在VNet中部署Azure Function App出现内部服务器错误求助
问题:Flex Consumption函数应用部署到VNet时触发内部服务器错误
部署Flex Consumption(FC1)层级的Azure函数应用到VNet子网时,遇到内部服务器错误;但移除函数应用配置中的virtualNetworkSubnetId项后,部署可正常完成。尝试切换到ARM模板也无法解决问题。
完整Bicep模板
param productName string = 'funcapptest' param environment string = 'dev' param location string = 'North Europe' param managedIdentityName string = 'mi-${productName}-${environment}' param vnetResourceName string = 'vnet-${productName}-${environment}' param resourceNameNsgBusiness string = 'nsg-${productName}-business-${environment}' param resourceNameSubnetBusiness string = 'subnet-${productName}-business-${environment}' param vnetAddressPrefix string = '10.0.0.0/16' param subnetPrefixBusiness string = '10.0.1.0/24' param storageAccountName string = 'sa${productName}${environment}' param functionAppName string = 'fa-${productName}-${environment}' param planName string = 'asp-${productName}-${environment}' resource managedIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = { name: managedIdentityName tags: { Environment: environment Application: productName } location: location } resource nsgBusiness 'Microsoft.Network/networkSecurityGroups@2024-01-01' = { name: resourceNameNsgBusiness tags: { Environment: environment Application: productName } location: location } resource vnet 'Microsoft.Network/virtualNetworks@2024-01-01' = { name: vnetResourceName tags: { Environment: environment Application: productName } location: location properties: { addressSpace: { addressPrefixes: [ vnetAddressPrefix ] } enableDdosProtection: false enableVmProtection: false } } resource subnet 'Microsoft.Network/virtualNetworks/subnets@2024-03-01' = { parent: vnet name: resourceNameSubnetBusiness properties: { addressPrefix: subnetPrefixBusiness networkSecurityGroup: { id: nsgBusiness.id } privateEndpointNetworkPolicies: 'Enabled' privateLinkServiceNetworkPolicies: 'Enabled' serviceEndpoints: [ { service: 'Microsoft.Storage' locations: [ location ] } { service: 'Microsoft.Web' } ] } } resource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = { name: storageAccountName location: location kind: 'StorageV2' sku: { name: 'Standard_LRS' } properties: { supportsHttpsTrafficOnly: true minimumTlsVersion: 'TLS1_2' allowBlobPublicAccess: false publicNetworkAccess: 'Disabled' allowSharedKeyAccess: false networkAcls: { defaultAction: 'Deny' bypass: 'AzureServices' virtualNetworkRules: [ { id: subnet.id } ] } } } resource flexFuncPlan 'Microsoft.Web/serverfarms@2023-12-01' = { name: planName location: location kind: 'functionapp' sku: { tier: 'FlexConsumption' name: 'FC1' } properties: { reserved: true } } var deploymentStorageContainerName = 'deploy-${functionAppName}' resource functionApp 'Microsoft.Web/sites@2024-04-01' = { name: functionAppName location: location kind: 'functionapp,linux' identity: { type: 'UserAssigned' userAssignedIdentities: { '${managedIdentity.id}': {} } } properties: { serverFarmId: flexFuncPlan.id virtualNetworkSubnetId: subnet.id siteConfig: { appSettings: [ { name: 'AzureWebJobsStorage__accountName' value: storageAccount.name } { name: 'AzureWebJobsStorage__credential' value: 'managedidentity' } { name: 'AzureWebJobsStorage__clientId' value: managedIdentity.properties.clientId } ] } functionAppConfig: { deployment: { storage: { type: 'blobContainer' value: '${storageAccount.properties.primaryEndpoints.blob}${deploymentStorageContainerName}' authentication: { type: 'UserAssignedIdentity' userAssignedIdentityResourceId: managedIdentity.id } } } scaleAndConcurrency: { maximumInstanceCount: 100 instanceMemoryMB: 2048 } runtime: { name: 'dotnet-isolated' version: '8.0' } } } } var storageRoleDefinitionId = 'b7e6dc6d-f1e8-4753-8033-0f276bb0955b' resource storageRoleAssignment 'Microsoft.Authorization/roleAssignments@2020-04-01-preview' = { name: guid(storageAccount.id, storageRoleDefinitionId) scope: storageAccount properties: { roleDefinitionId: resourceId('Microsoft.Authorization/roleDefinitions', storageRoleDefinitionId) principalId: managedIdentity.properties.principalId principalType: 'ServicePrincipal' } }
错误信息截图说明
- Azure门户错误:显示
InternalServerError,提示内容为“内部服务器错误” - 流水线错误:部署步骤失败,日志中包含
InternalServerError标识及资源创建超时/失败提示
排查与修复建议
- 修正子网专用终结点策略
Flex Consumption函数应用要求子网的privateEndpointNetworkPolicies必须设为Disabled,当前模板中为Enabled,修改子网配置:
privateEndpointNetworkPolicies: 'Disabled'
- 确保角色分配顺序正确
添加依赖关系,保证存储账户的角色分配在函数应用部署前完成:
resource functionApp 'Microsoft.Web/sites@2024-04-01' = { // 现有配置不变 dependsOn: [ storageRoleAssignment ] }
- 检查NSG出站规则
当前NSG未配置任何规则,默认会阻止所有出站流量,需添加允许函数应用访问Azure服务的规则:
- 允许出站到
AzureCloud服务标签的HTTPS(443)流量 - 允许出站到存储账户的私有端点流量(若使用)
- 验证API版本兼容性
尝试降级部分资源的API版本,比如将函数应用的API版本改为Microsoft.Web/sites@2023-12-01,子网版本改为Microsoft.Network/virtualNetworks/subnets@2023-11-01测试。
内容的提问来源于stack exchange,提问作者J. van der Horst
相关产品推荐
相关产品推荐

