Microsoft。搜尋服務 2026-03-01-preview

Bicep 資源定義

searchServices 資源類型可以使用目標作業來部署:

如需每個 API 版本中已變更屬性的清單,請參閱 變更記錄檔。

使用範例

Bicep 範例

部署 Search Service 的基本範例。

param resourceName string = 'acctest0001'
param location string = 'westeurope'

resource searchService 'Microsoft.Search/searchServices@2022-09-01' = {
  name: resourceName
  location: location
  sku: {
    name: 'standard'
  }
  properties: {
    authOptions: {
      apiKeyOnly: {}
    }
    disableLocalAuth: false
    encryptionWithCmk: {
      enforcement: 'Disabled'
    }
    hostingMode: 'default'
    networkRuleSet: {
      ipRules: []
    }
    partitionCount: 1
    publicNetworkAccess: 'Enabled'
    replicaCount: 1
  }
  tags: {
    environment: 'staging'
  }
}

Azure 已驗證的模組

下列 Azure 驗證模組 可用來部署此資源類型。

模組 說明
搜尋服務 搜尋服務的 AVM 資源模組

Azure 快速入門範例

以下的 Azure 快速啟動範本包含部署此資源類型的Bicep範例。

Bicep檔案 說明
Azure AI Foundry 網路受限 這組範本演示了如何在禁用專用連結和出口的情況下設置 Azure AI Foundry,使用 Microsoft 管理的密鑰進行加密,並使用 Microsoft 管理的標識配置為 AI 資源。
Azure 認知搜尋服務 此範本會建立 Azure 認知搜尋服務
具有使用者受控識別的網路保護代理程式 這組範本示範如何使用 AI 服務 / AOAI 連線的使用者受控識別驗證和專用網連結,設定具有虛擬網路隔離的 Azure AI 代理程式服務,以將代理程式連線到您的安全數據。
標準代理程式設定 這組範本示範如何使用標準設定來設定 Azure AI 代理程式服務,這表示已啟用專案/中樞連線和公用因特網存取的受控識別驗證。 代理程式會使用客戶擁有的單一租用戶搜尋和記憶體資源。 透過此設定,您可以完全控制這些資源並查看這些資源,但會根據您的使用量產生成本。

資源格式

若要建立 Microsoft.Search/searchServices 資源,請將下列 Bicep 新增至範本。

resource symbolicname 'Microsoft.Search/searchServices@2026-03-01-preview' = {
  identity: {
    type: 'string'
    userAssignedIdentities: {
      {customized property}: {}
    }
  }
  location: 'string'
  name: 'string'
  properties: {
    authOptions: {
      aadOrApiKey: {
        aadAuthFailureMode: 'string'
      }
      apiKeyOnly: any(...)
    }
    computeType: 'string'
    dataExfiltrationProtections: [
      'string'
    ]
    disableLocalAuth: bool
    encryptionWithCmk: {
      enforcement: 'string'
      serviceLevelEncryptionKey: {
        accessCredentials: {
          applicationId: 'string'
          applicationSecret: 'string'
        }
        identity: {
          @odata.type: 'string'
          // For remaining properties, see DataIdentity objects
        }
        keyVaultKeyName: 'string'
        keyVaultKeyVersion: 'string'
        keyVaultUri: 'string'
      }
    }
    endpoint: 'string'
    hostingMode: 'string'
    knowledgeRetrieval: 'string'
    networkRuleSet: {
      bypass: 'string'
      ipRules: [
        {
          value: 'string'
        }
      ]
    }
    partitionCount: int
    publicNetworkAccess: 'string'
    replicaCount: int
    semanticSearch: 'string'
    upgradeAvailable: 'string'
  }
  sku: {
    name: 'string'
  }
  tags: {
    {customized property}: 'string'
  }
}

DataIdentity 物件

設定 @odata.type 屬性以指定物件的類型。

針對 #Microsoft.Azure.Search.DataNoneIdentity,請使用:

{
  @odata.type: '#Microsoft.Azure.Search.DataNoneIdentity'
}

針對 #Microsoft.Azure.Search.DataUserAssignedIdentity,請使用:

{
  @odata.type: '#Microsoft.Azure.Search.DataUserAssignedIdentity'
  federatedIdentityClientId: 'string'
  userAssignedIdentity: 'string'
}

屬性值

Microsoft.Search/searchServices

名稱 說明 價值
身分識別 資源的身分識別。 身分識別
位置 資源所在的地理位置 字串 (必要)
名字 資源名稱 string

約束:
模式 = ^(?=.{2,60}$)[a-z0-9][a-z0-9]+(-[a-z0-9]+)*$ (必要)
屬性 搜尋服務的屬性。 SearchServiceProperties
sku 搜尋服務的 SKU,決定價格區間和容量限制。 建立新的搜尋服務時,需要這個屬性。 Sku
標記 資源標籤 標記名稱和值的字典。 請參閱範本中的 標籤

