You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过Bicep与GitHub Actions azure/arm-deploy@v2一键部署资源组及内部资源?

可行!将资源组与内部资源整合为单次Bicep部署

完全可以把资源组纳入Bicep模板,通过订阅级别部署实现资源组与内部资源的一键创建,所有资源会自动依赖资源组的创建完成。以下是具体修改步骤:

1. 修改Bicep模板 (main.bicep)

添加资源组定义,并调整原有资源的作用域与参数引用:

@description('资源组名称')
param resourceGroupName string

@description('资源组及所有资源所在区域')
param location string = 'eastus'

@description('选择要部署的环境类型,允许值:prod、staging、dev')
@allowed([
  'prod'
  'staging'
  'dev'
])
param environment string

@description('Azure Function应用名称')
param functionAppName string = 'func-${uniqueString(rg.id)}-${environment}'

@description('存储账户类型')
@allowed([
  'Standard_LRS'
  'Standard_GRS'
  'Standard_RAGRS'
])
param storageAccountType string = 'Standard_LRS'

var hostingPlanName = 'plan-${uniqueString(rg.id)}-${environment}'
var applicationInsightsName = 'ai-${uniqueString(rg.id)}-${environment}'
var storageAccountName = 'st${uniqueString(rg.id)}-${environment}'
var logAnalyticsName = 'log-${uniqueString(rg.id)}-${environment}'

// 存储Blob数据所有者角色ID
var storageBlobDataOwnerRoleId = subscriptionResourceId(
  'Microsoft.Authorization/roleDefinitions',
  'b7e6dc6d-f1e8-4753-8033-0f276bb0955b'
)
var storageFunctionRoleAssignment = guid(rg.id, storageBlobDataOwnerRoleId)

// Event Hub数据接收者角色ID
var eventHubDataReceiverRoleId = subscriptionResourceId(
  'Microsoft.Authorization/roleDefinitions',
  'a638d3c7-ab3a-418d-83e6-5f17a39d4fde'
)
var eventHubFunctionRoleAssignment = guid(rg.id, eventHubDataReceiverRoleId)

// 定义资源组
resource rg 'Microsoft.Resources/resourceGroups@2021-04-01' = {
  name: resourceGroupName
  location: location
}

// 日志分析工作区(作用域指向资源组)
resource logAnalyticsWorkspace 'Microsoft.OperationalInsights/workspaces@2022-10-01' = {
  name: logAnalyticsName
  location: location
  scope: rg
  properties: {
    sku: {
      name: 'PerGB2018'
    }
  }
}

// 应用洞察(作用域指向资源组)
resource applicationInsight 'Microsoft.Insights/components@2020-02-02' = {
  name: applicationInsightsName
  location: location
  scope: rg
  kind: 'web'
  properties: {
    Application_Type: 'web'
    WorkspaceResourceId: logAnalyticsWorkspace.id
  }
}

// 存储账户(作用域指向资源组)
resource storageAccount 'Microsoft.Storage/storageAccounts@2022-05-01' = {
  name: storageAccountName
  location: location
  scope: rg
  sku: {
    name: storageAccountType
  }
  kind: 'Storage'
  properties: {
    supportsHttpsTrafficOnly: true
    minimumTlsVersion: 'TLS1_2'
    allowBlobPublicAccess: false
  }
}

// 托管计划(作用域指向资源组)
resource hostingPlan 'Microsoft.Web/serverfarms@2022-03-01' = {
  name: hostingPlanName
  location: location
  scope: rg
  sku: {
    name: 'Y1'
    tier: 'Dynamic'
    size: 'Y1'
    family: 'Y'
  }
  properties: {
    reserved: true
  }
}

