Microsoft。搜尋搜尋服務 2026-09-01-preview

Bicep 資源定義

searchServices 資源類型可以使用目標作業來部署:

如需每個 API 版本中已變更屬性的清單,請參閱 變更記錄檔。

使用範例

Bicep 範例

部署 Search Service 的基本範例。

param resourceName string = 'acctest0001'
param location string = 'westeurope'

resource searchService 'Microsoft.Search/searchServices@2022-09-01' = {
  name: resourceName
  location: location
  sku: {
    name: 'standard'
  }
  properties: {
    authOptions: {
      apiKeyOnly: {}
    }
    disableLocalAuth: false
    encryptionWithCmk: {
      enforcement: 'Disabled'
    }
    hostingMode: 'default'
    networkRuleSet: {
      ipRules: []
    }
    partitionCount: 1
    publicNetworkAccess: 'Enabled'
    replicaCount: 1
  }
  tags: {
    environment: 'staging'
  }
}

Azure 已驗證的模組

下列 Azure 驗證模組 可用來部署此資源類型。

模組 Description
搜尋服務 搜尋服務的 AVM 資源模組

Azure 快速入門範例

下列 Azure 快速入門範本 包含用於部署此資源類型的 Bicep 範例。

Bicep 檔案 Description
Azure AI Foundry 網路受限 這組範本演示了如何在禁用專用連結和出口的情況下設置 Azure AI Foundry,使用 Microsoft 管理的密鑰進行加密,並使用 Microsoft 管理的標識配置為 AI 資源。
Azure 認知搜尋服務 此範本會建立 Azure 認知搜尋服務
具有使用者受控識別的網路保護代理程式 這組範本示範如何使用 AI 服務 / AOAI 連線的使用者受控識別驗證和專用網連結,設定具有虛擬網路隔離的 Azure AI 代理程式服務,以將代理程式連線到您的安全數據。
標準代理程式設定 這組範本示範如何使用標準設定來設定 Azure AI 代理程式服務,這表示已啟用專案/中樞連線和公用因特網存取的受控識別驗證。 代理程式會使用客戶擁有的單一租用戶搜尋和記憶體資源。 透過此設定,您可以完全控制這些資源並查看這些資源,但會根據您的使用量產生成本。

資源格式

若要建立 Microsoft.Search/searchServices 資源,請將下列 Bicep 新增至範本。

resource symbolicname 'Microsoft.Search/searchServices@2026-09-01-preview' = {
  identity: {
    type: 'string'
    userAssignedIdentities: {
      {customized property}: {}
    }
  }
  location: 'string'
  name: 'string'
  properties: {
    authOptions: {
      aadOrApiKey: {
        aadAuthFailureMode: 'string'
      }
      apiKeyOnly: any(...)
    }
    autoGeneratedDomainNameLabelScope: 'string'
    computeType: 'string'
    dataExfiltrationProtections: [
      'string'
    ]
    disableLocalAuth: bool
    encryptionWithCmk: {
      enforcement: 'string'
      serviceLevelEncryptionKey: {
        accessCredentials: {
          applicationId: 'string'
          applicationSecret: 'string'
        }
        identity: {
          @odata.type: 'string'
          // For remaining properties, see DataIdentity objects
        }
        keyVaultKeyName: 'string'
        keyVaultKeyVersion: 'string'
        keyVaultUri: 'string'
      }
    }
    endpoint: 'string'
    hostingMode: 'string'
    knowledgeRetrieval: 'string'
    networkRuleSet: {
      bypass: 'string'
      ipRules: [
        {
          value: 'string'
        }
      ]
    }
    partitionCount: int
    publicNetworkAccess: 'string'
    replicaCount: int
    semanticSearch: 'string'
    upgradeAvailable: 'string'
  }
  sku: {
    name: 'string'
  }
  tags: {
    {customized property}: 'string'
  }
}

DataIdentity 物件

設定 @odata.type 屬性以指定物件的類型。

針對 #Microsoft.Azure.Search.DataNoneIdentity,請使用:

{
  @odata.type: '#Microsoft.Azure.Search.DataNoneIdentity'
}

針對 #Microsoft.Azure.Search.DataUserAssignedIdentity,請使用:

{
  @odata.type: '#Microsoft.Azure.Search.DataUserAssignedIdentity'
  federatedIdentityClientId: 'string'
  userAssignedIdentity: 'string'
}

屬性值

Microsoft。搜尋/搜尋服務

Name Description 價值觀
身分識別 資源的身分識別。 Identity
位置 資源所在的地理位置 字串 (必要)
名字 資源名稱 string

約束:
模式 = ^(?=.{2,60}$)[a-z0-9][a-z0-9]+(-[a-z0-9]+)*$ (必要)
properties 搜尋服務的屬性。 SearchServiceProperties
sku 搜尋服務的 SKU,決定價格區間和容量限制。 建立新的搜尋服務時,需要這個屬性。 Sku
tags 資源標籤 標記名稱和值的字典。 請參考模板中的標籤

