You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署本地WAR文件至Azure App Service后无法访问求助

问题:Azure App Service无法部署存储账户中的WAR文件

我将本地下载目录中的.war文件通过Terraform上传到了Azure存储容器,但创建的App Service无法正常访问,不清楚App Service与存储账户的关联机制,以下是我的Terraform代码:

provider "azurerm" {
  features {}
}

resource "azurerm_resource_group" "rg2" {
  name     = "resoursegrpthree"
  location = "East US"
}

resource "azurerm_virtual_network" "virtunet1" {
  name                = "virnetxample"
  address_space       = ["10.0.0.0/16"]
  location            = azurerm_resource_group.rg2.location
  resource_group_name = azurerm_resource_group.rg2.name
}

resource "azurerm_subnet" "snet1" {
  name                 = "sunetxample"
  resource_group_name  = azurerm_resource_group.rg2.name
  virtual_network_name = azurerm_virtual_network.virtunet1.name
  address_prefixes     = ["10.0.1.0/24"]
  delegation {
    name = "delegationapp2"

    service_delegation {
      name    = "Microsoft.Web/serverFarms"
      actions = ["Microsoft.Network/virtualNetworks/subnets/action"]
    }
  }
}


resource "azurerm_app_service_plan" "azurewebapp2" {
  name                = "example-appservice-plan"
  location            = azurerm_resource_group.rg2.location
  resource_group_name = azurerm_resource_group.rg2.name
  kind                = "Linux"
  reserved            = true
  sku {
    tier = "Standard"
    size = "B1"
  }
}

resource "azurerm_app_service" "appservice2" {
  name                = "terraformappsvc"
  location            = azurerm_resource_group.rg2.location
  resource_group_name = azurerm_resource_group.rg2.name
  app_service_plan_id = azurerm_app_service_plan.azurewebapp2.id

  site_config {
    java_version = "1.8"
    java_container = "TOMCAT"
    java_container_version = "9.0"
    remote_debugging_enabled = true
  }

  app_settings = {
    "WEBSITE_WEBDEPLOY_USE_SCM" = "true"
  }

  connection_string {
    name  = "ExampleDB"
    type  = "SQLServer"
    value = "Server=myserver;User Id=myuser;Password=mypassword;Initial Catalog=mydb;"
  }
}

resource "azurerm_storage_account" "storagesecond2" {
  name                     = "accountstoragsec2"
  resource_group_name      = azurerm_resource_group.rg2.name
  location                 = azurerm_resource_group.rg2.location
  account_tier             = "Standard"
  account_replication_type = "LRS"
}
resource "azurerm_storage_container" "storageofwebapp" {
  name                  = "webappcontainer"
  storage_account_name = azurerm_storage_account.storagesecond2.name
  container_access_type = "private"
}

resource "azurerm_storage_blob" "blobexample" {
  name                   = "ram.war"
  storage_account_name  = azurerm_storage_account.storagesecond2.name
  storage_container_name = azurerm_storage_container.storageofwebapp.name
  type                   = "Block"
  source                 = "C:/Users/s***/Downloads/My_App.war"
}

resource "azurerm_app_service_virtual_network_swift_connection" "netswixam" {
  app_service_id = azurerm_app_service.appservice2.id
  subnet_id      = azurerm_subnet.snet1.id
}

核心问题

当前代码仅完成了存储资源创建、WAR文件上传和App Service基础配置,但未建立App Service与存储Blob的部署关联——App Service不知道需要从存储容器拉取WAR文件进行部署,这是应用无法访问的关键原因。

修复方案

1. 为App Service分配存储访问权限

启用App Service的系统分配身份,并赋予存储Blob数据读取权限,确保它能访问私有容器中的文件:

# 修改原有App Service资源,添加系统身份
resource "azurerm_app_service" "appservice2" {
  # 保留原有所有配置...
  identity {
    type = "SystemAssigned"
  }
}

# 给App Service的系统身份分配存储Blob读取权限
resource "azurerm_role_assignment" "app_storage_access" {
  scope                = azurerm_storage_account.storagesecond2.id
  role_definition_name = "Storage Blob Data Reader"
  principal_id         = azurerm_app_service.appservice2.identity[0].principal_id
}

2. 配置App Service从存储Blob部署WAR包

通过Terraform配置部署中心,指定从存储Blob拉取WAR文件:

resource "azurerm_app_service_source_control" "war_deployment" {
  app_service_id              = azurerm_app_service.appservice2.id
  repo_url                    = "https://${azurerm_storage_account.storagesecond2.name}.blob.core.windows.net/${azurerm_storage_container.storageofwebapp.name}/${azurerm_storage_blob.blobexample.name}"
  use_manual_integration      = true
  rollback_enabled            = true
}

3. 补充网络验证(可选)

因为App Service关联了虚拟网络,需确保:

  • 子网已启用Microsoft.Storage服务端点
  • 若存储账户开启防火墙,需将App Service的虚拟网络加入允许列表

4. 验证部署结果

部署完成后,可通过Azure CLI检查部署状态:

az webapp deployment show --name terraformappsvc --resource-group resoursegrpthree

内容的提问来源于stack exchange,提问作者Lekha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 19:40:39