You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform导入带count的Azure自定义主机名绑定失败问题排查

问题描述

在Azure环境中使用Terraform导入Staging环境的自定义主机名绑定,Staging槽位通过count变量控制(Acc/Prod环境设为1,其余为0)。当前绑定由其他团队创建后导入,代码片段及流水线执行错误如下:

相关代码

variable "web_app_slot_count" {
  type        = number
  description = "Number of slots (0 or 1)"
  default     = 0
  # tfvars contains web_app_slot_count = 1
}

resource "azurerm_windows_web_app_slot" "staging" {
  count          = var.web_app_slot_count
  ...
}

resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl" {
  count               = var.web_app_slot_count
  hostname            = "${var.environment}-staging.rdc.nl"
  app_service_name    = "${module.appservice_abc.name}/staging"
  resource_group_name = data.azurerm_resource_group.app.name
  ssl_state           = "SniEnabled"
  thumbprint          = data.azurerm_key_vault_certificate.ssl_certificate_staging[0].thumbprint
}

import {
  id = "/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl"
  to = azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]
}

执行错误日志

Providers required by state:

    provider[registry.terraform.io/hashicorp/azurerm]

/agent/_work/_tool/terraform/1.11.2/x64/terraform apply -auto-approve -input=false /agent/_work/2/Acceptance.tfplan
azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]: Importing... [id=/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl]
azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]: Import complete [id=/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl]
azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]: Destroying... [id=/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl]
azurerm_app_service_custom_hostname_binding._staging_abc_nl[0]: Destruction complete after 9s
azurerm_app_service_custom_hostname_binding._staging_abc_nl[0]: Creating...
╷
│ Error: creating/updating Custom Hostname Binding "acc-staging.abc.nl" (App Service "abc-acc-abc-we-app-001/staging" / Resource Group "abc-acc-we-app-rg-001"): web.AppsClient#CreateOrUpdateHostNameBinding: Failure responding to request: StatusCode=404 -- Original Error: autorest/azure: error response cannot be parsed: {"" '\x00' '\x00'} error: EOF
│ 
│   with azurerm_app_service_custom_hostname_binding.staging_abc_nl[0],
│   on compute.tf line 98, in resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl":
│   98: resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl" {
│ 
╵

##[error]Error: The process '/agent/_work/_tool/terraform/1.11.2/x64/terraform' failed with exit code 1
Finishing: Terraform Apply

原因分析

  1. 导入ID路径错误:目标主机名绑定属于Web App槽位,但导入时使用的ID未包含/slots/staging/路径,导致Terraform错误将其关联到主Web App而非Staging槽位,状态与实际资源不匹配。
  2. 自定义主机名绑定配置错误:绑定槽位时,错误地将槽位名称拼接到app_service_name中,正确的做法是app_service_name仅填写父Web App名称,通过slot_name参数指定槽位。该错误导致创建请求无法定位到目标槽位,返回404。
  3. 配置与状态不匹配触发销毁重建:导入的状态与本地配置参数冲突,Terraform自动触发“销毁原有资源→创建新资源”流程,最终因配置错误导致创建失败。

解决方案

1. 修正自定义主机名绑定配置

修改azurerm_app_service_custom_hostname_binding.staging_abc_nl资源,移除app_service_name中的槽位后缀,添加slot_name参数关联到Staging槽位:

resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl" {
  count               = var.web_app_slot_count
  hostname            = "${var.environment}-staging.rdc.nl"
  app_service_name    = module.appservice_abc.name # 仅填写父Web App的名称
  slot_name           = azurerm_windows_web_app_slot.staging[count.index].name # 关联槽位资源,或直接写"staging"
  resource_group_name = data.azurerm_resource_group.app.name
  ssl_state           = "SniEnabled"
  thumbprint          = data.azurerm_key_vault_certificate.ssl_certificate_staging[0].thumbprint
}

2. 清理错误状态并重新导入

  • 先移除错误的状态记录:
    terraform state rm azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]
    
  • 使用正确的槽位绑定ID重新导入:
    terraform import azurerm_app_service_custom_hostname_binding.staging_abc_nl[0] "/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/slots/staging/hostNameBindings/acc-staging.abc.nl"
    

3. 验证并执行应用

执行terraform plan确认配置与状态一致,无销毁重建操作后,再执行terraform apply完成同步。

内容的提问来源于stack exchange,提问作者realbart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 21:24:56