移除子网内Azure Functions Flex Consumption SKU后子网陷入损坏状态
我们在开发环境中采用每日销毁并重新部署资源的策略以节约成本,其他资源均正常,但Azure Functions Flex Consumption SKU应用在重新部署到已委托给Microsoft.App/environments的子网时出现异常。
移除Function App时已按流程先断开虚拟网络连接再删除资源,使用的Azure CLI命令如下:
az webapp vnet-integration remove --name $resource.name --resource-group $resourceGroup.name az resource delete --ids $resource.id
重新部署同一Function App到同一子网时触发Internal Server Error,尝试删除或编辑子网时得到明确错误:
Failed to delete subnet 'xxxx'. Error: Subnet xxxx is in use by /subscriptions/xxxx/resourceGroups/xxxx/providers/Microsoft.Network/virtualNetworks/xxxx/subnets/xxxx/serviceAssociationLinks/legionservicelink and cannot be deleted. In order to delete the subnet, delete all the resources within the subnet.
其中legionservicelink是Function App关联遗留的资源,无法在订阅中找到并手动删除。即使已遵循微软建议的"先移除网络关联再删除应用"流程,问题仍存在。
问题重现步骤(仅Flex Apps受影响)
- 使用Bicep创建Flex Consumption SKU的Function App
- 使用Bicep将应用关联到子网
若不先断开子网关联或删除应用就重复执行上述两步,会触发问题:
- 重新用Bicep创建Function App时,因未指定网络配置,应用会尝试更新并移除网络关联,但实际未正确断开,导致子网处于异常关联状态
- 再次用Bicep关联子网时失败,因子网仍被遗留的
legionservicelink关联锁定
临时解决方案
在运行Bicep部署脚本前,提前使用Azure CLI命令断开Function App与虚拟网络的连接,确保子网关联被正确清理。
官方状态
微软已确认这是已知问题。
内容的提问来源于stack exchange,提问作者Crwydryn