AzureActiveDirectoryApplicationCredentials

名稱 說明 價值
應用程式ID 租戶中應用程式註冊的應用程式(用戶端)ID。 字串
應用程式密碼 一個用於 Azure Key Vault 驗證的應用程式註冊產生的 AAD 用戶端秘密。 string

約束:
敏感性值。 以安全參數的形式傳入。

資料身分識別

名稱 說明 價值
@odata.type 針對 DataNoneIdentity 類型設定為 '#Microsoft.Azure.Search.DataNoneIdentity'。 針對 DataUserAssignedIdentity 類型設定為 '#Microsoft.Azure.Search.DataUserAssignedIdentity'。 '#Microsoft.Azure.Search.DataNoneIdentity'
'#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)

DataNone身分識別

名稱 說明 價值
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataNoneIdentity' (必要)

DataPlaneAadOrApiKeyAuthOption

名稱 說明 價值
aadAuthFailureMode 描述搜尋服務的數據平面 API 會針對驗證失敗的要求傳送哪些回應。 'http401WithBearerChallenge'
'http403'

DataPlaneAuthOptions

名稱 說明 價值
aadOrApiKey 表示 API 金鑰或來自 Microsoft Entra ID 租使用者的存取令牌都可用於驗證。 DataPlaneAadOrApiKeyAuthOption
apiKeyOnly 表示只能使用 API 金鑰進行驗證。 any

DataUserAssigned身分識別

名稱 說明 價值
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)
federatedIdentityClientId 多租戶 User-Assigned 管理身份 CMK 支援的選配:多租戶應用程式註冊的用戶端 ID(UUID)已設定與 userAssignedIdentity 聯合。 字串
userAssignedIdentity 使用者指派受控識別的完整 Azure 資源識別碼,通常採用「/subscriptions/12345678-1234-1234-1234567890ab/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId」格式,應該已指派給搜尋服務。 字串 (必要)

EncryptionWithCmk 的

名稱 說明 價值
執法 描述搜尋服務在找到未使用客戶管理密鑰加密的物件時,應如何強制執行合規性。 'Disabled'
'Enabled'
“未指定”
serviceLevelEncryption金鑰 描述由客戶管理的加密搜尋服務金鑰配置。 SearchResourceEncryptionKey

身分識別

名稱 說明 價值
型別 用於資源的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含系統所建立的身分識別和一組使用者指派的身分識別。 類型 『None』 會從服務中移除所有身分識別。 'None'
“系統分配”
'SystemAssigned, UserAssigned'
'UserAssigned' (必要)
userAssignedIdentities 與資源相關聯的使用者身分識別清單。 用戶識別字典索引鍵參考的格式為 ARM 資源標識符:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'。 IdentityUserAssignedIdentities

IdentityUserAssignedIdentities

名稱 說明 價值

IpRule (英语)

名稱 說明 價值
value 對應至單一 IPv4 位址的值(例如 123.1.2.3)或 CIDR 格式的 IP 範圍(例如 123.1.2.3/24)。 字串

NetworkRuleSet 網路規則集

名稱 說明 價值
旁路 可略過 『ipRules』 區段中所定義規則之輸入流量的可能來源。 “AzurePortal”
'AzureServices'
'None'
ipRules IP 限制規則清單,定義允許存取搜尋服務端點的輸入網路。 同時,所有其他公用IP網路都會遭到防火牆封鎖。 只有在搜尋服務的 'publicNetworkAccess' 已啟用時,才會套用這些限制規則;否則,即使有任何公用IP規則,也不允許透過公用介面的流量,而私人端點聯機會是獨佔存取方法。 IpRule[]

SearchResourceEncryptionKey

名稱 說明 價值
accessCredentials 用來存取 Azure 金鑰保存庫的選擇性 Azure Active Directory 認證。 如果改用受控識別,則不需要。 AzureActiveDirectoryApplicationCredentials
身分識別 要用於此加密金鑰的明確受控識別。 如果未指定,且存取認證屬性為 Null,則會使用系統指派的受控識別。 更新資源時,如果未指定明確識別,則會維持不變。 如果指定了 「none」 ,則會清除此屬性的值。 資料身分識別
keyVaultKeyName 要用來加密待用數據的 Azure Key Vault 金鑰名稱。 字串
keyVaultKeyVersion 要用來加密待用數據的 Azure Key Vault 金鑰版本。 字串
keyVaultUri Azure Key Vault 的 URI,也稱為 DNS 名稱,其中包含用來加密待用數據的密鑰。 範例 URI 可能會 https://my-keyvault-name.vault.azure.net。 字串

