You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用api_management_custom_domain创建多APIM自定义域名如何避冲突

解决APIM自定义域名创建的409冲突与资源重复问题

核心问题分析

你遇到的两个问题根源都是对azurerm_api_management_custom_domain资源的理解偏差:

  • 该资源每个APIM实例只能存在一个,它是用来批量配置APIM的所有自定义域名(包括网关、门户、管理等)的集合,而非单个域名的独立资源。
  • 用for_each创建多个该资源实例,会导致Terraform并行向锁定状态的APIM发送更新请求,触发ServiceLocked 409冲突;多次调用模块创建该资源则会因为同一个APIM下已有该资源而报错重复。

解决方案:单资源批量配置多域名

修改代码,将所有网关域名定义在同一个azurerm_api_management_custom_domain资源的多个gateway块中,而非创建多个资源实例。

修正后的代码示例

变量定义(保持不变)

variable "gateway_custom_domains" {
  description = "List of custom domains for the Gateway."
  type = list(object({
    host_name                    = string
    certificate_id               = string
    negotiate_client_certificate = optional(bool, false)
    default_ssl_binding          = optional(bool, false)
  }))
  default = []
}

自定义域名资源(关键修正)

resource "azurerm_api_management_custom_domain" "gateway" {
  api_management_id = azurerm_api_management.apim.id

  # 遍历变量中的域名列表,生成多个gateway块
  dynamic "gateway" {
    for_each = var.gateway_custom_domains
    content {
      host_name                   = gateway.value.host_name
      key_vault_id                = gateway.value.certificate_id
      negotiate_client_certificate = gateway.value.negotiate_client_certificate
      default_ssl_binding          = gateway.value.default_ssl_binding
    }
  }
}

模块调用(保持原有列表格式)

module "apim_01" {
  source              = ...
  
  ...

  gateway_custom_domains = [
    {
      host_name = "gw1.example.com"
      certificate_id = azurerm_key_vault_certificate.apimgw1.versionless_secret_id
      negotiate_client_certificate = false
      default_ssl_binding          = true
    },
    {
      host_name = "gw2.example.com"
      certificate_id = azurerm_key_vault_certificate.apimgw2.versionless_secret_id
      negotiate_client_certificate = false
      default_ssl_binding          = false
    }
  ]
}

为什么这能解决问题

  1. 避免并行冲突:单个资源更新会将所有域名配置一次性提交给Azure API,Azure会在APIM实例就绪后统一处理,不会触发ServiceLocked错误。
  2. 避免资源重复:每个APIM仅对应一个azurerm_api_management_custom_domain资源,符合Azure Terraform Provider的设计逻辑,不会出现资源已存在的报错。

额外注意事项

  • 如果之前已经创建过单个域名的azurerm_api_management_custom_domain资源,需要先执行terraform state rm移除旧的资源状态,再应用新的配置。
  • 确保Key Vault的访问策略已正确配置,允许APIM实例读取证书(需添加Microsoft.ApiManagement/service主体的get权限)。

内容的提问来源于stack exchange,提问作者Daniel Alves

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 20:04:51