You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep自动批准Front Door专用终结点请求的部署异常问题

问题:首次部署Bicep批准Front Door专用链接时失败,二次部署成功

我参考Stack Overflow上Thomas针对《如何自动批准来自Front Door的专用终结点请求?》的方案,实现了对应Bicep代码。代码看似可正常工作,但存在异常情况:首次部署时,专用链接已按预期创建并完成批准,但Bicep部署的批准步骤却失败,报错信息如下:

{
"status": "Failed",
"error": {
    "code": "ResourceDeploymentFailure",
    "target": "/subscriptions/<SUBID>/resourceGroups/<RGNAME>/providers/Microsoft.Web/sites/<APPNAME>/privateEndpointConnections/774ab459-37e5-4bb8-9bc5-436408c864c1-e54d42d7-34ce-42df-b09d-456031a9016d",
    "message": "The response for resource had empty or invalid content."
    }
}

如前所述,连接确实已批准,且再次运行相同的Bicep代码时,部署会成功。我已检查Bicep模板及重新部署的成功结果,未发现异常。以下是相关代码片段:

主模板中获取链接并批准的代码

module getPrivateLink 'private-link/web-getPrivateLink.bicep' = [for (origin, index) in originArray: if(contains(origin, 'privateLink') && privateLinkOriginDetails[index].groupId == 'sites'){
  name: 'getLink-${origin.name}'
  params: {
    name: origin.privateLink.privateLinkResourceName
  }
  dependsOn: [
    origins
  ]
}]

module approveLink 'private-link/web-approveLink.bicep' = [for (origin, index) in originArray: if(contains(origin, 'privateLink') && privateLinkOriginDetails[index].groupId == 'sites'){
  name: 'approveLink-${origin.name}'
  params: {
    appName: origin.privateLink.privateLinkResourceName
    linkName: getPrivateLink[index].outputs.linkName
  }
}]
param name string

resource appService 'Microsoft.Web/sites@2022-09-01' existing = {
  name: name
}

output linkName string = last(split(first(appService.properties.privateEndpointConnections).id,'/'))
output resourceName string = name
param appName string
param linkName string

resource appService 'Microsoft.Web/sites@2022-09-01' existing = {
  name: appName
}

resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = {
  parent: appService
  name: linkName
  properties: {
    privateLinkServiceConnectionState: {
      status: 'Approved'
      description: 'Approved by pipeline'
    }
  }
}

更新:经过约2个月的支持工单处理,我得到明确答复:仅能通过Azure门户或Azure CLI批准该链接。


内容的提问来源于stack exchange,提问作者ejer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 02:35:12