使用Terraform部署Azure托管Airflow实例启动失败求助
尝试通过Terraform在Azure上创建托管Airflow实例,Terraform plan和apply执行成功,资源已创建,但Airflow运行时在UI中先显示Starting,约20分钟后变为Stopped并报错。使用的Terraform代码如下:
terraform { required_version = "~> 1.3" required_providers { azurerm = { source = "hashicorp/azurerm" version = ">= 3.71, < 4.0" } azapi = { source = "Azure/azapi" version = ">= 1.9.0" } } } provider "azapi" { } provider "azurerm" { features {} } resource "azurerm_resource_group" "example-rg" { name = "someresourcegroupname" location = "uksouth" } resource "azurerm_data_factory" "example-adf" { name = "someadfexamplename" location = azurerm_resource_group.example-rg.location resource_group_name = azurerm_resource_group.example-rg.name } resource "azapi_resource" "example-adf_airflow" { type = "Microsoft.DataFactory/factories/integrationRuntimes@2018-06-01" name = "Airflow1" parent_id = azurerm_data_factory.example-adf.id schema_validation_enabled = false timeouts {} body = jsonencode({ properties = { type = "Airflow" description = "Airflow integration runtime" typeProperties = { computeProperties = { location = azurerm_data_factory.example-adf.location enableAutoscale = false enableAvailabilityZones = false computeSize = "Small" extraNodes = 0 } airflowProperties = { airflowRequirements = ["azure-cli==2.52.0"] enableTriggerers = false gitSyncProperties = { branch = "main" encryptedCredential = "encryptedCredentialGoHere" gitCredentialType = "PAT" gitServiceType = "Github" repo = "https://github.com/repo/reponame.git" username = "username" } airflowVersion = "2.4.3" enableAADIntegration = true airflowEntityReferences = [] encryptedSecrets = [] secrets = [] pythonVersion = "3.8" } } } }) }
Git同步配置无效
代码中encryptedCredential使用的是占位符encryptedCredentialGoHere,Azure无法识别该值来拉取Git仓库。需要通过Azure CLI生成有效的加密凭证:az datafactory integration-runtime git-credential encrypt --resource-group <你的资源组名> --factory-name <你的数据工厂名> --git-repo-url <仓库地址> --git-username <用户名> --git-password <你的PAT>将命令返回的加密字符串替换到
encryptedCredential字段中。同时检查:- PAT是否拥有仓库的读取权限
- Git分支
main是否存在 - 仓库URL是否正确可访问
依赖包冲突或兼容性问题
airflowRequirements中指定的azure-cli==2.52.0可能与Airflow 2.4.3存在依赖冲突。可以尝试移除该依赖,先启动Airflow实例,确认正常后再逐步添加需要的包;或者核对Azure官方文档中Airflow 2.4.3兼容的azure-cli版本。计算资源不足
当前配置的computeSize = "Small"且extraNodes = 0,可能无法满足Airflow启动的资源需求。可以尝试将computeSize调整为Medium,重新部署后观察启动状态。AAD集成配置缺失权限
enableAADIntegration = true但未配置对应的AAD权限,导致Airflow运行时无法获取必要的资源访问权限。检查数据工厂或Airflow运行时的托管身份是否拥有:- 存储账户的访问权限(若使用Azure存储)
- Git仓库的AAD访问权限(若使用AAD认证而非PAT)
查看Azure活动日志获取详细错误
登录Azure门户,进入对应的资源组,查看活动日志,筛选Airflow运行时相关的失败事件,日志中会包含具体的错误原因(如Git拉取失败、依赖安装超时、权限拒绝等),根据具体信息针对性解决。
内容的提问来源于stack exchange,提问作者csukcl

