Azure Function App 8.0 Isolated连接Azure SQL登录异常求助
排查Azure Function App托管身份连接Azure SQL的SSL连接异常问题
问题场景
本地运行通过托管身份+Entity Framework连接Azure SQL Server的Function App一切正常,但部署后抛出以下异常:
Failure Exception: Microsoft.Data.SqlClient.SqlException (0x80131904):
A connection was successfully established with the server, but then an
error occurred during the login process. (provider: SSL Provider,
error: 0 - An existing connection was forcibly closed by the remote
host.) ---> System.ComponentModel.Win32Exception (10054): An existing
connection was forcibly closed by the remote host
环境信息
- Function App版本:.NET 8.0 isolated模式
- EF版本:8.0.4
- 连接字符串:
Server=sql-xxx-test.database.windows.net;Database=XXX-Dev;Authentication=Active Directory Managed Identity;Encrypt=False;
已执行以下SQL添加托管身份权限:
CREATE USER [func-int-xxx-dev] FROM EXTERNAL PROVIDER; ALTER ROLE db_datareader ADD MEMBER [func-int-xxx-dev]; ALTER ROLE db_datawriter ADD MEMBER [func-int-xxx-dev];
排查与解决方向
- 强制启用加密连接:Azure SQL Server默认要求加密连接,云端环境可能强制覆盖
Encrypt=False的配置。将连接字符串改为Encrypt=True,可显式加上TrustServerCertificate=False(默认值),避免证书信任问题导致连接中断。 - 检查Function App网络配置:
- 若使用VNet集成,确认SQL Server防火墙规则允许该VNet的流量进入;未使用VNet集成的话,需添加Function App的出站IP到SQL防火墙,或临时开启“允许Azure服务和资源访问此服务器”选项测试。
- 验证托管身份配置:
- 确认Function App的系统托管身份名称与数据库中创建的
[func-int-xxx-dev]完全一致(Azure SQL对名称大小写敏感)。 - 临时给托管身份添加
db_owner权限测试,排除权限不足导致的登录中断(测试后需改回最小权限)。
- 确认Function App的系统托管身份名称与数据库中创建的
- 检查EF Core与SqlClient版本:
- 确认EF Core的
OnConfiguring方法未覆盖连接字符串的加密设置。 - 升级Microsoft.Data.SqlClient到最新稳定版,旧版本可能存在.NET 8 isolated模式下的兼容性问题,引发SSL握手失败。
- 确认EF Core的
- 检查SQL Server SSL强制设置:
- 在Azure Portal查看SQL Server的“连接安全性”设置,若SSL强制加密已开启,客户端必须使用加密连接,
Encrypt=False会直接导致连接被关闭。
- 在Azure Portal查看SQL Server的“连接安全性”设置,若SSL强制加密已开启,客户端必须使用加密连接,
- 查看详细日志:
- 在Azure Portal的Function App日志或Application Insights中查看更底层的错误信息,确认是否存在DNS解析失败、443端口被阻断等网络问题。
内容的提问来源于stack exchange,提问作者Thomas Segato
相关产品推荐
相关产品推荐

