You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep部署Azure Web App时如何配置容器注册表标识

问题:Bicep部署Azure Web App时无法配置容器注册表标识

我在使用Bicep创建Azure Web App时,无法正确配置容器注册表标识(Registry Identity)。通过Azure UI手动配置可正常生效,但使用Bicep部署时,尝试了以下配置段却未成功分配标识,想请教正确的语法:

properties: {
  serverFarmId: appServicePlan.id
  httpsOnly: true
  siteConfig: {
    linuxFxVersion: 'DOTNETCORE|8.0'
    acrUseManagedIdentityCreds: true // --this is new to test the managed identity
    acrUserManagedIdentityID: managedIdentity.id
  }
}

以下是我的完整Bicep脚本:

var appServicePlanName = '${environmentName}-${solutionName}-plan'
var appServiceAppName = '${environmentName}-${solutionName}-app'
var sqlServerName = '${environmentName}-${solutionName}-sql'
var sqlDatabaseName = 'dis-${environmentName}'
var managedIdentityName = '${environmentName}-${solutionName}-mi'

resource managedIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = {
  name: managedIdentityName
  location: location
}

resource sqlServer 'Microsoft.Sql/servers@2023-08-01-preview' = {
  name: sqlServerName
  location: location
  properties: {
    administratorLogin: sqlServerLogin
    administratorLoginPassword: sqlServerPassword
  }
}

resource allowAccessToAzureServices 'Microsoft.Sql/servers/firewallRules@2023-08-01-preview' = {
  parent: sqlServer
  name: 'AllowAccessToAzureServices'
  properties: {
    startIpAddress: '0.0.0.0'
    endIpAddress: '0.0.0.0'
  }
}

resource sqlDatabase 'Microsoft.Sql/servers/databases@2023-08-01-preview' = {
  parent: sqlServer
  name: sqlDatabaseName
  location: location
  sku: {
    name: sqlDatabaseSku.name
    tier: sqlDatabaseSku.tier
  }
}

resource appServicePlan 'Microsoft.Web/serverfarms@2023-01-01' = {
  name: appServicePlanName
  location: location
  sku: {
    name: appServicePlanSku.name
    tier: appServicePlanSku.tier
    capacity: appServicePlanInstanceCount
  }
  kind: 'linux'
  properties: {
    reserved: true
  }
}

resource appServiceApp 'Microsoft.Web/sites@2023-01-01' = {
  name: appServiceAppName
  location: location
  kind: 'app,linux,container'
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${managedIdentity.id}': {}
    }
  }
  properties: {
    serverFarmId: appServicePlan.id
    httpsOnly: true
    siteConfig: {
      linuxFxVersion: 'DOTNETCORE|8.0'
      acrUseManagedIdentityCreds: true // --this is new to test the managed identity
      acrUserManagedIdentityID: managedIdentity.id
    }
  }
}

resource logs 'Microsoft.Web/sites/config@2023-01-01' = {
  name: 'logs'
  parent: appServiceApp
  properties: {
    applicationLogs: {
      fileSystem: { level: 'Verbose' }
    }
    detailedErrorMessages: { enabled: true }
    httpLogs: {
      fileSystem: { retentionInDays: 7, enabled: true }
    }
  }
}

手动在Azure UI中配置标识的示例:
手动配置容器注册表标识


解决方案

你的配置存在两个核心问题:

  1. linuxFxVersion设置为DOTNETCORE|8.0时,Web App会使用内置运行时,而非容器部署模式,导致ACR相关的标识配置被忽略
  2. acrUserManagedIdentityID应该使用用户分配标识的客户端ID(clientId),而非资源ID

修正后的Web App配置

resource appServiceApp 'Microsoft.Web/sites@2023-01-01' = {
  name: appServiceAppName
  location: location
  kind: 'app,linux,container'
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${managedIdentity.id}': {}
    }
  }
  properties: {
    serverFarmId: appServicePlan.id
    httpsOnly: true
    siteConfig: {
      // 替换为你的ACR容器镜像地址,格式:"DOCKER|{ACR名称}.azurecr.io/{镜像名}:{标签}"
      linuxFxVersion: 'DOCKER|your-acr-name.azurecr.io/your-image:latest'
      acrUseManagedIdentityCreds: true
      // 使用标识的clientId而非资源ID
      acrUserManagedIdentityID: managedIdentity.properties.clientId
    }
  }
}

额外必要配置:给标识分配ACR拉取权限

必须确保用户分配标识拥有目标ACR的AcrPull角色权限,否则无法拉取镜像。可以通过以下Bicep代码添加角色分配:

// 假设你的ACR资源定义如下(根据实际情况调整)
resource acr 'Microsoft.ContainerRegistry/registries@2023-07-01' = {
  name: 'your-acr-name'
  location: location
  sku: {
    name: 'Standard'
  }
  properties: {
    adminUserEnabled: false
  }
}

// 为用户分配标识添加AcrPull角色权限
resource acrPullRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(acr.id, managedIdentity.id, 'b24988ac-6180-42a0-ab88-20f7382dd24c')
  scope: acr
  properties: {
    // AcrPull角色的固定ID
    roleDefinitionId: '/subscriptions/${subscription().subscriptionId}/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c'
    principalId: managedIdentity.properties.principalId
    principalType: 'ServicePrincipal'
  }
}

内容的提问来源于stack exchange,提问作者Dobromir Ivanov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 05:16:06