You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure FrontDoor无法从Blob存储加载图片的配置排查求助

Azure FrontDoor 无法路由到Blob存储的配置修复方案

问题场景

已通过Terraform配置Blob存储与Azure FrontDoor(AFD)资源,直接访问Blob存储端点可正常获取图片,但使用AFD的两种URL格式(https://afd-endpoint-name.azurefd.net/images/image.png、https://afd-endpoint-name-a1234.z00.azurefd.net/image.png)均无法访问图片。

原Terraform配置如下:

resource "azurerm_storage_account" "website_storage" {
  name                       = "storagename"
  resource_group_name        = azurerm_resource_group.rg.name
  location                   = azurerm_resource_group.rg.location
  account_tier               = "Standard"
  account_replication_type   = "LRS"
  https_traffic_only_enabled = true
}

resource "azurerm_storage_container" "website_images" {
  name                  = "images"
  storage_account_id    = azurerm_storage_account.website_storage.id
  container_access_type = "blob"
}

resource "azurerm_cdn_frontdoor_profile" "fd_profile" {
  name                = "name-fd-profile"
  resource_group_name = azurerm_resource_group.rg.name
  sku_name            = "Standard_AzureFrontDoor" # Replace sku with sku_name

  tags = {
    environment = var.environment
  }
}

resource "azurerm_cdn_frontdoor_endpoint" "fd_endpoint_images" {
  name                     = "name-images"
  cdn_frontdoor_profile_id = azurerm_cdn_frontdoor_profile.fd_profile.id

  tags = {
    environment = var.environment
  }
}

resource "azurerm_cdn_frontdoor_origin" "image_storage_origin" {
  name                           = "image-storage-origin"
  cdn_frontdoor_origin_group_id  = azurerm_cdn_frontdoor_origin_group.fd_origin_group_images.id
  host_name                      = azurerm_storage_account.website_storage.primary_blob_endpoint
  certificate_name_check_enabled = true

  priority = 1
  weight   = 50
  enabled  = true
}

resource "azurerm_cdn_frontdoor_origin_group" "fd_origin_group_images" {
  name                     = "images-origin-group"
  cdn_frontdoor_profile_id = azurerm_cdn_frontdoor_profile.fd_profile.id

  health_probe {
    interval_in_seconds = 30
    protocol            = "Https"
    path                = "/images/"
  }

  load_balancing {
    additional_latency_in_milliseconds = 50
    sample_size                        = 4
    successful_samples_required        = 3
  }
}

resource "azurerm_cdn_frontdoor_route" "route_images" {
  name                      = "images-route"
  cdn_frontdoor_endpoint_id = azurerm_cdn_frontdoor_endpoint.fd_endpoint_images.id

  cdn_frontdoor_origin_ids = [
    azurerm_cdn_frontdoor_origin.image_storage_origin.id
  ]

  supported_protocols    = ["Https", "Http"]
  patterns_to_match      = ["/images/*"]
  https_redirect_enabled = true
  cdn_frontdoor_origin_group_id = azurerm_cdn_frontdoor_origin_group.fd_origin_group_images.id

  depends_on = [
    azurerm_cdn_frontdoor_origin_group.fd_origin_group_images,
    azurerm_cdn_frontdoor_origin.image_storage_origin
  ]
}

缺失配置及修复步骤

1. 修正健康探测路径

当前健康探测路径设置为/images/,但Blob容器的访问类型为blob时,无法直接访问容器根路径(会返回403/404),导致AFD将Origin标记为不健康,拒绝转发请求。

修改azurerm_cdn_frontdoor_origin_group的健康探测路径为容器内已存在的Blob文件路径:

resource "azurerm_cdn_frontdoor_origin_group" "fd_origin_group_images" {
  name                     = "images-origin-group"
  cdn_frontdoor_profile_id = azurerm_cdn_frontdoor_profile.fd_profile.id

  health_probe {
    interval_in_seconds = 30
    protocol            = "Https"
    path                = "/images/test.png" # 替换为你实际存在的Blob文件路径
  }

  load_balancing {
    additional_latency_in_milliseconds = 50
    sample_size                        = 4
    successful_samples_required        = 3
  }
}

2. 显式设置Origin主机头

虽然默认主机头与host_name一致,但显式设置可避免潜在的路由错误,确保Blob存储识别正确的请求来源:

resource "azurerm_cdn_frontdoor_origin" "image_storage_origin" {
  name                           = "image-storage-origin"
  cdn_frontdoor_origin_group_id  = azurerm_cdn_frontdoor_origin_group.fd_origin_group_images.id
  host_name                      = azurerm_storage_account.website_storage.primary_blob_endpoint
  origin_host_header             = azurerm_storage_account.website_storage.primary_blob_endpoint # 新增显式主机头配置
  certificate_name_check_enabled = true

  priority = 1
  weight   = 50
  enabled  = true
}

3. 强制HTTPS转发协议

由于存储账户已开启https_traffic_only_enabled = true,需确保AFD仅通过HTTPS转发请求到Blob存储,避免协议不兼容:

resource "azurerm_cdn_frontdoor_route" "route_images" {
  name                      = "images-route"
  cdn_frontdoor_endpoint_id = azurerm_cdn_frontdoor_endpoint.fd_endpoint_images.id

  cdn_frontdoor_origin_ids = [
    azurerm_cdn_frontdoor_origin.image_storage_origin.id
  ]

  supported_protocols    = ["Https", "Http"]
  patterns_to_match      = ["/images/*"]
  https_redirect_enabled = true
  cdn_frontdoor_origin_group_id = azurerm_cdn_frontdoor_origin_group.fd_origin_group_images.id
  forwarding_protocol    = "HttpsOnly" # 新增强制HTTPS转发配置

  depends_on = [
    azurerm_cdn_frontdoor_origin_group.fd_origin_group_images,
    azurerm_cdn_frontdoor_origin.image_storage_origin
  ]
}

4. 等待AFD部署完成

修改配置后,需等待Azure FrontDoor完成全局部署(通常需要5-10分钟),之后再测试访问。

内容的提问来源于stack exchange,提问作者BigDevJames

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 15:15:09