AzureActiveDirectoryApplicationCredentials

Name Description 價值觀
應用程式ID 租戶中應用程式註冊的應用程式(用戶端)ID。 字串
應用程式密碼 一個用於 Azure Key Vault 認證的 App Registration 產生的 AAD 用戶端秘密。 string

約束:
敏感性值。 以安全參數的形式傳入。

資料身分識別

Name Description 價值觀
@odata.type 針對 DataNoneIdentity 類型設定為 '#Microsoft.Azure.Search.DataNoneIdentity'。 針對 DataUserAssignedIdentity 類型設定為 '#Microsoft.Azure.Search.DataUserAssignedIdentity'。 '#Microsoft.Azure.Search.DataNoneIdentity'
'#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)

DataNone身分識別

Name Description 價值觀
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataNoneIdentity' (必要)

DataPlaneAadOrApiKeyAuthOption

Name Description 價值觀
aadAuthFailureMode 描述搜尋服務的數據平面 API 會針對驗證失敗的要求傳送哪些回應。 'http401WithBearerChallenge'
'http403'

DataPlaneAuthOptions

Name Description 價值觀
aadOrApiKey 表示 API 金鑰或 Microsoft Entra ID 租戶的存取權杖可用於認證。 DataPlaneAadOrApiKeyAuthOption
apiKeyOnly 表示只能使用 API 金鑰進行驗證。 任何

DataUserAssigned身分識別

Name Description 價值觀
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)
federatedIdentityClientId 多租戶 User-Assigned 管理身份 CMK 支援的選配:多租戶應用程式註冊的用戶端 ID(UUID)已設定與 userAssignedIdentity 聯合。 字串
userAssignedIdentity 使用者指派受控識別的完整 Azure 資源標識符,通常格式為 “/subscriptions/12345678-1234-1234-1234-1234567890ab/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId”。 字串 (必要)

EncryptionWithCmk 的

Name Description 價值觀
執法 描述搜尋服務在找到未使用客戶管理密鑰加密的物件時,應如何強制執行合規性。 “已禁用”
“已啟用”
“未指定”
serviceLevelEncryption金鑰 描述由客戶管理的加密搜尋服務金鑰配置。 SearchResourceEncryptionKey

身份

Name Description 價值觀
型別 用於資源的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含系統所建立的身分識別和一組使用者指派的身分識別。 類型 『None』 會從服務中移除所有身分識別。 “無”
“系統分配”
'SystemAssigned, UserAssigned'
“UserAssigned”(必需)
userAssignedIdentities 與資源相關聯的使用者身分識別清單。 使用者身份字典的金鑰參考將是 ARM 資源 ID,形式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'. IdentityUserAssignedIdentities

IdentityUserAssignedIdentities

Name Description 價值觀

IpRule (英语)

Name Description 價值觀
value 對應至單一 IPv4 位址的值(例如 123.1.2.3)或 CIDR 格式的 IP 範圍(例如 123.1.2.3/24)。 字串

NetworkRuleSet 網路規則集

Name Description 價值觀
旁路 可略過 『ipRules』 區段中所定義規則之輸入流量的可能來源。 “AzurePortal”
“Azure服務”
“無”
ip規則 IP 限制規則清單,定義允許存取搜尋服務端點的輸入網路。 同時,所有其他公用IP網路都會遭到防火牆封鎖。 只有在搜尋服務的 'publicNetworkAccess' 已啟用時,才會套用這些限制規則;否則,即使有任何公用IP規則,也不允許透過公用介面的流量,而私人端點聯機會是獨佔存取方法。 IpRule[]

SearchResourceEncryptionKey

Name Description 價值觀
accessCredentials 可選的 Azure Active Directory 憑證用於存取你的 Azure Key Vault。 如果改用受控識別,則不需要。 AzureActiveDirectoryApplicationCredentials
身分識別 要用於此加密金鑰的明確受控識別。 如果未指定,且存取認證屬性為 Null,則會使用系統指派的受控識別。 更新資源時,如果未指定明確識別,則會維持不變。 如果指定了 「none」 ,則會清除此屬性的值。 資料身分識別
keyVaultKeyName 要用來加密待用數據的 Azure Key Vault 金鑰名稱。 字串
keyVaultKeyVersion 要用來加密待用數據的 Azure Key Vault 金鑰版本。 字串
keyVaultUri Azure Key Vault 的 URI,也稱為 DNS 名稱,其中包含用來加密待用數據的密鑰。 範例 URI 可能會 https://my-keyvault-name.vault.azure.net。 字串

