You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何避免Terraform重建Azure资源时手动添加Container Registry至服务连接

解决Azure流水线重建时手动添加Container Registry到服务连接的问题

你当前的Terraform脚本可正常部署基础设施,但每次删除资源组后通过流水线重建时,都需要手动将新创建的Container Registry添加到Azure服务连接中。可以通过添加Azure DevOps服务连接的自动化配置来避免这个手动操作,以下是修改后的完整代码:

terraform {
  backend "azurerm" {}
}

# Azure资源管理器Provider
provider "azurerm" {
  features {}
}

# Azure DevOps Provider,用于管理服务连接
provider "azuredevops" {
  org_service_url = var.devops_organization_url
}

resource "azurerm_resource_group" "rg-dnma" {
  name     = var.resource_group_name
  location = var.resource_group_location
}

resource "azurerm_container_registry" "cr-dnma" {
  name                = var.container_registry_name
  resource_group_name = azurerm_resource_group.rg-dnma.name
  location            = azurerm_resource_group.rg-dnma.location
  sku                 = var.container_registry_sku
  admin_enabled       = true
}

resource "azurerm_service_plan" "sp-dnma" {
  name                = var.service_plan_name
  location            = azurerm_resource_group.rg-dnma.location
  resource_group_name = azurerm_resource_group.rg-dnma.name
  os_type             = var.service_plan_os_type
  sku_name            = var.service_plan_sku_name
}

resource "azurerm_linux_web_app" "lwa-dnma" {
  name                = var.linux_web_app_name
  resource_group_name = azurerm_resource_group.rg-dnma.name
  location            = azurerm_resource_group.rg-dnma.location
  service_plan_id     = azurerm_service_plan.sp-dnma.id
  https_only          = var.linux_web_app_https_only
  app_settings = {
    "DOCKER_REGISTRY_SERVER_URL"      = "https://${azurerm_container_registry.cr-dnma.login_server}"
    "DOCKER_REGISTRY_SERVER_PASSWORD" = azurerm_container_registry.cr-dnma.admin_password
    "DOCKER_REGISTRY_SERVER_USERNAME" = azurerm_container_registry.cr-dnma.admin_username
  }

  site_config {
    application_stack {
      docker_registry_url      = "https://${azurerm_container_registry.cr-dnma.login_server}"
      docker_image_name        = "${var.linux_web_app_name}:${var.build_id}"
      docker_registry_username = azurerm_container_registry.cr-dnma.admin_username
      docker_registry_password = azurerm_container_registry.cr-dnma.admin_password
    }
  }
}

# 自动创建Azure DevOps中关联ACR的服务连接
resource "azuredevops_service_endpoint_azure_container_registry" "acr_service_connection" {
  project_id            = azuredevops_project.project.id
  name                  = "${var.container_registry_name}-service-connection"
  azure_registry_id     = azurerm_container_registry.cr-dnma.id
  service_endpoint_name = "${var.container_registry_name}-service-connection"
  
  # 使用服务主体认证,确保流水线有足够权限
  authentication {
    type = "spnKey"
    serviceprincipalid   = var.devops_service_principal_id
    serviceprincipalkey  = var.devops_service_principal_key
    tenantid             = var.azure_tenant_id
  }
}

# 引用已存在的Azure DevOps项目(如果项目已创建)
data "azuredevops_project" "project" {
  name = var.devops_project_name
}

关键说明:

  1. 添加Azure DevOps Provider:引入azuredevops Provider来管理服务连接,需配置Azure DevOps组织URL。
  2. 自动创建ACR服务连接:通过azuredevops_service_endpoint_azure_container_registry资源,将新创建的ACR自动关联到Azure DevOps服务连接,无需手动操作。
  3. 服务主体认证:使用服务主体进行认证,确保流水线拥有访问ACR的权限,需提前准备好服务主体的ID、密钥以及Azure租户ID。
  4. 修正ACR地址引用:将原脚本中硬编码的ACR地址改为引用azurerm_container_registry.cr-dnma.login_server,避免因名称不一致导致的错误。

需要补充的变量定义示例:

variable "devops_organization_url" {
  type        = string
  description = "Azure DevOps组织URL"
}

variable "devops_project_name" {
  type        = string
  description = "Azure DevOps项目名称"
}

variable "devops_service_principal_id" {
  type        = string
  description = "用于服务连接的服务主体ID"
}

variable "devops_service_principal_key" {
  type        = string
  description = "用于服务连接的服务主体密钥"
}

variable "azure_tenant_id" {
  type        = string
  description = "Azure租户ID"
}

# 保留你原有的变量定义
variable "resource_group_name" {
  type        = string
}
# ... 其他原有变量

内容的提问来源于stack exchange,提问作者Free Gameplays

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 07:16:12