Terraform部署Azure Function:Zip包依赖未导入致函数无法识别
Azure Functions部署后函数不识别问题排查与解决
通过Terraform部署Azure Function,Function App部署成功,门户“应用文件”标签页可见所有文件,但概览页无函数显示、无法触发。测试发现无外部依赖的Hello World可正常识别,添加外部库导入后函数消失,判定为依赖安装或加载问题。
环境与配置信息
Terraform代码
resource "azurerm_storage_account" "function_storage" { name = var.storage_account_name resource_group_name = var.resource_group_name location = var.location account_tier = "Standard" account_replication_type = "LRS" min_tls_version = "TLS1_2" public_network_access_enabled = true } resource "azurerm_storage_container" "function_container" { name = "${var.function_name}files" storage_account_name = azurerm_storage_account.function_storage.name container_access_type = "private" } resource "azurerm_service_plan" "appplan" { name = var.app_serviceplan_name location = var.location resource_group_name = var.resource_group_name os_type = "Linux" sku_name = "S1" } data "archive_file" "file_function_app" { type = "zip" source_dir = "../src/azure_functions/my_functions" # Use a hash of all code files as a zip filename to trigger the deployment on every changes output_path = "archives/${sha1(join("", [for f in fileset("../src/azure_functions/my_functions", "**") : filesha1("../src/azure_functions/my_functions/${f}")]))}-function.zip" } resource "azurerm_linux_function_app" "funcapp" { name = var.funcapp_name location = var.location resource_group_name = var.resource_group_name service_plan_id = azurerm_service_plan.appplan.id storage_account_name = azurerm_storage_account.function_storage.name storage_account_access_key = azurerm_storage_account.function_storage.primary_access_key site_config { application_stack { python_version = 3.11 } } app_settings = { WEBSITE_RUN_FROM_PACKAGE = 1 AzureWebJobsFeatureFlags = "EnableWorkerIndexing" SCM_DO_BUILD_DURING_DEPLOYMENT = true ENABLE_ORYX_BUILD = true } zip_deploy_file = data.archive_file.file_function_app.output_path }
函数代码(function_app.py)
import azure.functions as func # 导入任何外部库都会触发问题,删除此句后函数可正常识别 import jsonschema app = func.FunctionApp(http_auth_level=func.AuthLevel.FUNCTION) @app.route(route="p4_profiling", auth_level=func.AuthLevel.FUNCTION) def p4_profiling(req: func.HttpRequest) -> func.HttpResponse: return func.HttpResponse("OK", status_code=200)
依赖清单(requirements.txt)
azure-functions==1.17.0 jsonschema==4.19.2 numpy==1.26.1 pandas==2.1.2 thefuzz==0.20.0 psycopg2-binary
本地文件结构
├── infrastructure │ ├── azure-function.tf │ ├── main.tf │ └── variable.tf └── src ├── azure_functions │ └── my_function │ ├── function_app.py │ ├── host.json │ ├── __init__.py │ ├── local.settings.json │ └── requirements.txt
部署Zip包结构
├── function_app.py ├── host.json ├── __init__.py ├── local.settings.json └── requirements.txt
问题分析与解决步骤
核心原因
启用WEBSITE_RUN_FROM_PACKAGE=1时,Azure Functions直接从压缩包运行代码,但依赖安装过程可能因权限、网络或构建配置问题失败,导致函数加载时因依赖缺失崩溃,无法被索引识别。
解决方案
调整应用设置,确保依赖正确构建
修改Terraform中的app_settings,添加/调整配置:app_settings = { WEBSITE_RUN_FROM_PACKAGE = 1 AzureWebJobsFeatureFlags = "EnableWorkerIndexing" SCM_DO_BUILD_DURING_DEPLOYMENT = true ENABLE_ORYX_BUILD = true # 指定Python版本匹配运行环境 PYTHON_VERSION = "3.11" # 强制依赖安装到函数可加载的目录 PIP_TARGET = "/home/site/wwwroot/.python_packages/lib/site-packages" # 开启构建日志便于调试 SCM_BUILD_ARGS = "--verbose" }检查构建日志定位失败原因
登录Azure门户,进入Function App的部署中心 -> 日志,查看Oryx构建过程中是否有依赖安装错误(如numpy、psycopg2等编译类库的编译失败问题)。预编译依赖并打包(离线部署方案)
若网络或构建环境限制无法在线安装依赖,可在本地构建适配Linux环境的依赖后打包:- 在函数代码目录创建
.python_packages/lib/site-packages目录 - 运行命令下载Linux兼容的依赖:
pip install -r requirements.txt -t .python_packages/lib/site-packages --platform manylinux2014_x86_64 --only-binary=:all: - 将
.python_packages目录加入Zip包,确保最终包结构包含该目录。
- 在函数代码目录创建
验证host.json配置
确保host.json启用了扩展包并配置正确:{ "version": "2.0", "extensionBundle": { "id": "Microsoft.Azure.Functions.ExtensionBundle", "version": "[4.*, 5.0.0)" } }调整Terraform打包逻辑
若使用预编译依赖,需修改data "archive_file"确保.python_packages目录被包含在Zip包中,可通过source_files指定所有需要打包的文件或目录。
内容的提问来源于stack exchange,提问作者Nakeuh
相关产品推荐
相关产品推荐

