Terraform导入带count的Azure自定义主机名绑定失败问题排查
问题描述
在Azure环境中使用Terraform导入Staging环境的自定义主机名绑定,Staging槽位通过count变量控制(Acc/Prod环境设为1,其余为0)。当前绑定由其他团队创建后导入,代码片段及流水线执行错误如下:
相关代码
variable "web_app_slot_count" { type = number description = "Number of slots (0 or 1)" default = 0 # tfvars contains web_app_slot_count = 1 } resource "azurerm_windows_web_app_slot" "staging" { count = var.web_app_slot_count ... } resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl" { count = var.web_app_slot_count hostname = "${var.environment}-staging.rdc.nl" app_service_name = "${module.appservice_abc.name}/staging" resource_group_name = data.azurerm_resource_group.app.name ssl_state = "SniEnabled" thumbprint = data.azurerm_key_vault_certificate.ssl_certificate_staging[0].thumbprint } import { id = "/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl" to = azurerm_app_service_custom_hostname_binding.staging_abc_nl[0] }
执行错误日志
Providers required by state: provider[registry.terraform.io/hashicorp/azurerm] /agent/_work/_tool/terraform/1.11.2/x64/terraform apply -auto-approve -input=false /agent/_work/2/Acceptance.tfplan azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]: Importing... [id=/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl] azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]: Import complete [id=/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl] azurerm_app_service_custom_hostname_binding.staging_abc_nl[0]: Destroying... [id=/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/hostNameBindings/acc-staging.abc.nl] azurerm_app_service_custom_hostname_binding._staging_abc_nl[0]: Destruction complete after 9s azurerm_app_service_custom_hostname_binding._staging_abc_nl[0]: Creating... ╷ │ Error: creating/updating Custom Hostname Binding "acc-staging.abc.nl" (App Service "abc-acc-abc-we-app-001/staging" / Resource Group "abc-acc-we-app-rg-001"): web.AppsClient#CreateOrUpdateHostNameBinding: Failure responding to request: StatusCode=404 -- Original Error: autorest/azure: error response cannot be parsed: {"" '\x00' '\x00'} error: EOF │ │ with azurerm_app_service_custom_hostname_binding.staging_abc_nl[0], │ on compute.tf line 98, in resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl": │ 98: resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl" { │ ╵ ##[error]Error: The process '/agent/_work/_tool/terraform/1.11.2/x64/terraform' failed with exit code 1 Finishing: Terraform Apply
原因分析
- 导入ID路径错误:目标主机名绑定属于Web App槽位,但导入时使用的ID未包含
/slots/staging/路径,导致Terraform错误将其关联到主Web App而非Staging槽位,状态与实际资源不匹配。 - 自定义主机名绑定配置错误:绑定槽位时,错误地将槽位名称拼接到
app_service_name中,正确的做法是app_service_name仅填写父Web App名称,通过slot_name参数指定槽位。该错误导致创建请求无法定位到目标槽位,返回404。 - 配置与状态不匹配触发销毁重建:导入的状态与本地配置参数冲突,Terraform自动触发“销毁原有资源→创建新资源”流程,最终因配置错误导致创建失败。
解决方案
1. 修正自定义主机名绑定配置
修改azurerm_app_service_custom_hostname_binding.staging_abc_nl资源,移除app_service_name中的槽位后缀,添加slot_name参数关联到Staging槽位:
resource "azurerm_app_service_custom_hostname_binding" "staging_abc_nl" { count = var.web_app_slot_count hostname = "${var.environment}-staging.rdc.nl" app_service_name = module.appservice_abc.name # 仅填写父Web App的名称 slot_name = azurerm_windows_web_app_slot.staging[count.index].name # 关联槽位资源,或直接写"staging" resource_group_name = data.azurerm_resource_group.app.name ssl_state = "SniEnabled" thumbprint = data.azurerm_key_vault_certificate.ssl_certificate_staging[0].thumbprint }
2. 清理错误状态并重新导入
- 先移除错误的状态记录:
terraform state rm azurerm_app_service_custom_hostname_binding.staging_abc_nl[0] - 使用正确的槽位绑定ID重新导入:
terraform import azurerm_app_service_custom_hostname_binding.staging_abc_nl[0] "/subscriptions/12341234-1234-1234-1234-123412341234/resourceGroups/abc-acc-we-app-rg-001/providers/Microsoft.Web/sites/abc-acc-abc-we-app-001/slots/staging/hostNameBindings/acc-staging.abc.nl"
3. 验证并执行应用
执行terraform plan确认配置与状态一致,无销毁重建操作后,再执行terraform apply完成同步。
内容的提问来源于stack exchange,提问作者realbart
相关产品推荐
相关产品推荐

