如何通过Bicep确保Azure App Service使用区域VNet集成而非网关模式
如何通过Bicep确保Azure App Service使用区域VNet集成而非网关型集成?
我尝试使用Bicep模板为Azure App Service配置区域VNet集成,但系统默认采用了网关型集成。
现有配置代码
Network.Bicep
@description('Name of the VNet to be created') param vnetName string @description('Name of the subnet to be created') param subnetName string @description('Name of the Network Security Group to be created') param nsgName string @description('Location for the resources') param targetLocation string @description('Desired set of tags to apply to each created resource') param resourceTags object = {} resource nsg 'Microsoft.Network/networkSecurityGroups@2021-05-01' = { name: nsgName location: targetLocation properties: { securityRules: [] } tags: resourceTags } resource vnet 'Microsoft.Network/virtualNetworks@2021-05-01' = { name: vnetName location: targetLocation properties: { addressSpace: { addressPrefixes: [ '10.0.0.0/16' ] } subnets: [ { name: subnetName properties: { addressPrefix: '10.0.2.0/27' // Adjusted to /27 for sufficient IPs serviceEndpoints: [ { service: 'Microsoft.AzureCosmosDB' } ] delegations: [ { name: 'webServerFarmDelegation' properties: { serviceName: 'Microsoft.Web/serverFarms' } } ] networkSecurityGroup: { id: resourceId('Microsoft.Network/networkSecurityGroups', nsgName) } } } ] } tags: resourceTags } output subnetId string = vnet.properties.subnets[0].id
Vnetintegration.bicep
@description('The name of the existing web app to update') param webAppName string @description('Name of the existing web app Slot') param webAppSlotName string? @description('Denotes the desired name for the app service plan') param appServicePlanName string @description('The name of the virtual network') param vnetName string @description('The name of the subnet within the virtual network') param subnetName string resource webApp 'Microsoft.Web/sites@2021-03-01' existing = { name: webAppName } resource appServicePlan 'Microsoft.Web/serverfarms@2021-03-01' existing = { name: appServicePlanName } resource vnet 'Microsoft.Network/virtualNetworks@2021-05-01' existing = { name: vnetName } resource vnetIntegration 'Microsoft.Web/sites/virtualNetworkConnections@2021-03-01' = { parent: webApp name: 'vnet' properties: { vnetResourceId: resourceId('Microsoft.Network/virtualNetworks/subnets', vnetName, subnetName) } dependsOn: [ vnet appServicePlan ] }
解决方法
要强制启用区域VNet集成,需在virtualNetworkConnections资源的properties中添加isSwift: true参数,这是区分区域集成和网关型集成的核心配置。
修改后的vnetIntegration资源配置如下:
resource vnetIntegration 'Microsoft.Web/sites/virtualNetworkConnections@2021-03-01' = { parent: webApp name: 'vnet' properties: { vnetResourceId: resourceId('Microsoft.Network/virtualNetworks/subnets', vnetName, subnetName) isSwift: true // 启用区域VNet集成 } dependsOn: [ vnet appServicePlan ] }
同时需确认以下前提条件已满足:
- 子网已正确委托给
Microsoft.Web/serverFarms(你的Network.Bicep中已配置此委托) - 子网地址前缀至少为
/27(你的配置中10.0.2.0/27符合要求) - App Service Plan必须为Premium V2/V3、Isolated或Elastic Premium SKU,区域VNet集成不支持基础/标准SKU
内容的提问来源于stack exchange,提问作者Nagarjun
相关产品推荐
相关产品推荐