SearchServiceProperties

名稱 說明 價值
authOptions 定義搜尋服務數據平面 API 如何驗證要求的選項。 如果 'disableLocalAuth' 設定為 true,則無法設定此設定。 DataPlaneAuthOptions
computeType 設定此屬性以支援使用預設計算或 Azure 機密計算的搜尋服務。 '機密'
'Default'
dataExfiltrationProtections 明確不允許搜尋服務的數據外流案例清單。 目前,唯一支援的值是 『All』,以停用所有可能的數據匯出案例,並針對未來規劃更精細的控制。 包含任何的字串數組:
'BlockAll'
disableLocalAuth 當設定為 true 時,不允許對搜尋服務的呼叫利用 API 金鑰進行驗證。 如果已定義 『dataPlaneAuthOptions』,則無法設定為 true。 布爾 (bool)
encryptionWithCmk 指定在搜尋服務中使用客戶經理密鑰加密資源(例如索引)的任何原則。 EncryptionWithCmk 的
端點 Azure AI 搜尋服務的端點。 字串
hostingMode 僅適用於 standard3 SKU。 您可以設定此屬性來啟用最多 3 個高密度分割區,允許最多 1000 個索引,這遠高於任何其他 SKU 允許的最大索引。 對於 standard3 SKU,值為 'Default' 或 'HighDensity'。 對於所有其他 SKU,此值必須為「預設」。 'Default'
“高密度”
知識檢索 指定 Azure AI 搜尋服務 服務代理檢索的計費計畫。 此配置僅在特定地區的特定價格層級提供。 “免費”
'standard'
networkRuleSet 網路規則集 決定如何觸達 Azure AI 搜尋服務的網路特定規則。 NetworkRuleSet 網路規則集
partitionCount 專用搜尋服務中的分割區數量;若有指定,可以是1、2、3、4、6或12。 大於 1 的值僅適用於標準 SKU。 對於 hostingMode 設定為 'highDensity' 的 'standard3' 服務,允許的值介於 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
公共網路存取 此值可以設定為「已啟用」,以避免對現有客戶資源和範本進行重大變更。 如果設定為「已停用」,則不允許透過公用介面進行流量,而專用端點連線會是獨佔存取方法。 'Disabled'
'Enabled'
“SecuredByPerimeter”
replicaCount 專用搜尋服務中的複本數量。 如果指定,它必須是標準 SKU 的 1 到 12 之間的值,或基本 SKU 的 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
語義搜索 規定 Azure AI 搜尋服務中語意搜尋的可用性與計費計畫。 此配置僅在特定地區的特定價格層級提供。 '已禁用'
“免費”
'standard'
upgrade可用 指出搜尋服務是否有可用的升級。 '可用'
'notAvailable'

Sku

名稱 說明 價值
名字 搜尋服務的 SKU。 有效值包括:「免費」:共享服務。 'basic':最多 3 個複本的專用服務。 'standard': 專用服務,最多可有 12 個分割區和 12 個復本。 'standard2':類似於標準,但每個搜尋單位的容量較多。 'standard3':最大標準供應專案,最多可有 12 個分割區和 12 個復本(如果您也將 hostingMode 屬性設定為 'highDensity',則最多 3 個具有更多索引的數據分割)。 'storage_optimized_l1':支援每個分割區 1TB,最多 12 個分割區。 「storage_optimized_l2」:支援每個分割區 2TB,最多可支援 12 個分割區。 「無伺服器」:無伺服器層級,具備自動擴展功能。 'basic'
“免費”
「無伺服器」
'standard'
'標準 2'
'標準3'
“storage_optimized_l1”
“storage_optimized_l2”

TrackedResourceTags

名稱 說明 價值

UserAssignedIdentity

名稱 說明 價值

ARM 樣本資源定義

searchServices 資源類型可以使用目標作業來部署:

使用範例

Azure 快速入門範本

以下的 Azure 快速起始範本部署此資源類型。

Template 說明
Azure AI Foundry 網路受限

部署至Azure
這組範本演示了如何在禁用專用連結和出口的情況下設置 Azure AI Foundry,使用 Microsoft 管理的密鑰進行加密,並使用 Microsoft 管理的標識配置為 AI 資源。
Azure 認知搜尋服務

部署至Azure
此範本會建立 Azure 認知搜尋服務
使用私人端點 Azure 認知搜尋服務

部署至Azure
此範本會建立具有私人端點的 Azure 認知搜尋服務。
具有使用者受控識別的網路保護代理程式

部署至Azure
這組範本示範如何使用 AI 服務 / AOAI 連線的使用者受控識別驗證和專用網連結,設定具有虛擬網路隔離的 Azure AI 代理程式服務,以將代理程式連線到您的安全數據。
標準代理程式設定

部署至Azure
這組範本示範如何使用標準設定來設定 Azure AI 代理程式服務,這表示已啟用專案/中樞連線和公用因特網存取的受控識別驗證。 代理程式會使用客戶擁有的單一租用戶搜尋和記憶體資源。 透過此設定,您可以完全控制這些資源並查看這些資源,但會根據您的使用量產生成本。
Web 應用程式搭配 SQL 資料庫、Azure Cosmos DB、Azure Search