SearchServiceProperties

Name Description 價值觀
authOptions 定義搜尋服務數據平面 API 如何驗證要求的選項。 如果 'disableLocalAuth' 設定為 true,則無法設定此設定。 DataPlaneAuthOptions
autoGeneratedDomainNameLabelScope 定義搜尋服務自動產生網域名稱標籤的重用程度(例如 myservice-uniqueId.search.windows.net<>)。 若未指定,則不會為搜尋服務建立自動產生的網域名稱標籤。 '禁止重複使用'
“訂閱重用”
“TenantReuse”
computeType 設定此屬性以支援搜尋服務,使用預設運算或 Azure 機密運算。 '機密'
'Default'
dataExfiltrationProtections 明確不允許搜尋服務的數據外流案例清單。 目前,唯一支援的值是 『All』,以停用所有可能的數據匯出案例,並針對未來規劃更精細的控制。 包含任何的字串數組:
'BlockAll'
disableLocalAuth 當設定為 true 時,不允許對搜尋服務的呼叫利用 API 金鑰進行驗證。 如果已定義 『dataPlaneAuthOptions』,則無法設定為 true。 布爾 (bool)
encryptionWithCmk 指定在搜尋服務中使用客戶經理密鑰加密資源(例如索引)的任何原則。 EncryptionWithCmk 的
端點 Azure AI 搜尋服務 服務的端點。 字串
hostingMode 僅適用於 standard3 SKU。 您可以設定此屬性來啟用最多 3 個高密度分割區,允許最多 1000 個索引,這遠高於任何其他 SKU 允許的最大索引。 對於 standard3 SKU,值為 'Default' 或 'HighDensity'。 對於所有其他 SKU,此值必須為「預設」。 'Default'
“高密度”
知識檢索 指定 Azure AI 搜尋服務 服務上的代理檢索計費計劃。 此配置僅在特定地區的特定價格層級提供。 “免費”
'standard'
networkRuleSet 網路規則集 網路特定的規則決定如何存取 Azure AI 搜尋服務 服務。 NetworkRuleSet 網路規則集
partitionCount 專用搜尋服務中的分割區數量;若有指定,可以是1、2、3、4、6或12。 大於 1 的值僅適用於標準 SKU。 對於 hostingMode 設定為 'highDensity' 的 'standard3' 服務,允許的值介於 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
publicNetworkAccess 此值可以設定為「已啟用」,以避免對現有客戶資源和範本進行重大變更。 如果設定為「已停用」,則不允許透過公用介面進行流量,而專用端點連線會是獨佔存取方法。 “已禁用”
“已啟用”
“SecuredByPerimeter”
replicaCount 專用搜尋服務中的複本數量。 如果指定,它必須是標準 SKU 的 1 到 12 之間的值,或基本 SKU 的 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
語義搜索 規定 Azure AI 搜尋服務 服務語意搜尋的可用性與計費計畫。 此配置僅在特定地區的特定價格層級提供。 '已禁用'
“免費”
'standard'
upgrade可用 指出搜尋服務是否有可用的升級。 '可用'
'notAvailable'

Sku

Name Description 價值觀
名字 搜尋服務的 SKU。 有效值包括:「免費」:共享服務。 'basic':最多 3 個複本的專用服務。 'standard': 專用服務,最多可有 12 個分割區和 12 個復本。 'standard2':類似於標準,但每個搜尋單位的容量較多。 'standard3':最大標準供應專案,最多可有 12 個分割區和 12 個復本(如果您也將 hostingMode 屬性設定為 'highDensity',則最多 3 個具有更多索引的數據分割)。 'storage_optimized_l1':支援每個分割區 1TB,最多 12 個分割區。 「storage_optimized_l2」:支援每個分割區 2TB,最多可支援 12 個分割區。 「無伺服器」:無伺服器層級,具備自動擴展功能。 'basic'
“免費”
「無伺服器」
'standard'
'標準 2'
'標準3'
“storage_optimized_l1”
“storage_optimized_l2”

TrackedResourceTags

Name Description 價值觀

UserAssignedIdentity

Name Description 價值觀

ARM 樣本資源定義

searchServices 資源類型可以使用目標作業來部署:

使用範例

Azure 快速入門範本

下列 Azure 快速入門範本 部署此資源類型。

Template Description
Azure AI Foundry 網路受限

部署至Azure
這組範本演示了如何在禁用專用連結和出口的情況下設置 Azure AI Foundry,使用 Microsoft 管理的密鑰進行加密,並使用 Microsoft 管理的標識配置為 AI 資源。
Azure 認知搜尋服務

部署至Azure
此範本會建立 Azure 認知搜尋服務
使用私人端點 Azure 認知搜尋服務

部署至Azure
此範本會建立具有私人端點的 Azure 認知搜尋服務。
具有使用者受控識別的網路保護代理程式

部署至Azure
這組範本示範如何使用 AI 服務 / AOAI 連線的使用者受控識別驗證和專用網連結,設定具有虛擬網路隔離的 Azure AI 代理程式服務,以將代理程式連線到您的安全數據。
標準代理程式設定

部署至Azure
這組範本示範如何使用標準設定來設定 Azure AI 代理程式服務,這表示已啟用專案/中樞連線和公用因特網存取的受控識別驗證。 代理程式會使用客戶擁有的單一租用戶搜尋和記憶體資源。 透過此設定,您可以完全控制這些資源並查看這些資源,但會根據您的使用量產生成本。
使用 SQL Database、Azure Cosmos DB、Azure 搜尋服務 Web 應用程式

