You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署Azure Web App时auth_settings_v2不支持问题求助

使用Terraform部署Azure Linux Web App时无法启用auth_settings_v2配置

问题描述

我正在用Terraform创建Azure Linux Web App,想要启用v2版本的授权配置,但使用auth_settings_v2块时出现Error: Unsupported block type错误。使用旧版v1的auth_settings块可以正常创建应用,且我使用的是Terraform Azure Provider 3.9版本,按文档应该支持auth_settings_v2。

基础代码如下:

resource "azurerm_linux_web_app" "webapp" {
  name                  = var.app_service_name
  location              = azurerm_resource_group.rg.location
  resource_group_name   = azurerm_resource_group.rg.name
  service_plan_id       = azurerm_service_plan.appserviceplan.id
  https_only            = true
  
  # 报错的v2配置
  auth_settings_v2 {
    auth_enabled = true
  }
  # 正常工作的v1配置(已注释)
  # auth_settings {
  #   enabled = false
  # }
  site_config { }
}

解决方案

1. 确认并升级Azure Provider版本

首先确保你在Terraform配置中明确指定了3.9版本的Azure Provider,并执行升级操作:

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.9.0"
    }
  }
}

执行命令更新Provider:

terraform init -upgrade

2. 修正auth_settings_v2块的参数错误

你代码中使用的auth_enabled参数是错误的,v2配置块中启用授权的参数为enabled。此外,v2授权配置需要至少配置一个身份提供商(比如Azure AD)才能生效,示例配置如下:

resource "azurerm_linux_web_app" "webapp" {
  name                  = var.app_service_name
  location              = azurerm_resource_group.rg.location
  resource_group_name   = azurerm_resource_group.rg.name
  service_plan_id       = azurerm_service_plan.appserviceplan.id
  https_only            = true
  
  auth_settings_v2 {
    enabled = true

    # 示例:配置Azure AD身份提供商
    azure_active_directory {
      client_id         = var.aad_client_id
      client_secret     = var.aad_client_secret
      tenant_id         = var.tenant_id
      allowed_audiences = ["https://${var.app_service_name}.azurewebsites.net"]
    }
  }

  site_config { }
}

3. 避免v1和v2授权块冲突

确保配置中不同时存在auth_settings和auth_settings_v2块,即使v1块被注释,若之前的Terraform状态中存在相关记录,可能需要先执行terraform state rm azurerm_linux_web_app.webapp.auth_settings清理旧状态,再重新部署。

内容的提问来源于stack exchange,提问作者DNy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 00:03:13