部署至Azure
此範本可配置網頁應用程式、SQL 資料庫、Azure Cosmos 資料庫、Azure 搜尋及應用程式洞察。

資源格式

若要建立 Microsoft.Search/searchServices 資源,請將下列 JSON 新增至範本。

{
  "type": "Microsoft.Search/searchServices",
  "apiVersion": "2026-03-01-preview",
  "name": "string",
  "identity": {
    "type": "string",
    "userAssignedIdentities": {
      "{customized property}": {
      }
    }
  },
  "location": "string",
  "properties": {
    "authOptions": {
      "aadOrApiKey": {
        "aadAuthFailureMode": "string"
      },
      "apiKeyOnly": {}
    },
    "computeType": "string",
    "dataExfiltrationProtections": [ "string" ],
    "disableLocalAuth": "bool",
    "encryptionWithCmk": {
      "enforcement": "string",
      "serviceLevelEncryptionKey": {
        "accessCredentials": {
          "applicationId": "string",
          "applicationSecret": "string"
        },
        "identity": {
          "@odata.type": "string"
          // For remaining properties, see DataIdentity objects
        },
        "keyVaultKeyName": "string",
        "keyVaultKeyVersion": "string",
        "keyVaultUri": "string"
      }
    },
    "endpoint": "string",
    "hostingMode": "string",
    "knowledgeRetrieval": "string",
    "networkRuleSet": {
      "bypass": "string",
      "ipRules": [
        {
          "value": "string"
        }
      ]
    },
    "partitionCount": "int",
    "publicNetworkAccess": "string",
    "replicaCount": "int",
    "semanticSearch": "string",
    "upgradeAvailable": "string"
  },
  "sku": {
    "name": "string"
  },
  "tags": {
    "{customized property}": "string"
  }
}

DataIdentity 物件

設定 @odata.type 屬性以指定物件的類型。

針對 #Microsoft.Azure.Search.DataNoneIdentity,請使用:

{
  "@odata.type": "#Microsoft.Azure.Search.DataNoneIdentity"
}

針對 #Microsoft.Azure.Search.DataUserAssignedIdentity,請使用:

{
  "@odata.type": "#Microsoft.Azure.Search.DataUserAssignedIdentity",
  "federatedIdentityClientId": "string",
  "userAssignedIdentity": "string"
}

屬性值

Microsoft.Search/searchServices

名稱 說明 價值
apiVersion API 版本 『2026-03-01-預覽』
身分識別 資源的身分識別。 身分識別
位置 資源所在的地理位置 字串 (必要)
名字 資源名稱 string

約束:
模式 = ^(?=.{2,60}$)[a-z0-9][a-z0-9]+(-[a-z0-9]+)*$ (必要)
屬性 搜尋服務的屬性。 SearchServiceProperties
sku 搜尋服務的 SKU,決定價格區間和容量限制。 建立新的搜尋服務時,需要這個屬性。 Sku
標記 資源標籤 標記名稱和值的字典。 請參閱範本中的 標籤
型別 資源類型 “Microsoft.Search/searchServices”

AzureActiveDirectoryApplicationCredentials

名稱 說明 價值
應用程式ID 租戶中應用程式註冊的應用程式(用戶端)ID。 字串
應用程式密碼 一個用於 Azure Key Vault 驗證的應用程式註冊產生的 AAD 用戶端秘密。 string

約束:
敏感性值。 以安全參數的形式傳入。

資料身分識別

名稱 說明 價值
@odata.type 針對 DataNoneIdentity 類型設定為 '#Microsoft.Azure.Search.DataNoneIdentity'。 針對 DataUserAssignedIdentity 類型設定為 '#Microsoft.Azure.Search.DataUserAssignedIdentity'。 '#Microsoft.Azure.Search.DataNoneIdentity'
'#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)

DataNone身分識別

名稱 說明 價值
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataNoneIdentity' (必要)

DataPlaneAadOrApiKeyAuthOption

名稱 說明 價值
aadAuthFailureMode 描述搜尋服務的數據平面 API 會針對驗證失敗的要求傳送哪些回應。 'http401WithBearerChallenge'
'http403'

DataPlaneAuthOptions

名稱 說明 價值
aadOrApiKey 表示 API 金鑰或來自 Microsoft Entra ID 租使用者的存取令牌都可用於驗證。 DataPlaneAadOrApiKeyAuthOption
apiKeyOnly 表示只能使用 API 金鑰進行驗證。 any

DataUserAssigned身分識別

名稱 說明 價值
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)
federatedIdentityClientId 多租戶 User-Assigned 管理身份 CMK 支援的選配:多租戶應用程式註冊的用戶端 ID(UUID)已設定與 userAssignedIdentity 聯合。 字串
userAssignedIdentity 使用者指派受控識別的完整 Azure 資源識別碼,通常採用「/subscriptions/12345678-1234-1234-1234567890ab/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId」格式,應該已指派給搜尋服務。 字串 (必要)

