如何用Terraform实现Azure与Git自动部署及解决授权错误
Terraform实现Git变更自动部署Azure的完整解决方案(修复404 SourceControlToken错误)
错误原因
出现无法找到名为GitHub的SourceControlToken 404错误,核心原因是Azure环境中未创建对应名称的源代码控制令牌,或令牌名称与Terraform代码中引用的名称不匹配,导致部署配置无法关联到有效的GitHub授权凭证。
GitHub端必要配置(OAuth授权应用)
1. 创建GitHub OAuth应用
- 登录GitHub账号,进入Settings > Developer settings > OAuth Apps,点击New OAuth App
- 填写配置信息:
- Application name:自定义名称(如
Azure-Auto-Deploy) - Homepage URL:填写你的目标GitHub仓库地址(如
https://github.com/your-username/your-deploy-repo) - Authorization callback URL:填写
https://management.azure.com
- Application name:自定义名称(如
- 注册完成后,复制生成的Client ID和Client Secret(Client Secret生成后仅显示一次,务必立即保存)
2. 授予仓库权限
- 进入目标GitHub仓库,打开Settings > Applications
- 找到刚创建的OAuth应用,授予
repo权限(私有仓库必填,公有仓库可选择public_repo)
修正后的Terraform代码
以下示例以App Service自动部署为例,核心是添加azurerm_source_control_token资源解决404错误:
main.tf
terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = "~> 3.0" } } } provider "azurerm" { features {} } # 创建GitHub源代码控制令牌(解决404错误的核心配置) resource "azurerm_source_control_token" "github" { name = "GitHub" # 名称必须与报错提示的一致 token_type = "GitHub" token = var.github_auth_token # 填写GitHub OAuth Client Secret或PAT organization = "" # 若使用GitHub组织仓库,填写组织名称;个人仓库留空 } # 资源组配置 resource "azurerm_resource_group" "deploy_group" { name = "auto-deploy-rg" location = "East Asia" } # App Service计划 resource "azurerm_app_service_plan" "deploy_plan" { name = "auto-deploy-plan" resource_group_name = azurerm_resource_group.deploy_group.name location = azurerm_resource_group.deploy_group.location sku { tier = "Basic" size = "B1" } } # App Service实例 resource "azurerm_app_service" "deploy_app" { name = "auto-deploy-app-${random_string.suffix.result}" resource_group_name = azurerm_resource_group.deploy_group.name location = azurerm_resource_group.deploy_group.location app_service_plan_id = azurerm_app_service_plan.deploy_plan.id } # 随机字符串避免App Service名称冲突 resource "random_string" "suffix" { length = 4 special = false upper = false } # 配置自动部署:关联GitHub仓库与App Service resource "azurerm_app_service_deployment_source" "github_deploy" { app_id = azurerm_app_service.deploy_app.id repo_url = "https://github.com/your-username/your-deploy-repo" branch = "main" use_manual_integration = false # 开启代码变更自动触发部署 source_control_token_id = azurerm_source_control_token.github.id }
variables.tf
variable "github_auth_token" { type = string description = "GitHub OAuth Client Secret or Personal Access Token" sensitive = true # 标记为敏感变量,避免输出泄露 }
完整分步实现流程
1. 前置准备
- 安装Terraform并配置环境变量
- 通过Azure CLI登录Azure:
az login - 完成上述GitHub OAuth应用创建与权限配置
- 确保目标GitHub仓库包含可正常构建的应用代码
2. Terraform部署执行
- 创建本地代码目录,将上述
main.tf和variables.tf放入目录 - 初始化Terraform:
terraform init - 预览部署计划:
terraform plan,确认资源创建逻辑无误 - 执行部署:
terraform apply,当提示输入github_auth_token时,填入之前保存的GitHub OAuth Client Secret或PAT - 部署完成后,进入Azure Portal的App Service页面,查看Deployment Center确认已关联GitHub仓库
3. 自动部署验证
- 修改GitHub仓库代码并提交到指定分支(如
main) - 回到Azure App Service的Deployment Center,查看是否自动触发部署任务
- 部署完成后访问App Service域名,验证代码变更已生效
4. 常见问题排查
- 若仍出现404错误:检查
azurerm_source_control_token的name是否与报错提示完全一致;或登录Azure Portal,在App Service > Deployment Center > Manage token中确认是否存在名为GitHub的令牌 - 自动部署未触发:检查GitHub仓库的Webhook是否已自动创建(仓库Settings > Webhooks),或确认Terraform中
use_manual_integration已设为false
内容的提问来源于stack exchange,提问作者Lekha
相关产品推荐
相关产品推荐

