You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform与FastAPI关联Azure函数与静态Web应用遇访问异常

Azure静态Web应用关联Azure函数的访问问题及部署冲突解决

问题概述

使用Terraform将FastAPI实现的Azure函数关联至静态Web应用,资源部署流程正常,但访问出现两类异常:

  • 直接请求函数应用URL https://func-***.azurewebsites.net/api/v1/ping,返回错误:{"code":400,"message":"Login not supported for provider azureStaticWebApps"}
  • 请求静态Web应用的API路径 https://***.azurestaticapps.net/api/v1/ping,返回404 Not Found
  • 函数本地运行正常,host.json中routePrefix已设为空
  • 发现使用Azure DevOps的AzureFunctionApp@2任务部署函数会破坏静态Web应用与函数的关联,改用func azure functionapp publish $(appName) --python命令部署则关联正常,但不确定该方案是否合规

相关代码片段

Terraform资源定义

// 创建Linux函数应用
resource "azurerm_linux_function_app" "this" {
  name                       = "func-${var.organization}-${var.application}-${var.environment}"
  location                   = azurerm_resource_group.this.location
  resource_group_name        = azurerm_resource_group.this.name
  service_plan_id            = azurerm_service_plan.this.id
  storage_account_name       = azurerm_storage_account.function.name
  storage_account_access_key = azurerm_storage_account.function.primary_access_key

  identity {
    type = "SystemAssigned"
  }

  site_config {
    always_on                = true
    application_insights_key = azurerm_application_insights.this.instrumentation_key
    application_stack {
      python_version = "3.11"
    }
  }

  app_settings = {
    "SCM_DO_BUILD_DURING_DEPLOYMENT" = "true"
    "URL_BASE"                       = "https://${azurerm_static_web_app.this.default_host_name}"
    "URL_BASE_API"                   = "https://${azurerm_static_web_app.this.default_host_name}/api"
  }

  tags = local.tags

  lifecycle {
    ignore_changes = [auth_settings_v2]
  }
}

// 创建静态Web应用
resource "azurerm_static_web_app" "this" {
  name                = "app-${var.organization}-${var.application}-${var.environment}"
  resource_group_name = azurerm_resource_group.this.name
  location            = azurerm_resource_group.this.location
  sku_tier            = "Standard"
  sku_size            = "Standard"
}

// 将函数注册为静态Web应用的API
resource "azurerm_static_web_app_function_app_registration" "this" {
  static_web_app_id = azurerm_static_web_app.this.id
  function_app_id   = azurerm_linux_function_app.this.id
}

FastAPI函数代码

import azure.functions as func
import fastapi

fastapi_app = fastapi.FastAPI(root_path="/api/v1")


@fastapi_app.get("/ping")
async def index():
    return "pong"


app = func.AsgiFunctionApp(
    app=fastapi_app, 
    http_auth_level=func.AuthLevel.ANONYMOUS
)

Azure DevOps部署任务

- task: AzureFunctionApp@2
  inputs:
    connectedServiceNameARM: $(subscription)
    appType: 'functionAppLinux'
    appName: $(appName)
    runtimeStack: 'PYTHON|3.11'

问题分析与解决方案

报错原因解析

  1. 直接访问函数URL的400错误:函数与静态Web应用关联后,Azure会自动配置函数的身份验证规则,仅允许静态Web应用的身份提供者发起请求,直接访问函数原生URL会触发身份验证拦截,属于关联后的预期行为,不应直接访问函数原生URL。
  2. 静态Web应用API路径的404错误:核心原因是AzureFunctionApp@2任务部署Python函数时,会修改函数应用的核心配置(如身份验证设置、路由前缀),破坏了静态Web应用与函数的关联映射,导致路由无法正确匹配。

解决方案

  1. 采用官方推荐的部署方式:func azure functionapp publish $(appName) --python是Python Azure函数的官方部署命令,会保留函数应用的原有配置(包括静态Web应用的关联设置),避免配置被覆盖。在DevOps流水线中可通过Bash任务执行:
    func azure functionapp publish $(appName) --python
    
  2. 验证路由配置:
    • 确认host.json中的routePrefix为空,确保静态Web应用的/api前缀能直接映射到函数的根路由
    • FastAPI的root_path="/api/v1"配置正确,确保/api/v1/ping能正确路由到函数的/ping端点
  3. 确认关联状态:在Azure门户中检查静态Web应用的「API」设置,确认函数应用已正确关联;同时检查函数应用的「身份验证」设置,确保其已被配置为仅允许静态Web应用访问(由Terraform关联资源自动配置)

内容的提问来源于stack exchange,提问作者poklaassen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 14:35:12