EncryptionWithCmk 的

名稱 說明 價值
執法 描述搜尋服務在找到未使用客戶管理密鑰加密的物件時,應如何強制執行合規性。 'Disabled'
'Enabled'
“未指定”
serviceLevelEncryption金鑰 描述由客戶管理的加密搜尋服務金鑰配置。 SearchResourceEncryptionKey

身分識別

名稱 說明 價值
型別 用於資源的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含系統所建立的身分識別和一組使用者指派的身分識別。 類型 『None』 會從服務中移除所有身分識別。 'None'
“系統分配”
'SystemAssigned, UserAssigned'
'UserAssigned' (必要)
userAssignedIdentities 與資源相關聯的使用者身分識別清單。 用戶識別字典索引鍵參考的格式為 ARM 資源標識符:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'。 IdentityUserAssignedIdentities

IdentityUserAssignedIdentities

名稱 說明 價值

IpRule (英语)

名稱 說明 價值
value 對應至單一 IPv4 位址的值(例如 123.1.2.3)或 CIDR 格式的 IP 範圍(例如 123.1.2.3/24)。 字串

NetworkRuleSet 網路規則集

名稱 說明 價值
旁路 可略過 『ipRules』 區段中所定義規則之輸入流量的可能來源。 “AzurePortal”
'AzureServices'
'None'
ipRules IP 限制規則清單,定義允許存取搜尋服務端點的輸入網路。 同時,所有其他公用IP網路都會遭到防火牆封鎖。 只有在搜尋服務的 'publicNetworkAccess' 已啟用時,才會套用這些限制規則;否則,即使有任何公用IP規則,也不允許透過公用介面的流量,而私人端點聯機會是獨佔存取方法。 IpRule[]

SearchResourceEncryptionKey

名稱 說明 價值
accessCredentials 用來存取 Azure 金鑰保存庫的選擇性 Azure Active Directory 認證。 如果改用受控識別,則不需要。 AzureActiveDirectoryApplicationCredentials
身分識別 要用於此加密金鑰的明確受控識別。 如果未指定,且存取認證屬性為 Null,則會使用系統指派的受控識別。 更新資源時,如果未指定明確識別,則會維持不變。 如果指定了 「none」 ,則會清除此屬性的值。 資料身分識別
keyVaultKeyName 要用來加密待用數據的 Azure Key Vault 金鑰名稱。 字串
keyVaultKeyVersion 要用來加密待用數據的 Azure Key Vault 金鑰版本。 字串
keyVaultUri Azure Key Vault 的 URI,也稱為 DNS 名稱,其中包含用來加密待用數據的密鑰。 範例 URI 可能會 https://my-keyvault-name.vault.azure.net。 字串

SearchServiceProperties

名稱 說明 價值
authOptions 定義搜尋服務數據平面 API 如何驗證要求的選項。 如果 'disableLocalAuth' 設定為 true,則無法設定此設定。 DataPlaneAuthOptions
computeType 設定此屬性以支援使用預設計算或 Azure 機密計算的搜尋服務。 '機密'
'Default'
dataExfiltrationProtections 明確不允許搜尋服務的數據外流案例清單。 目前,唯一支援的值是 『All』,以停用所有可能的數據匯出案例,並針對未來規劃更精細的控制。 包含任何的字串數組:
'BlockAll'
disableLocalAuth 當設定為 true 時,不允許對搜尋服務的呼叫利用 API 金鑰進行驗證。 如果已定義 『dataPlaneAuthOptions』,則無法設定為 true。 布爾 (bool)
encryptionWithCmk 指定在搜尋服務中使用客戶經理密鑰加密資源(例如索引)的任何原則。 EncryptionWithCmk 的
端點 Azure AI 搜尋服務的端點。 字串
hostingMode 僅適用於 standard3 SKU。 您可以設定此屬性來啟用最多 3 個高密度分割區,允許最多 1000 個索引,這遠高於任何其他 SKU 允許的最大索引。 對於 standard3 SKU,值為 'Default' 或 'HighDensity'。 對於所有其他 SKU,此值必須為「預設」。 'Default'
“高密度”
知識檢索 指定 Azure AI 搜尋服務 服務代理檢索的計費計畫。 此配置僅在特定地區的特定價格層級提供。 “免費”
'standard'
networkRuleSet 網路規則集 決定如何觸達 Azure AI 搜尋服務的網路特定規則。 NetworkRuleSet 網路規則集
partitionCount 專用搜尋服務中的分割區數量;若有指定,可以是1、2、3、4、6或12。 大於 1 的值僅適用於標準 SKU。 對於 hostingMode 設定為 'highDensity' 的 'standard3' 服務,允許的值介於 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
公共網路存取 此值可以設定為「已啟用」,以避免對現有客戶資源和範本進行重大變更。 如果設定為「已停用」,則不允許透過公用介面進行流量,而專用端點連線會是獨佔存取方法。 'Disabled'
'Enabled'
“SecuredByPerimeter”
replicaCount 專用搜尋服務中的複本數量。 如果指定,它必須是標準 SKU 的 1 到 12 之間的值,或基本 SKU 的 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
語義搜索 規定 Azure AI 搜尋服務中語意搜尋的可用性與計費計畫。 此配置僅在特定地區的特定價格層級提供。 '已禁用'
“免費”
'standard'
upgrade可用 指出搜尋服務是否有可用的升級。 '可用'
'notAvailable'