部署至Azure
此範本會布建 Web 應用程式、SQL Database、Azure Cosmos DB、Azure 搜尋服務和 Application Insights。

資源格式

若要建立 Microsoft.Search/searchServices 資源,請將下列 JSON 新增至範本。

{
  "type": "Microsoft.Search/searchServices",
  "apiVersion": "2026-09-01-preview",
  "name": "string",
  "identity": {
    "type": "string",
    "userAssignedIdentities": {
      "{customized property}": {
      }
    }
  },
  "location": "string",
  "properties": {
    "authOptions": {
      "aadOrApiKey": {
        "aadAuthFailureMode": "string"
      },
      "apiKeyOnly": {}
    },
    "autoGeneratedDomainNameLabelScope": "string",
    "computeType": "string",
    "dataExfiltrationProtections": [ "string" ],
    "disableLocalAuth": "bool",
    "encryptionWithCmk": {
      "enforcement": "string",
      "serviceLevelEncryptionKey": {
        "accessCredentials": {
          "applicationId": "string",
          "applicationSecret": "string"
        },
        "identity": {
          "@odata.type": "string"
          // For remaining properties, see DataIdentity objects
        },
        "keyVaultKeyName": "string",
        "keyVaultKeyVersion": "string",
        "keyVaultUri": "string"
      }
    },
    "endpoint": "string",
    "hostingMode": "string",
    "knowledgeRetrieval": "string",
    "networkRuleSet": {
      "bypass": "string",
      "ipRules": [
        {
          "value": "string"
        }
      ]
    },
    "partitionCount": "int",
    "publicNetworkAccess": "string",
    "replicaCount": "int",
    "semanticSearch": "string",
    "upgradeAvailable": "string"
  },
  "sku": {
    "name": "string"
  },
  "tags": {
    "{customized property}": "string"
  }
}

DataIdentity 物件

設定 @odata.type 屬性以指定物件的類型。

針對 #Microsoft.Azure.Search.DataNoneIdentity,請使用:

{
  "@odata.type": "#Microsoft.Azure.Search.DataNoneIdentity"
}

針對 #Microsoft.Azure.Search.DataUserAssignedIdentity,請使用:

{
  "@odata.type": "#Microsoft.Azure.Search.DataUserAssignedIdentity",
  "federatedIdentityClientId": "string",
  "userAssignedIdentity": "string"
}

屬性值

Microsoft。搜尋/搜尋服務

Name Description 價值觀
apiVersion API 版本 『2026-09-01-預覽』
身分識別 資源的身分識別。 Identity
位置 資源所在的地理位置 字串 (必要)
名字 資源名稱 string

約束:
模式 = ^(?=.{2,60}$)[a-z0-9][a-z0-9]+(-[a-z0-9]+)*$ (必要)
properties 搜尋服務的屬性。 SearchServiceProperties
sku 搜尋服務的 SKU,決定價格區間和容量限制。 建立新的搜尋服務時,需要這個屬性。 Sku
tags 資源標籤 標記名稱和值的字典。 請參考模板中的標籤
型別 資源類型 “Microsoft.Search/searchServices”

AzureActiveDirectoryApplicationCredentials

Name Description 價值觀
應用程式ID 租戶中應用程式註冊的應用程式(用戶端)ID。 字串
應用程式密碼 一個用於 Azure Key Vault 認證的 App Registration 產生的 AAD 用戶端秘密。 string

約束:
敏感性值。 以安全參數的形式傳入。

資料身分識別

Name Description 價值觀
@odata.type 針對 DataNoneIdentity 類型設定為 '#Microsoft.Azure.Search.DataNoneIdentity'。 針對 DataUserAssignedIdentity 類型設定為 '#Microsoft.Azure.Search.DataUserAssignedIdentity'。 '#Microsoft.Azure.Search.DataNoneIdentity'
'#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)

DataNone身分識別

Name Description 價值觀
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataNoneIdentity' (必要)

DataPlaneAadOrApiKeyAuthOption

Name Description 價值觀
aadAuthFailureMode 描述搜尋服務的數據平面 API 會針對驗證失敗的要求傳送哪些回應。 'http401WithBearerChallenge'
'http403'

DataPlaneAuthOptions

Name Description 價值觀
aadOrApiKey 表示 API 金鑰或 Microsoft Entra ID 租戶的存取權杖可用於認證。 DataPlaneAadOrApiKeyAuthOption
apiKeyOnly 表示只能使用 API 金鑰進行驗證。 任何

DataUserAssigned身分識別

Name Description 價值觀
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)
federatedIdentityClientId 多租戶 User-Assigned 管理身份 CMK 支援的選配:多租戶應用程式註冊的用戶端 ID(UUID)已設定與 userAssignedIdentity 聯合。 字串
userAssignedIdentity 使用者指派受控識別的完整 Azure 資源標識符,通常格式為 “/subscriptions/12345678-1234-1234-1234-1234567890ab/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId”。 字串 (必要)

