You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Bicep脚本为Web App部署槽分配专用终结点

Azure Web App部署槽专用终结点关联问题修复方案

问题背景

已通过Bicep定义Azure Web App主站点及名为preview的部署槽,并尝试为部署槽创建专用终结点,但当前终结点连接仅关联到父应用,未正确绑定到preview部署槽。

现有配置代码

主站点资源:

resource app 'Microsoft.Web/sites@2022-09-01' = {
  name: '${appName}-${env}'
  location: location

  identity: {
    type: 'SystemAssigned'
  }

  properties: {
    serverFarmId: servicePlanId
    httpsOnly: true
    // clientAffinityEnabled: false
    virtualNetworkSubnetId: subnetId

    siteConfig: {
      ftpsState: 'Disabled'
      minTlsVersion: '1.2'
      publicNetworkAccess: 'Disabled'
    }
  }
}

部署槽资源:

resource stagingSlot 'Microsoft.Web/sites/slots@2021-02-01' = {
  name: 'preview'
  parent: app
  location: location
  kind: 'app'
  properties: {
    serverFarmId: servicePlanId
  }
}

现有专用终结点连接配置:

resource stagingSlotEndpoint 'Microsoft.Web/sites/slots/privateEndpointConnections@2022-03-01' = {
  name: '${appName}-preview'
  kind: 'app'
  parent: stagingSlot
  properties: {
    privateLinkServiceConnectionState: {
      status: 'Approved'
      description: 'Auto-Approved'
      actionsRequired: 'None'
    }
  }
}

修复方案

需从API版本统一、资源标识指定、终结点关联三个维度调整配置:

1. 统一API版本

部署槽与专用终结点连接的API版本需与主站点保持一致(如2022-09-01),避免版本差异导致的资源层级识别异常。更新后的部署槽代码:

resource stagingSlot 'Microsoft.Web/sites/slots@2022-09-01' = {
  name: 'preview'
  parent: app
  location: location
  kind: 'app'
  properties: {
    serverFarmId: servicePlanId
    // 同步主站点安全配置,确保一致性
    httpsOnly: true
    publicNetworkAccess: 'Disabled'
    siteConfig: {
      ftpsState: 'Disabled'
      minTlsVersion: '1.2'
    }
  }
}

2. 完善专用终结点及连接配置

专用终结点需明确关联部署槽的资源ID,并指定groupIds为['slots'](主站点对应['sites']),以此区分关联目标。完整配置示例:

// 1. 创建部署槽专用终结点
resource stagingPrivateEndpoint 'Microsoft.Network/privateEndpoints@2023-04-01' = {
  name: '${appName}-preview-pe'
  location: location
  properties: {
    subnet: {
      id: subnetId
    }
    privateLinkServiceConnections: [
      {
        name: '${appName}-preview-pls'
        properties: {
          privateLinkServiceId: stagingSlot.id
          groupIds: ['slots'] // 关键:指定关联部署槽类型
        }
      }
    ]
  }
}

// 2. 创建部署槽的专用终结点连接并审批
resource stagingSlotEndpoint 'Microsoft.Web/sites/slots/privateEndpointConnections@2022-09-01' = {
  name: stagingPrivateEndpoint.name
  parent: stagingSlot
  properties: {
    privateEndpoint: {
      id: stagingPrivateEndpoint.id // 绑定到部署槽的专用终结点
    }
    privateLinkServiceConnectionState: {
      status: 'Approved'
      description: 'Auto-Approved'
      actionsRequired: 'None'
    }
    groupIds: ['slots'] // 再次确认关联标识
  }
}

关键注意事项

  • GroupIds标识:groupIds是区分主站点与部署槽的核心参数,部署槽必须设置为['slots'],否则会默认关联主站点的sites标识。
  • 资源关联正确性:专用终结点的privateLinkServiceId必须指向部署槽的资源ID(stagingSlot.id),而非主站点ID。
  • API版本兼容性:确保所有相关资源(Web App、部署槽、专用终结点、终结点连接)使用兼容的API版本,避免因版本差异导致的元数据解析错误。

内容的提问来源于stack exchange,提问作者cpoDesign

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 19:17:46