使用Bicep/Azure PowerShell创建Event Grid系统主题订阅遇端点错误
问题分析与解决方案
核心问题定位
报错Destination endpoint not found的本质是Event Grid无法识别或访问目标函数的端点,常见原因包括:函数资源ID错误、触发器配置问题、权限缺失、或函数App的身份验证限制。
排查与修复步骤
1. 验证函数资源ID的准确性
手动拼接资源ID容易出错,建议直接从Azure Portal获取函数的官方资源ID,或用PowerShell精准查询:
# 直接获取函数的完整资源ID,避免手动拼接错误 $funcEmailDelivery = Get-AzResource ` -ResourceGroupName rg-cc-dev ` -ResourceType Microsoft.Web/sites/functions ` -ResourceName "my-func/FunctionEmailDeliveryReportReceived" | Select-Object -ExpandProperty Id
对比查询结果与你之前拼接的ID,确保完全一致(注意函数名称的大小写、拼写需与Portal显示的逻辑名称完全匹配)。
2. 确认EventGridTrigger配置有效性
- 检查函数代码中的
[EventGridTrigger]属性是否正确声明,例如:public static void Run([EventGridTrigger] EventGridEvent eventGridEvent, ILogger log) { log.LogInformation("Event received: {EventId}", eventGridEvent.Id); } - 在Azure Portal的函数页面,进入触发器标签,确认Event Grid触发器状态为启用,且配置无缺失。
3. 配置Event Grid访问权限
Event Grid服务需要具备访问函数App的权限,在函数App的**访问控制(IAM)**中添加角色分配:
- 角色选择:
Azure Event Grid EventSubscription Contributor - 成员类型选择:
服务主体 - 搜索并选择
Azure Event Grid服务主体
4. 修正PowerShell代码
使用精准查询到的函数资源ID,重新创建订阅:
# 获取系统主题 $systemTopic = Get-AzEventGridSystemTopic -ResourceGroupName my-rg-acs-dev -name egst-acs-dev # 获取函数资源ID $funcEmailDelivery = Get-AzResource ` -ResourceGroupName rg-cc-dev ` -ResourceType Microsoft.Web/sites/functions ` -ResourceName "my-func/FunctionEmailDeliveryReportReceived" | Select-Object -ExpandProperty Id # 创建目标对象 $func_evdo = New-AzEventGridAzureFunctionEventSubscriptionDestinationObject ` -MaxEventsPerBatch 1 ` -PreferredBatchSizeInKilobyte 64 ` -ResourceId $funcEmailDelivery # 定义事件类型 $includedEventTypesForEmailDelivery = @('Microsoft.Communication.EmailDeliveryReportReceived') # 创建订阅 New-AzEventGridSystemTopicEventSubscription ` -EventSubscriptionName evgs-acs-email-delivery-dev ` -ResourceGroupName my-rg-acs-dev ` -SystemTopicName $systemTopic.Name ` -Destination $func_evdo ` -EventDeliverySchema CloudEventSchemaV1_0 ` -FilterEnableAdvancedFilteringOnArray ` -FilterIncludedEventType $includedEventTypesForEmailDelivery ` -RetryPolicyMaxDeliveryAttempt 10 ` -RetryPolicyEventTimeToLiveInMinute 1440
5. Bicep声明式解决方案
使用现有资源引用确保ID准确性,同时配置必要权限:
param systemTopicName string = 'egst-acs-dev' param systemTopicRg string = 'my-rg-acs-dev' param functionAppName string = 'my-func' param functionAppRg string = 'rg-cc-dev' param subscriptionName1 string = 'evgs-acs-email-delivery-dev' param functionName1 string = 'FunctionEmailDeliveryReportReceived' // 引用现有ACS系统主题 resource systemTopic 'Microsoft.EventGrid/systemTopics@2024-06-01-preview' existing = { name: systemTopicName scope: resourceGroup(systemTopicRg) } // 引用现有Function App resource functionApp 'Microsoft.Web/sites@2023-12-01' existing = { name: functionAppName scope: resourceGroup(functionAppRg) } // 第一个Event Grid订阅 resource eventSub1 'Microsoft.EventGrid/systemTopics/eventSubscriptions@2024-06-01-preview' = { parent: systemTopic name: subscriptionName1 properties: { destination: { type: 'AzureFunction' properties: { resourceId: '${functionApp.id}/functions/${functionName1}' maxEventsPerBatch: 1 preferredBatchSizeInKilobytes: 64 } } eventDeliverySchema: 'CloudEventSchemaV1_0' filter: { includedEventTypes: ['Microsoft.Communication.EmailDeliveryReportReceived'] enableAdvancedFilteringOnArrays: true } retryPolicy: { maxDeliveryAttempts: 10 eventTimeToLiveInMinutes: 1440 } } } // 第二个订阅(复制上述块,修改functionName和subscriptionName即可)
6. 特殊场景处理:函数App启用AAD身份验证
如果函数App开启了Azure AD身份验证,需为Event Grid订阅指定身份:
- PowerShell中添加参数:
-IdentityType SystemAssigned - Bicep中在订阅资源内添加身份配置:
identity: { type: 'SystemAssigned' }
同时需确保该系统身份被授予函数App的Function App Contributor角色。
内容的提问来源于stack exchange,提问作者Panayotis Tzedakis
相关产品推荐
相关产品推荐