EncryptionWithCmk 的

Name Description 價值觀
執法 描述搜尋服務在找到未使用客戶管理密鑰加密的物件時,應如何強制執行合規性。 “已禁用”
“已啟用”
“未指定”
serviceLevelEncryption金鑰 描述由客戶管理的加密搜尋服務金鑰配置。 SearchResourceEncryptionKey

身份

Name Description 價值觀
型別 用於資源的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含系統所建立的身分識別和一組使用者指派的身分識別。 類型 『None』 會從服務中移除所有身分識別。 “無”
“系統分配”
'SystemAssigned, UserAssigned'
“UserAssigned”(必需)
userAssignedIdentities 與資源相關聯的使用者身分識別清單。 使用者身份字典的金鑰參考將是 ARM 資源 ID,形式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'. IdentityUserAssignedIdentities

IdentityUserAssignedIdentities

Name Description 價值觀

IpRule (英语)

Name Description 價值觀
value 對應至單一 IPv4 位址的值(例如 123.1.2.3)或 CIDR 格式的 IP 範圍(例如 123.1.2.3/24)。 字串

NetworkRuleSet 網路規則集

Name Description 價值觀
旁路 可略過 『ipRules』 區段中所定義規則之輸入流量的可能來源。 “AzurePortal”
“Azure服務”
“無”
ip規則 IP 限制規則清單,定義允許存取搜尋服務端點的輸入網路。 同時,所有其他公用IP網路都會遭到防火牆封鎖。 只有在搜尋服務的 'publicNetworkAccess' 已啟用時,才會套用這些限制規則;否則,即使有任何公用IP規則,也不允許透過公用介面的流量,而私人端點聯機會是獨佔存取方法。 IpRule[]

SearchResourceEncryptionKey

Name Description 價值觀
accessCredentials 可選的 Azure Active Directory 憑證用於存取你的 Azure Key Vault。 如果改用受控識別,則不需要。 AzureActiveDirectoryApplicationCredentials
身分識別 要用於此加密金鑰的明確受控識別。 如果未指定,且存取認證屬性為 Null,則會使用系統指派的受控識別。 更新資源時,如果未指定明確識別,則會維持不變。 如果指定了 「none」 ,則會清除此屬性的值。 資料身分識別
keyVaultKeyName 要用來加密待用數據的 Azure Key Vault 金鑰名稱。 字串
keyVaultKeyVersion 要用來加密待用數據的 Azure Key Vault 金鑰版本。 字串
keyVaultUri Azure Key Vault 的 URI,也稱為 DNS 名稱,其中包含用來加密待用數據的密鑰。 範例 URI 可能會 https://my-keyvault-name.vault.azure.net。 字串

SearchServiceProperties

Name Description 價值觀
authOptions 定義搜尋服務數據平面 API 如何驗證要求的選項。 如果 'disableLocalAuth' 設定為 true,則無法設定此設定。 DataPlaneAuthOptions
autoGeneratedDomainNameLabelScope 定義搜尋服務自動產生網域名稱標籤的重用程度(例如 myservice-uniqueId.search.windows.net<>)。 若未指定,則不會為搜尋服務建立自動產生的網域名稱標籤。 '禁止重複使用'
“訂閱重用”
“TenantReuse”
computeType 設定此屬性以支援搜尋服務,使用預設運算或 Azure 機密運算。 '機密'
'Default'
dataExfiltrationProtections 明確不允許搜尋服務的數據外流案例清單。 目前,唯一支援的值是 『All』,以停用所有可能的數據匯出案例,並針對未來規劃更精細的控制。 包含任何的字串數組:
'BlockAll'
disableLocalAuth 當設定為 true 時,不允許對搜尋服務的呼叫利用 API 金鑰進行驗證。 如果已定義 『dataPlaneAuthOptions』,則無法設定為 true。 布爾 (bool)
encryptionWithCmk 指定在搜尋服務中使用客戶經理密鑰加密資源(例如索引)的任何原則。 EncryptionWithCmk 的
端點 Azure AI 搜尋服務 服務的端點。 字串
hostingMode 僅適用於 standard3 SKU。 您可以設定此屬性來啟用最多 3 個高密度分割區,允許最多 1000 個索引,這遠高於任何其他 SKU 允許的最大索引。 對於 standard3 SKU,值為 'Default' 或 'HighDensity'。 對於所有其他 SKU,此值必須為「預設」。 'Default'
“高密度”
知識檢索 指定 Azure AI 搜尋服務 服務上的代理檢索計費計劃。 此配置僅在特定地區的特定價格層級提供。 “免費”
'standard'
networkRuleSet 網路規則集 網路特定的規則決定如何存取 Azure AI 搜尋服務 服務。 NetworkRuleSet 網路規則集
partitionCount 專用搜尋服務中的分割區數量;若有指定,可以是1、2、3、4、6或12。 大於 1 的值僅適用於標準 SKU。 對於 hostingMode 設定為 'highDensity' 的 'standard3' 服務,允許的值介於 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
publicNetworkAccess 此值可以設定為「已啟用」,以避免對現有客戶資源和範本進行重大變更。 如果設定為「已停用」,則不允許透過公用介面進行流量,而專用端點連線會是獨佔存取方法。 “已禁用”
“已啟用”
“SecuredByPerimeter”
replicaCount 專用搜尋服務中的複本數量。 如果指定,它必須是標準 SKU 的 1 到 12 之間的值,或基本 SKU 的 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
語義搜索 規定 Azure AI 搜尋服務 服務語意搜尋的可用性與計費計畫。 此配置僅在特定地區的特定價格層級提供。 '已禁用'
“免費”
'standard'
upgrade可用 指出搜尋服務是否有可用的升級。 '可用'
'notAvailable'