Sku

名稱 說明 價值
名字 搜尋服務的 SKU。 有效值包括:「免費」:共享服務。 'basic':最多 3 個複本的專用服務。 'standard': 專用服務,最多可有 12 個分割區和 12 個復本。 'standard2':類似於標準,但每個搜尋單位的容量較多。 'standard3':最大標準供應專案,最多可有 12 個分割區和 12 個復本(如果您也將 hostingMode 屬性設定為 'highDensity',則最多 3 個具有更多索引的數據分割)。 'storage_optimized_l1':支援每個分割區 1TB,最多 12 個分割區。 「storage_optimized_l2」:支援每個分割區 2TB,最多可支援 12 個分割區。 「無伺服器」:無伺服器層級,具備自動擴展功能。 'basic'
“免費”
「無伺服器」
'standard'
'標準 2'
'標準3'
“storage_optimized_l1”
“storage_optimized_l2”

TrackedResourceTags

名稱 說明 價值

UserAssignedIdentity

名稱 說明 價值

Terraform (AzAPI 提供者) 資源定義

searchServices 資源類型可以使用目標作業來部署:

  • 資源團體 關於每個 API 版本變更屬性的清單,請參見 變更日誌。

使用範例

Terraform 範例

部署 Search Service 的基本範例。

terraform {
  required_providers {
    azapi = {
      source = "Azure/azapi"
    }
  }
}

provider "azapi" {
  skip_provider_registration = false
}

variable "resource_name" {
  type    = string
  default = "acctest0001"
}

variable "location" {
  type    = string
  default = "westeurope"
}

resource "azapi_resource" "resourceGroup" {
  type     = "Microsoft.Resources/resourceGroups@2020-06-01"
  name     = var.resource_name
  location = var.location
}

resource "azapi_resource" "searchService" {
  type      = "Microsoft.Search/searchServices@2022-09-01"
  parent_id = azapi_resource.resourceGroup.id
  name      = var.resource_name
  location  = var.location
  body = {
    properties = {
      authOptions = {
        apiKeyOnly = {
        }
      }
      disableLocalAuth = false
      encryptionWithCmk = {
        enforcement = "Disabled"
      }
      hostingMode = "default"
      networkRuleSet = {
        ipRules = [
        ]
      }
      partitionCount      = 1
      publicNetworkAccess = "Enabled"
      replicaCount        = 1
    }
    sku = {
      name = "standard"
    }
    tags = {
      environment = "staging"
    }
  }
  schema_validation_enabled = false
  response_export_values    = ["*"]
}

Azure 已驗證的模組

下列 Azure 驗證模組 可用來部署此資源類型。

模組 說明
搜尋服務 搜尋服務的 AVM 資源模組

資源格式

若要建立 Microsoft.Search/searchServices 資源,請將下列 Terraform 新增至範本。

resource "azapi_resource" "symbolicname" {
  type = "Microsoft.Search/searchServices@2026-03-01-preview"
  name = "string"
  parent_id = "string"
  identity {
    type = "string"
    identity_ids = [
      "string"
    ]
  }
  location = "string"
  tags = {
    {customized property} = "string"
  }
  body = {
    properties = {
      authOptions = {
        aadOrApiKey = {
          aadAuthFailureMode = "string"
        }
        apiKeyOnly = ?
      }
      computeType = "string"
      dataExfiltrationProtections = [
        "string"
      ]
      disableLocalAuth = bool
      encryptionWithCmk = {
        enforcement = "string"
        serviceLevelEncryptionKey = {
          accessCredentials = {
            applicationId = "string"
            applicationSecret = "string"
          }
          identity = {
            @odata.type = "string"
            // For remaining properties, see DataIdentity objects
          }
          keyVaultKeyName = "string"
          keyVaultKeyVersion = "string"
          keyVaultUri = "string"
        }
      }
      endpoint = "string"
      hostingMode = "string"
      knowledgeRetrieval = "string"
      networkRuleSet = {
        bypass = "string"
        ipRules = [
          {
            value = "string"
          }
        ]
      }
      partitionCount = int
      publicNetworkAccess = "string"
      replicaCount = int
      semanticSearch = "string"
      upgradeAvailable = "string"
    }
    sku = {
      name = "string"
    }
  }
}

