You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署Language Service禁用公网访问关联Search遇报错的解决咨询

解决Language Service一步部署公网访问禁用+私有端点配置问题

问题原因

当Language Service的apiProperties关联Azure Search时,直接在部署阶段设置publicNetworkAccess: 'Disabled',Azure会先校验关联的Search服务是否满足私有链接要求,但此时私有端点尚未创建完成,触发依赖冲突报错。分步部署能成功,是因为先完成私有端点配置,再禁用公网时已满足前置条件。

一步部署实现方案

1. 显式指定资源部署依赖顺序

在Bicep中通过dependsOn强制让私有端点连接资源先于Language Service的公网禁用配置完成部署,确保私有端点就绪后再关闭公网访问。

示例代码片段:

// 关联的Azure Search服务(需提前创建或同文件部署)
resource searchService 'Microsoft.Search/searchServices@2023-11-01' = {
  name: 'your-search-service'
  location: resourceGroup().location
  sku: {
    name: 'standard'
  }
  properties: {
    publicNetworkAccess: 'Disabled'
    privateEndpointConnections: []
  }
}

// 私有端点资源
resource privateEndpoint 'Microsoft.Network/privateEndpoints@2023-09-01' = {
  name: 'your-pe'
  location: resourceGroup().location
  properties: {
    subnet: {
      id: subnet.id
    }
    privateLinkServiceConnections: [
      {
        name: 'your-pe-connection'
        properties: {
          privateLinkServiceId: languageService.id
          groupIds: ['LanguageService']
        }
      }
    ]
  }
}

// 私有端点连接资源
resource privateEndpointConnection 'Microsoft.CognitiveServices/accounts/privateEndpointConnections@2023-05-01' = {
  parent: languageService
  name: 'your-pe-connection-name'
  properties: {
    privateEndpoint: {
      id: privateEndpoint.id
    }
    privateLinkServiceConnectionState: {
      status: 'Approved'
      description: 'Auto-approved'
      actionsRequired: 'None'
    }
  }
}

// Language Service主资源,显式依赖私有端点连接
resource languageService 'Microsoft.CognitiveServices/accounts@2023-05-01' = {
  name: 'your-language-service'
  location: resourceGroup().location
  sku: {
    name: 'S'
  }
  kind: 'LanguageService'
  properties: {
    publicNetworkAccess: 'Disabled'
    apiProperties: {
      azureSearch: {
        resourceId: searchService.id
        adminKey: listKeys(searchService.id, '2023-11-01').primaryKey
      }
    }
  }
  dependsOn: [
    privateEndpointConnection
    searchService
  ]
}

2. 用条件参数分阶段执行同一模板

通过Bicep的condition参数,在同一个模板中实现“先创建资源+私有端点、再禁用公网”的两步逻辑,无需重复编写配置。

示例代码片段:

param stage string = 'deploy' // 可选值:deploy / lock-down

resource languageService 'Microsoft.CognitiveServices/accounts@2023-05-01' = {
  name: 'your-language-service'
  location: resourceGroup().location
  sku: {
    name: 'S'
  }
  kind: 'LanguageService'
  properties: {
    publicNetworkAccess: stage == 'deploy' ? 'Enabled' : 'Disabled'
    apiProperties: {
      azureSearch: {
        resourceId: searchService.id
        adminKey: listKeys(searchService.id, '2023-11-01').primaryKey
      }
    }
    privateEndpointConnections: [
      privateEndpointConnection.properties
    ]
  }
  dependsOn: [
    privateEndpointConnection
  ]
}

// 私有端点、Search服务等资源定义同上

执行部署时先运行初始化阶段:

az deployment group create --resource-group your-rg --template-file main.bicep --parameters stage=deploy

再运行锁阶段:

az deployment group create --resource-group your-rg --template-file main.bicep --parameters stage=lock-down

3. 校验关联Search服务的私有链接状态

确保关联的Azure Search服务已配置私有端点,且publicNetworkAccess设置符合要求(如Disabled或Enabled但限制IP),避免因Search服务本身的公网配置触发联动报错。

关键注意事项

  • 私有端点连接必须处于Approved状态后,才能禁用Language Service的公网访问,显式依赖能确保这一顺序。
  • apiProperties中的Search密钥通过listKeys动态获取,避免硬编码泄露风险。

内容的提问来源于stack exchange,提问作者Don Chambers

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 05:33:20