Sku

Name Description 價值觀
名字 搜尋服務的 SKU。 有效值包括:「免費」:共享服務。 'basic':最多 3 個複本的專用服務。 'standard': 專用服務,最多可有 12 個分割區和 12 個復本。 'standard2':類似於標準,但每個搜尋單位的容量較多。 'standard3':最大標準供應專案,最多可有 12 個分割區和 12 個復本(如果您也將 hostingMode 屬性設定為 'highDensity',則最多 3 個具有更多索引的數據分割)。 'storage_optimized_l1':支援每個分割區 1TB,最多 12 個分割區。 「storage_optimized_l2」:支援每個分割區 2TB,最多可支援 12 個分割區。 「無伺服器」:無伺服器層級,具備自動擴展功能。 'basic'
“免費”
「無伺服器」
'standard'
'標準 2'
'標準3'
“storage_optimized_l1”
“storage_optimized_l2”

TrackedResourceTags

Name Description 價值觀

UserAssignedIdentity

Name Description 價值觀

Terraform (AzAPI 提供者) 資源定義

searchServices 資源類型可以使用目標作業來部署:

  • 資源團體 關於每個 API 版本變更屬性的清單,請參見 變更日誌。

使用範例

Terraform 範例

部署 Search Service 的基本範例。

terraform {
  required_providers {
    azapi = {
      source = "Azure/azapi"
    }
  }
}

provider "azapi" {
  skip_provider_registration = false
}

variable "resource_name" {
  type    = string
  default = "acctest0001"
}

variable "location" {
  type    = string
  default = "westeurope"
}

resource "azapi_resource" "resourceGroup" {
  type     = "Microsoft.Resources/resourceGroups@2020-06-01"
  name     = var.resource_name
  location = var.location
}

resource "azapi_resource" "searchService" {
  type      = "Microsoft.Search/searchServices@2022-09-01"
  parent_id = azapi_resource.resourceGroup.id
  name      = var.resource_name
  location  = var.location
  body = {
    properties = {
      authOptions = {
        apiKeyOnly = {
        }
      }
      disableLocalAuth = false
      encryptionWithCmk = {
        enforcement = "Disabled"
      }
      hostingMode = "default"
      networkRuleSet = {
        ipRules = [
        ]
      }
      partitionCount      = 1
      publicNetworkAccess = "Enabled"
      replicaCount        = 1
    }
    sku = {
      name = "standard"
    }
    tags = {
      environment = "staging"
    }
  }
  schema_validation_enabled = false
  response_export_values    = ["*"]
}

Azure 已驗證的模組

下列 Azure 驗證模組 可用來部署此資源類型。

模組 Description
搜尋服務 搜尋服務的 AVM 資源模組

資源格式

若要建立 Microsoft.Search/searchServices 資源,請將下列 Terraform 新增至範本。

resource "azapi_resource" "symbolicname" {
  type = "Microsoft.Search/searchServices@2026-09-01-preview"
  name = "string"
  parent_id = "string"
  identity {
    type = "string"
    identity_ids = [
      "string"
    ]
  }
  location = "string"
  tags = {
    {customized property} = "string"
  }
  body = {
    properties = {
      authOptions = {
        aadOrApiKey = {
          aadAuthFailureMode = "string"
        }
        apiKeyOnly = ?
      }
      autoGeneratedDomainNameLabelScope = "string"
      computeType = "string"
      dataExfiltrationProtections = [
        "string"
      ]
      disableLocalAuth = bool
      encryptionWithCmk = {
        enforcement = "string"
        serviceLevelEncryptionKey = {
          accessCredentials = {
            applicationId = "string"
            applicationSecret = "string"
          }
          identity = {
            @odata.type = "string"
            // For remaining properties, see DataIdentity objects
          }
          keyVaultKeyName = "string"
          keyVaultKeyVersion = "string"
          keyVaultUri = "string"
        }
      }
      endpoint = "string"
      hostingMode = "string"
      knowledgeRetrieval = "string"
      networkRuleSet = {
        bypass = "string"
        ipRules = [
          {
            value = "string"
          }
        ]
      }
      partitionCount = int
      publicNetworkAccess = "string"
      replicaCount = int
      semanticSearch = "string"
      upgradeAvailable = "string"
    }
    sku = {
      name = "string"
    }
  }
}