DataIdentity 物件

設定 @odata.type 屬性以指定物件的類型。

針對 #Microsoft.Azure.Search.DataNoneIdentity,請使用:

{
  @odata.type = "#Microsoft.Azure.Search.DataNoneIdentity"
}

針對 #Microsoft.Azure.Search.DataUserAssignedIdentity,請使用:

{
  @odata.type = "#Microsoft.Azure.Search.DataUserAssignedIdentity"
  federatedIdentityClientId = "string"
  userAssignedIdentity = "string"
}

屬性值

Microsoft.Search/searchServices

名稱 說明 價值
身分識別 資源的身分識別。 身分識別
位置 資源所在的地理位置 字串 (必要)
名字 資源名稱 string

約束:
模式 = ^(?=.{2,60}$)[a-z0-9][a-z0-9]+(-[a-z0-9]+)*$ (必要)
屬性 搜尋服務的屬性。 SearchServiceProperties
sku 搜尋服務的 SKU,決定價格區間和容量限制。 建立新的搜尋服務時,需要這個屬性。 Sku
標記 資源標籤 標記名稱和值的字典。
型別 資源類型 「Microsoft.搜尋/searchServices@2026-03-01-預覽」

AzureActiveDirectoryApplicationCredentials

名稱 說明 價值
應用程式ID 租戶中應用程式註冊的應用程式(用戶端)ID。 字串
應用程式密碼 一個用於 Azure Key Vault 驗證的應用程式註冊產生的 AAD 用戶端秘密。 string

約束:
敏感性值。 以安全參數的形式傳入。

資料身分識別

名稱 說明 價值
@odata.type 針對 DataNoneIdentity 類型設定為 '#Microsoft.Azure.Search.DataNoneIdentity'。 針對 DataUserAssignedIdentity 類型設定為 '#Microsoft.Azure.Search.DataUserAssignedIdentity'。 '#Microsoft.Azure.Search.DataNoneIdentity'
'#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)

DataNone身分識別

名稱 說明 價值
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataNoneIdentity' (必要)

DataPlaneAadOrApiKeyAuthOption

名稱 說明 價值
aadAuthFailureMode 描述搜尋服務的數據平面 API 會針對驗證失敗的要求傳送哪些回應。 'http401WithBearerChallenge'
'http403'

DataPlaneAuthOptions

名稱 說明 價值
aadOrApiKey 表示 API 金鑰或來自 Microsoft Entra ID 租使用者的存取令牌都可用於驗證。 DataPlaneAadOrApiKeyAuthOption
apiKeyOnly 表示只能使用 API 金鑰進行驗證。 any

DataUserAssigned身分識別

名稱 說明 價值
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)
federatedIdentityClientId 多租戶 User-Assigned 管理身份 CMK 支援的選配:多租戶應用程式註冊的用戶端 ID(UUID)已設定與 userAssignedIdentity 聯合。 字串
userAssignedIdentity 使用者指派受控識別的完整 Azure 資源識別碼,通常採用「/subscriptions/12345678-1234-1234-1234567890ab/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId」格式,應該已指派給搜尋服務。 字串 (必要)

EncryptionWithCmk 的

名稱 說明 價值
執法 描述搜尋服務在找到未使用客戶管理密鑰加密的物件時,應如何強制執行合規性。 'Disabled'
'Enabled'
“未指定”
serviceLevelEncryption金鑰 描述由客戶管理的加密搜尋服務金鑰配置。 SearchResourceEncryptionKey

身分識別

名稱 說明 價值
型別 用於資源的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含系統所建立的身分識別和一組使用者指派的身分識別。 類型 『None』 會從服務中移除所有身分識別。 'None'
“系統分配”
'SystemAssigned, UserAssigned'
'UserAssigned' (必要)
userAssignedIdentities 與資源相關聯的使用者身分識別清單。 用戶識別字典索引鍵參考的格式為 ARM 資源標識符:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'。 IdentityUserAssignedIdentities

IdentityUserAssignedIdentities

名稱 說明 價值

IpRule (英语)

名稱 說明 價值
value 對應至單一 IPv4 位址的值(例如 123.1.2.3)或 CIDR 格式的 IP 範圍(例如 123.1.2.3/24)。 字串

NetworkRuleSet 網路規則集

名稱 說明 價值
旁路 可略過 『ipRules』 區段中所定義規則之輸入流量的可能來源。 “AzurePortal”
'AzureServices'
'None'
ipRules IP 限制規則清單,定義允許存取搜尋服務端點的輸入網路。 同時,所有其他公用IP網路都會遭到防火牆封鎖。 只有在搜尋服務的 'publicNetworkAccess' 已啟用時,才會套用這些限制規則;否則,即使有任何公用IP規則,也不允許透過公用介面的流量,而私人端點聯機會是獨佔存取方法。 IpRule[]

