Terraform创建关联Azure Function的Event Grid订阅失败:触发器类型不支持
问题背景
已通过Terraform完成Azure Function App及下属Function的部署,尝试创建EventGrid订阅以实现“存储账户容器存入文件时触发Function”,但执行terraform apply时失败,错误信息如下:
"Failed" "Unsupported Azure Function Trigger" "Can't add resource
/subscriptions/XXX-XXX-XXX-XXX/resourceGroups/dummy-rg/providers/Microsoft.Web/sites/test-function-app/functions/ProjectOutboxEventFunction
as a destination with unsupported Azure function triggers. Azure Event
Grid supports EventGrid Trigger type only."
----[start]---- {"id":"https://management.azure.com/subscriptions/XXX-XXX-XXX-XXX/providers/Microsoft.EventGrid/locations/uksouth/operationsStatus/FB17FC7E-D332-46F2-8D21-FCB01B35C542?api-version=2022-06-15","name":"fb17fc7e-d332-46f2-8d21-fcb01b35c542","status":"Failed","error":{"code":"Unsupported
Azure Function Trigger","message":"Can't add resource
/subscriptions/XXX-XXX-XXX-XXX/resourceGroups/dummy-rg/providers/Microsoft.Web/sites/test-function-app/functions/ProjectOutboxEventFunction
as a destination with unsupported Azure function triggers. Azure Event
Grid supports EventGrid Trigger type only."}}
-----[end]-----
错误原因
当前配置的Function使用httpTrigger类型,而EventGrid的azure_function_endpoint目标要求关联的Function必须使用EventGrid Trigger。若要通过HTTP Trigger接收EventGrid事件,需改用webhook_endpoint配置,而非azure_function_endpoint。
解决方案
方案1:将Function改为EventGrid Trigger(官方推荐)
EventGrid Trigger是Azure EventGrid与Function集成的原生方式,自动处理事件签名验证、格式解析,无需手动处理HTTP请求细节。
修改Function的Terraform代码,替换触发器类型:
resource "azurerm_function_app_function" "example" { depends_on = [module.create_fapp_re_id] name = local.reid_function_name function_app_id = module.create_fapp_re_id.function_app_id config_json = jsonencode({ "bindings" = [ { "direction" = "in" "name" = "eventGridEvent" "type" = "eventGridTrigger" }, { "direction" = "out" "name" = "$return" "type" = "http" }, ] }) }
EventGrid订阅代码保持原有azure_function_endpoint配置即可,无需修改。
方案2:保留HTTP Trigger,改用Webhook Endpoint
若需继续使用HTTP Trigger,需切换到webhook_endpoint配置,并确保Function访问密钥正确传入:
修改EventGrid订阅的Terraform代码:
resource "azurerm_eventgrid_event_subscription" "blob_created_sub" { depends_on = [module.create_fapp_re_id] name = "${var.env}-outbox-blob-created-sub" scope = module.create_reid_storage_account.id event_delivery_schema = "EventGridSchema" # 启用webhook endpoint,注释原azure_function_endpoint webhook_endpoint { url = "https://${module.create_fapp_re_id.function_app_name}.azurewebsites.net/api/${local.reid_function_name}?code=${data.azurerm_function_app_host_keys.host_key.default_function_key}" } included_event_types = ["Microsoft.Storage.BlobCreated"] advanced_filter { string_contains { values = ["outbox"] key = "subject" } } labels = ["blob", "outbox", "automation"] }
注意:需提前定义
data.azurerm_function_app_host_keys以获取Function的访问密钥:data "azurerm_function_app_host_keys" "host_key" { name = module.create_fapp_re_id.function_app_name resource_group_name = module.create_fapp_re_id.resource_group_name }
额外建议:使用HTTP Trigger时,需在Function代码中添加EventGrid签名验证逻辑,避免非法请求触发Function。
内容的提问来源于stack exchange,提问作者Ian Carrick