// Function应用(作用域指向资源组)
resource functionApp 'Microsoft.Web/sites@2022-03-01' = {
  name: functionAppName
  location: location
  scope: rg
  kind: 'functionapp,linux'
  identity: {
    type: 'SystemAssigned'
  }
  properties: {
    reserved: true
    serverFarmId: hostingPlan.id
    httpsOnly: true
    siteConfig: {
      linuxFxVersion: 'DOTNETCORE|8.0'
      appSettings: [
        {
          name: 'APPLICATIONINSIGHTS_CONNECTION_STRING'
          value: applicationInsight.properties.ConnectionString
        }
        {
          name: 'AzureWebJobsStorage__accountName'
          value: storageAccountName
        }
        {
          name: 'FUNCTIONS_EXTENSION_VERSION'
          value: '~4'
        }
        {
          name: 'FUNCTIONS_WORKER_RUNTIME'
          value: 'dotnet-isolated'
        }
        {
          name: 'WEBSITE_RUN_FROM_PACKAGE'
          value: '1'
        }
      ]
    }
  }

  resource config 'config' = {
    name: 'web'
    properties: {
      ftpsState: 'Disabled'
      minTlsVersion: '1.2'
    }
  }
}

// 存储账户角色分配(作用域指向存储账户)
resource storageRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: storageFunctionRoleAssignment
  scope: storageAccount
  properties: {
    principalId: functionApp.identity.principalId
    roleDefinitionId: storageBlobDataOwnerRoleId
  }
}

// Event Hub角色分配(作用域指向资源组)
resource eventHubRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: eventHubFunctionRoleAssignment
  scope: rg
  properties: {
    principalId: functionApp.identity.principalId
    roleDefinitionId: eventHubDataReceiverRoleId
  }
}

关键调整说明:

  • 新增resourceGroupName和location参数,用于定义资源组
  • 添加资源组rg的定义,所有后续资源通过scope: rg指定部署到该资源组内
  • 将所有原来引用resourceGroup()的地方替换为rg的属性(如rg.id),确保依赖关系正确
  • 调整角色分配的作用域,确保部署权限生效

2. 修改GitHub Actions工作流 (deploy.yml)

删除单独的create-rg任务,修改部署步骤为订阅级别:

...
# 移除create-rg任务

deploy-infra:
  name: Deploy infrastructure
  runs-on: ubuntu-latest
  environment: ${{ inputs.environment }}
  outputs:
    appServiceAppName: ${{ steps.deploy.outputs.appServiceAppName }}
    appServiceAppHostName: ${{ steps.deploy.outputs.appServiceAppHostName }}
  steps:
    - name: Checkout
      uses: actions/checkout@v4
    - name: Login to Azure
      uses: azure/login@v2
      with:
        client-id: ${{ vars.AZURE_CLIENT_ID }}
        tenant-id: ${{ vars.AZURE_TENANT_ID }}
        subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }}
    - name: Deploy infrastructure
      uses: azure/arm-deploy@v2
      id: deploy
      with:
        deploymentName: ${{ github.run_number }}
        scope: subscription
        template: ./infra/main.bicep
        parameters: >
          resourceGroupName=${{ inputs.resourceGroupName }}
          environment=${{ inputs.environment }}
          location=${{ vars.AZURE_DEFAULT_LOCATION }}
        deploymentMode: Incremental # 推荐用Incremental避免误删订阅内其他资源
        failOnStdErr: false
  needs: [validate-infra]
...

关键调整说明:

  • 移除create-rg任务,资源组由Bicep模板自动创建
  • 将部署scope改为subscription,支持订阅级别的资源部署
  • 添加resourceGroupName和location参数传递给Bicep模板
  • 推荐将deploymentMode改为Incremental,避免Complete模式下误删订阅内未定义的资源

注意事项

  • 确保部署账号拥有订阅级别的部署权限(如Contributor角色)
  • 若需保留原有资源组的配置,可根据实际情况调整Bicep中的资源组属性
  • 测试时建议先在非生产环境验证部署流程

内容的提问来源于stack exchange,提问作者Shuzheng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 14:14:56