SearchResourceEncryptionKey

名稱 說明 價值
accessCredentials 用來存取 Azure 金鑰保存庫的選擇性 Azure Active Directory 認證。 如果改用受控識別,則不需要。 AzureActiveDirectoryApplicationCredentials
身分識別 要用於此加密金鑰的明確受控識別。 如果未指定,且存取認證屬性為 Null,則會使用系統指派的受控識別。 更新資源時,如果未指定明確識別,則會維持不變。 如果指定了 「none」 ,則會清除此屬性的值。 資料身分識別
keyVaultKeyName 要用來加密待用數據的 Azure Key Vault 金鑰名稱。 字串
keyVaultKeyVersion 要用來加密待用數據的 Azure Key Vault 金鑰版本。 字串
keyVaultUri Azure Key Vault 的 URI,也稱為 DNS 名稱,其中包含用來加密待用數據的密鑰。 範例 URI 可能會 https://my-keyvault-name.vault.azure.net。 字串

SearchServiceProperties

名稱 說明 價值
authOptions 定義搜尋服務數據平面 API 如何驗證要求的選項。 如果 'disableLocalAuth' 設定為 true,則無法設定此設定。 DataPlaneAuthOptions
computeType 設定此屬性以支援使用預設計算或 Azure 機密計算的搜尋服務。 '機密'
'Default'
dataExfiltrationProtections 明確不允許搜尋服務的數據外流案例清單。 目前,唯一支援的值是 『All』,以停用所有可能的數據匯出案例,並針對未來規劃更精細的控制。 包含任何的字串數組:
'BlockAll'
disableLocalAuth 當設定為 true 時,不允許對搜尋服務的呼叫利用 API 金鑰進行驗證。 如果已定義 『dataPlaneAuthOptions』,則無法設定為 true。 布爾 (bool)
encryptionWithCmk 指定在搜尋服務中使用客戶經理密鑰加密資源(例如索引)的任何原則。 EncryptionWithCmk 的
端點 Azure AI 搜尋服務的端點。 字串
hostingMode 僅適用於 standard3 SKU。 您可以設定此屬性來啟用最多 3 個高密度分割區,允許最多 1000 個索引,這遠高於任何其他 SKU 允許的最大索引。 對於 standard3 SKU,值為 'Default' 或 'HighDensity'。 對於所有其他 SKU,此值必須為「預設」。 'Default'
“高密度”
知識檢索 指定 Azure AI 搜尋服務 服務代理檢索的計費計畫。 此配置僅在特定地區的特定價格層級提供。 “免費”
'standard'
networkRuleSet 網路規則集 決定如何觸達 Azure AI 搜尋服務的網路特定規則。 NetworkRuleSet 網路規則集
partitionCount 專用搜尋服務中的分割區數量;若有指定,可以是1、2、3、4、6或12。 大於 1 的值僅適用於標準 SKU。 對於 hostingMode 設定為 'highDensity' 的 'standard3' 服務,允許的值介於 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
公共網路存取 此值可以設定為「已啟用」,以避免對現有客戶資源和範本進行重大變更。 如果設定為「已停用」,則不允許透過公用介面進行流量,而專用端點連線會是獨佔存取方法。 'Disabled'
'Enabled'
“SecuredByPerimeter”
replicaCount 專用搜尋服務中的複本數量。 如果指定,它必須是標準 SKU 的 1 到 12 之間的值,或基本 SKU 的 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
語義搜索 規定 Azure AI 搜尋服務中語意搜尋的可用性與計費計畫。 此配置僅在特定地區的特定價格層級提供。 '已禁用'
“免費”
'standard'
upgrade可用 指出搜尋服務是否有可用的升級。 '可用'
'notAvailable'

Sku

名稱 說明 價值
名字 搜尋服務的 SKU。 有效值包括:「免費」:共享服務。 'basic':最多 3 個複本的專用服務。 'standard': 專用服務,最多可有 12 個分割區和 12 個復本。 'standard2':類似於標準,但每個搜尋單位的容量較多。 'standard3':最大標準供應專案,最多可有 12 個分割區和 12 個復本(如果您也將 hostingMode 屬性設定為 'highDensity',則最多 3 個具有更多索引的數據分割)。 'storage_optimized_l1':支援每個分割區 1TB,最多 12 個分割區。 「storage_optimized_l2」:支援每個分割區 2TB,最多可支援 12 個分割區。 「無伺服器」:無伺服器層級,具備自動擴展功能。 'basic'
“免費”
「無伺服器」
'standard'
'標準 2'
'標準3'
“storage_optimized_l1”
“storage_optimized_l2”

TrackedResourceTags

名稱 說明 價值

UserAssignedIdentity

名稱 說明 價值