parameters('VMNames'),'UpdateEncryptionSettings')]",
"type": "Microsoft.Resources/deployments",

你需要给这个名字添加copyIndex()功能