DataIdentity 物件

設定 @odata.type 屬性以指定物件的類型。

針對 #Microsoft.Azure.Search.DataNoneIdentity,請使用:

{
  @odata.type = "#Microsoft.Azure.Search.DataNoneIdentity"
}

針對 #Microsoft.Azure.Search.DataUserAssignedIdentity,請使用:

{
  @odata.type = "#Microsoft.Azure.Search.DataUserAssignedIdentity"
  federatedIdentityClientId = "string"
  userAssignedIdentity = "string"
}

屬性值

Microsoft。搜尋/搜尋服務

Name Description 價值觀
身分識別 資源的身分識別。 Identity
位置 資源所在的地理位置 字串 (必要)
名字 資源名稱 string

約束:
模式 = ^(?=.{2,60}$)[a-z0-9][a-z0-9]+(-[a-z0-9]+)*$ (必要)
properties 搜尋服務的屬性。 SearchServiceProperties
sku 搜尋服務的 SKU,決定價格區間和容量限制。 建立新的搜尋服務時,需要這個屬性。 Sku
tags 資源標籤 標記名稱和值的字典。
型別 資源類型 「Microsoft。搜尋/searchServices@2026-09-01-預覽」

AzureActiveDirectoryApplicationCredentials

Name Description 價值觀
應用程式ID 租戶中應用程式註冊的應用程式(用戶端)ID。 字串
應用程式密碼 一個用於 Azure Key Vault 認證的 App Registration 產生的 AAD 用戶端秘密。 string

約束:
敏感性值。 以安全參數的形式傳入。

資料身分識別

Name Description 價值觀
@odata.type 針對 DataNoneIdentity 類型設定為 '#Microsoft.Azure.Search.DataNoneIdentity'。 針對 DataUserAssignedIdentity 類型設定為 '#Microsoft.Azure.Search.DataUserAssignedIdentity'。 '#Microsoft.Azure.Search.DataNoneIdentity'
'#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)

DataNone身分識別

Name Description 價值觀
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataNoneIdentity' (必要)

DataPlaneAadOrApiKeyAuthOption

Name Description 價值觀
aadAuthFailureMode 描述搜尋服務的數據平面 API 會針對驗證失敗的要求傳送哪些回應。 'http401WithBearerChallenge'
'http403'

DataPlaneAuthOptions

Name Description 價值觀
aadOrApiKey 表示 API 金鑰或 Microsoft Entra ID 租戶的存取權杖可用於認證。 DataPlaneAadOrApiKeyAuthOption
apiKeyOnly 表示只能使用 API 金鑰進行驗證。 任何

DataUserAssigned身分識別

Name Description 價值觀
@odata.type 指定身分類型的 URI 片段。 '#Microsoft.Azure.Search.DataUserAssignedIdentity' (必要)
federatedIdentityClientId 多租戶 User-Assigned 管理身份 CMK 支援的選配:多租戶應用程式註冊的用戶端 ID(UUID)已設定與 userAssignedIdentity 聯合。 字串
userAssignedIdentity 使用者指派受控識別的完整 Azure 資源標識符,通常格式為 “/subscriptions/12345678-1234-1234-1234-1234567890ab/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId”。 字串 (必要)

EncryptionWithCmk 的

Name Description 價值觀
執法 描述搜尋服務在找到未使用客戶管理密鑰加密的物件時,應如何強制執行合規性。 “已禁用”
“已啟用”
“未指定”
serviceLevelEncryption金鑰 描述由客戶管理的加密搜尋服務金鑰配置。 SearchResourceEncryptionKey

身份

Name Description 價值觀
型別 用於資源的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含系統所建立的身分識別和一組使用者指派的身分識別。 類型 『None』 會從服務中移除所有身分識別。 “無”
“系統分配”
'SystemAssigned, UserAssigned'
“UserAssigned”(必需)
userAssignedIdentities 與資源相關聯的使用者身分識別清單。 使用者身份字典的金鑰參考將是 ARM 資源 ID,形式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'. IdentityUserAssignedIdentities

IdentityUserAssignedIdentities

Name Description 價值觀

IpRule (英语)

Name Description 價值觀
value 對應至單一 IPv4 位址的值(例如 123.1.2.3)或 CIDR 格式的 IP 範圍(例如 123.1.2.3/24)。 字串

NetworkRuleSet 網路規則集

Name Description 價值觀
旁路 可略過 『ipRules』 區段中所定義規則之輸入流量的可能來源。 “AzurePortal”
“Azure服務”
“無”
ip規則 IP 限制規則清單,定義允許存取搜尋服務端點的輸入網路。 同時,所有其他公用IP網路都會遭到防火牆封鎖。 只有在搜尋服務的 'publicNetworkAccess' 已啟用時,才會套用這些限制規則;否則,即使有任何公用IP規則,也不允許透過公用介面的流量,而私人端點聯機會是獨佔存取方法。 IpRule[]

