You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Bicep确保Azure App Service使用区域VNet集成而非网关模式

如何通过Bicep确保Azure App Service使用区域VNet集成而非网关型集成?

我尝试使用Bicep模板为Azure App Service配置区域VNet集成,但系统默认采用了网关型集成。

现有配置代码

Network.Bicep

@description('Name of the VNet to be created')
param vnetName string

@description('Name of the subnet to be created')
param subnetName string

@description('Name of the Network Security Group to be created')
param nsgName string

@description('Location for the resources')
param targetLocation string

@description('Desired set of tags to apply to each created resource')
param resourceTags object = {}

resource nsg 'Microsoft.Network/networkSecurityGroups@2021-05-01' = {
  name: nsgName
  location: targetLocation
  properties: {
    securityRules: []
  }
  tags: resourceTags
}

resource vnet 'Microsoft.Network/virtualNetworks@2021-05-01' = {
  name: vnetName
  location: targetLocation
  properties: {
    addressSpace: {
      addressPrefixes: [
        '10.0.0.0/16'
      ]
    }
    subnets: [
      {
        name: subnetName
        properties: {
          addressPrefix: '10.0.2.0/27' // Adjusted to /27 for sufficient IPs
          serviceEndpoints: [
            {
              service: 'Microsoft.AzureCosmosDB'
            }
          ]
          delegations: [
            {
              name: 'webServerFarmDelegation'
              properties: {
                serviceName: 'Microsoft.Web/serverFarms'
              }
            }
          ]
          networkSecurityGroup: {
            id: resourceId('Microsoft.Network/networkSecurityGroups', nsgName)
          }
        }
      }
    ]
  }
  tags: resourceTags
}

output subnetId string = vnet.properties.subnets[0].id

Vnetintegration.bicep

@description('The name of the existing web app to update')
param webAppName string

@description('Name of the existing web app Slot')
param webAppSlotName string?

@description('Denotes the desired name for the app service plan')
param appServicePlanName string

@description('The name of the virtual network')
param vnetName string

@description('The name of the subnet within the virtual network')
param subnetName string

resource webApp 'Microsoft.Web/sites@2021-03-01' existing = {
  name: webAppName
}

resource appServicePlan 'Microsoft.Web/serverfarms@2021-03-01' existing = {
  name: appServicePlanName
}

resource vnet 'Microsoft.Network/virtualNetworks@2021-05-01' existing = {
  name: vnetName
}

resource vnetIntegration 'Microsoft.Web/sites/virtualNetworkConnections@2021-03-01' = {
  parent: webApp
  name: 'vnet'
  properties: {
    vnetResourceId: resourceId('Microsoft.Network/virtualNetworks/subnets', vnetName, subnetName)
  }
  dependsOn: [
    vnet
    appServicePlan
  ]
}

解决方法

要强制启用区域VNet集成,需在virtualNetworkConnections资源的properties中添加isSwift: true参数,这是区分区域集成和网关型集成的核心配置。

修改后的vnetIntegration资源配置如下:

resource vnetIntegration 'Microsoft.Web/sites/virtualNetworkConnections@2021-03-01' = {
  parent: webApp
  name: 'vnet'
  properties: {
    vnetResourceId: resourceId('Microsoft.Network/virtualNetworks/subnets', vnetName, subnetName)
    isSwift: true // 启用区域VNet集成
  }
  dependsOn: [
    vnet
    appServicePlan
  ]
}

同时需确认以下前提条件已满足:

  • 子网已正确委托给Microsoft.Web/serverFarms(你的Network.Bicep中已配置此委托)
  • 子网地址前缀至少为/27(你的配置中10.0.2.0/27符合要求)
  • App Service Plan必须为Premium V2/V3、Isolated或Elastic Premium SKU,区域VNet集成不支持基础/标准SKU

内容的提问来源于stack exchange,提问作者Nagarjun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 19:13:16