You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform为Azure灵活MySQL数据库配置后端应用专属防火墙规则?

实现Azure MySQL灵活服务器仅允许后端Web应用访问的防火墙规则

要让你的.NET Core后端Web应用独占访问MySQL灵活服务器,只需添加azurerm_mysql_flexible_server_firewall_rule资源,将Web应用的所有出站IP地址纳入允许列表即可。Azure Web App的出站IP可通过Terraform资源属性直接引用,无需手动查询。

完整配置示例

在现有Terraform代码中添加以下资源:

# 为后端Web应用的每个出站IP创建独立的MySQL防火墙规则
resource "azurerm_mysql_flexible_server_firewall_rule" "be_access" {
  for_each             = toset(split(",", azurerm_linux_web_app.be.outbound_ip_addresses))
  name                 = "allow-be-${replace(each.value, ".", "-")}"
  resource_group_name  = azurerm_resource_group.rg.name
  server_name          = azurerm_mysql_flexible_server.mysql.name
  start_ip_address     = each.value
  end_ip_address       = each.value
}

关键配置说明

  • for_each:将Web应用返回的逗号分隔出站IP字符串拆分为集合,自动为每个IP生成一条防火墙规则
  • name:通过替换IP中的点号为横杠,生成符合Azure命名规范的唯一规则名称
  • start_ip_address/end_ip_address:由于Web应用的出站IP均为单个独立IP,因此起始和结束IP设为同一个值

补充说明

如果你的Web应用使用Premium级App Service计划,推荐通过VNet集成方案实现内网访问(无需依赖出站IP),安全性更高;若使用基础/标准计划,上述基于出站IP的防火墙规则是最直接的实现方式。

内容的提问来源于stack exchange,提问作者Nour Mawla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 05:07:12