使用Terraform从私有GitHub仓库部署Azure Web App遇认证问题
问题描述
我已使用Terraform在Azure中创建了一个Linux Web App,希望通过私有GitHub仓库的CI来部署该Web App(如同在Azure门户中配置Web App时的操作)。当前编写的Terraform代码如下:
resource "azurerm_service_plan" "dev_plan" { provider = azurerm.dev name = "app-plan" location = azurerm_resource_group.dev_rg.location resource_group_name = azurerm_resource_group.dev_rg.name sku_name = "B1" os_type = "Linux" } resource "azurerm_linux_web_app" "dev_service" { provider = azurerm.dev name = "api" location = azurerm_resource_group.dev_rg.location resource_group_name = azurerm_resource_group.dev_rg.name service_plan_id = azurerm_service_plan.dev_plan.id https_only = true site_config { application_stack { dotnet_version = "7.0" } } } resource "azurerm_app_service_source_control" "dev_source" { provider = azurerm.dev app_id = azurerm_linux_web_app.dev_service.id repo_url = "REPO_URL" branch = "main" github_action_configuration { code_configuration { runtime_stack = "dotnetcore" runtime_version = "7.0" } } }
这段代码能正确创建App Service,但在执行azurerm_app_service_source_control步骤时失败,报错信息如下:
Error: creating Source Control configuration for Web App: (Site Name "api" / Resource Group "dev"): web.AppsClient#UpdateSourceControl: Failure responding to request: StatusCode=404 -- Original Error: autorest/azure: Service returned an error. Status=404 Code="NotFound" Message="Cannot find User with name 00000000-0000-0000-0000-000000000000." Details=[{"Message":"Cannot find User with name 00000000-0000-0000-0000-000000000000."},{"Code":"NotFound"},{"ErrorEntity":{"Code":"NotFound","ExtendedCode":"51004","Message":"Cannot find User with name 00000000-0000-0000-0000-000000000000.","MessageTemplate":"Cannot find {0} with name {1}.","Parameters":["User","00000000-0000-0000-0000-000000000000"]}}]
猜测是缺少GitHub部署的认证步骤,但查阅文档后仍未找到解决方法,请问有什么思路?
解决思路
这个错误核心是Azure无法找到关联的GitHub用户身份,因为配置GitHub Actions部署时,需要先完成Azure与GitHub的授权绑定,Terraform的azurerm_app_service_source_control资源本身不会自动处理这个授权。以下是具体解决步骤:
1. 创建GitHub个人访问令牌(PAT)
在GitHub上生成具有repo和workflow权限的个人访问令牌,用于Azure访问私有仓库。
2. 在Azure中存储PAT作为应用设置
在azurerm_linux_web_app资源中添加应用设置,将GitHub PAT存入其中(建议用Terraform变量或Azure Key Vault管理敏感信息,避免硬编码):
resource "azurerm_linux_web_app" "dev_service" { # 原有配置... app_settings = { "GITHUB_TOKEN" = var.github_pat } }
3. 完善azurerm_app_service_source_control配置
需要添加github_action_configuration中的secrets块引用存储的PAT,同时指定正确的GitHub仓库所有者用户名:
resource "azurerm_app_service_source_control" "dev_source" { provider = azurerm.dev app_id = azurerm_linux_web_app.dev_service.id repo_url = "https://github.com/你的GitHub用户名/仓库名.git" branch = "main" is_manual_integration = false github_action_configuration { code_configuration { runtime_stack = "dotnetcore" runtime_version = "7.0" } secrets { github_token = azurerm_linux_web_app.dev_service.app_settings["GITHUB_TOKEN"] } owner = "你的GitHub用户名" } }
4. 确保Azure账号权限与授权
- 执行Terraform的Azure账号需要拥有
Microsoft.Web/sites/sourcecontrols/write权限 - 可以先通过Azure门户手动配置一次该Web App的GitHub部署,完成Azure与GitHub的授权绑定后,再用Terraform执行配置覆盖
额外注意点
- 如果是GitHub组织仓库,需确保PAT拥有组织级访问权限,或目标仓库已单独授予PAT访问权限
- 避免在代码中硬编码敏感信息,优先使用Terraform变量、环境变量或Azure Key Vault存储PAT
内容的提问来源于stack exchange,提问作者Thomas Read
相关产品推荐
相关产品推荐