SearchResourceEncryptionKey

Name Description 價值觀
accessCredentials 可選的 Azure Active Directory 憑證用於存取你的 Azure Key Vault。 如果改用受控識別,則不需要。 AzureActiveDirectoryApplicationCredentials
身分識別 要用於此加密金鑰的明確受控識別。 如果未指定,且存取認證屬性為 Null,則會使用系統指派的受控識別。 更新資源時,如果未指定明確識別,則會維持不變。 如果指定了 「none」 ,則會清除此屬性的值。 資料身分識別
keyVaultKeyName 要用來加密待用數據的 Azure Key Vault 金鑰名稱。 字串
keyVaultKeyVersion 要用來加密待用數據的 Azure Key Vault 金鑰版本。 字串
keyVaultUri Azure Key Vault 的 URI,也稱為 DNS 名稱,其中包含用來加密待用數據的密鑰。 範例 URI 可能會 https://my-keyvault-name.vault.azure.net。 字串

SearchServiceProperties

Name Description 價值觀
authOptions 定義搜尋服務數據平面 API 如何驗證要求的選項。 如果 'disableLocalAuth' 設定為 true,則無法設定此設定。 DataPlaneAuthOptions
autoGeneratedDomainNameLabelScope 定義搜尋服務自動產生網域名稱標籤的重用程度(例如 myservice-uniqueId.search.windows.net<>)。 若未指定,則不會為搜尋服務建立自動產生的網域名稱標籤。 '禁止重複使用'
“訂閱重用”
“TenantReuse”
computeType 設定此屬性以支援搜尋服務,使用預設運算或 Azure 機密運算。 '機密'
'Default'
dataExfiltrationProtections 明確不允許搜尋服務的數據外流案例清單。 目前,唯一支援的值是 『All』,以停用所有可能的數據匯出案例,並針對未來規劃更精細的控制。 包含任何的字串數組:
'BlockAll'
disableLocalAuth 當設定為 true 時,不允許對搜尋服務的呼叫利用 API 金鑰進行驗證。 如果已定義 『dataPlaneAuthOptions』,則無法設定為 true。 布爾 (bool)
encryptionWithCmk 指定在搜尋服務中使用客戶經理密鑰加密資源(例如索引)的任何原則。 EncryptionWithCmk 的
端點 Azure AI 搜尋服務 服務的端點。 字串
hostingMode 僅適用於 standard3 SKU。 您可以設定此屬性來啟用最多 3 個高密度分割區,允許最多 1000 個索引,這遠高於任何其他 SKU 允許的最大索引。 對於 standard3 SKU,值為 'Default' 或 'HighDensity'。 對於所有其他 SKU,此值必須為「預設」。 'Default'
“高密度”
知識檢索 指定 Azure AI 搜尋服務 服務上的代理檢索計費計劃。 此配置僅在特定地區的特定價格層級提供。 “免費”
'standard'
networkRuleSet 網路規則集 網路特定的規則決定如何存取 Azure AI 搜尋服務 服務。 NetworkRuleSet 網路規則集
partitionCount 專用搜尋服務中的分割區數量;若有指定,可以是1、2、3、4、6或12。 大於 1 的值僅適用於標準 SKU。 對於 hostingMode 設定為 'highDensity' 的 'standard3' 服務,允許的值介於 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
publicNetworkAccess 此值可以設定為「已啟用」,以避免對現有客戶資源和範本進行重大變更。 如果設定為「已停用」,則不允許透過公用介面進行流量,而專用端點連線會是獨佔存取方法。 “已禁用”
“已啟用”
“SecuredByPerimeter”
replicaCount 專用搜尋服務中的複本數量。 如果指定,它必須是標準 SKU 的 1 到 12 之間的值,或基本 SKU 的 1 到 3 之間。 int

約束:
最小值 = 1
最大值 = 12
語義搜索 規定 Azure AI 搜尋服務 服務語意搜尋的可用性與計費計畫。 此配置僅在特定地區的特定價格層級提供。 '已禁用'
“免費”
'standard'
upgrade可用 指出搜尋服務是否有可用的升級。 '可用'
'notAvailable'

Sku

Name Description 價值觀
名字 搜尋服務的 SKU。 有效值包括:「免費」:共享服務。 'basic':最多 3 個複本的專用服務。 'standard': 專用服務,最多可有 12 個分割區和 12 個復本。 'standard2':類似於標準,但每個搜尋單位的容量較多。 'standard3':最大標準供應專案,最多可有 12 個分割區和 12 個復本(如果您也將 hostingMode 屬性設定為 'highDensity',則最多 3 個具有更多索引的數據分割)。 'storage_optimized_l1':支援每個分割區 1TB,最多 12 個分割區。 「storage_optimized_l2」:支援每個分割區 2TB,最多可支援 12 個分割區。 「無伺服器」:無伺服器層級,具備自動擴展功能。 'basic'
“免費”
「無伺服器」
'standard'
'標準 2'
'標準3'
“storage_optimized_l1”
“storage_optimized_l2”

TrackedResourceTags

Name Description 價值觀

UserAssignedIdentity

Name Description 價值觀