You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform实现Azure与Git自动部署及解决授权错误

Terraform实现Git变更自动部署Azure的完整解决方案(修复404 SourceControlToken错误)

错误原因

出现无法找到名为GitHub的SourceControlToken 404错误,核心原因是Azure环境中未创建对应名称的源代码控制令牌,或令牌名称与Terraform代码中引用的名称不匹配,导致部署配置无法关联到有效的GitHub授权凭证。


GitHub端必要配置(OAuth授权应用)

1. 创建GitHub OAuth应用

  • 登录GitHub账号,进入Settings > Developer settings > OAuth Apps,点击New OAuth App
  • 填写配置信息:
    • Application name:自定义名称(如Azure-Auto-Deploy)
    • Homepage URL:填写你的目标GitHub仓库地址(如https://github.com/your-username/your-deploy-repo)
    • Authorization callback URL:填写https://management.azure.com
  • 注册完成后,复制生成的Client ID和Client Secret(Client Secret生成后仅显示一次,务必立即保存)

2. 授予仓库权限

  • 进入目标GitHub仓库,打开Settings > Applications
  • 找到刚创建的OAuth应用,授予repo权限(私有仓库必填,公有仓库可选择public_repo)

修正后的Terraform代码

以下示例以App Service自动部署为例,核心是添加azurerm_source_control_token资源解决404错误:

main.tf

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.0"
    }
  }
}

provider "azurerm" {
  features {}
}

# 创建GitHub源代码控制令牌(解决404错误的核心配置)
resource "azurerm_source_control_token" "github" {
  name        = "GitHub" # 名称必须与报错提示的一致
  token_type  = "GitHub"
  token       = var.github_auth_token # 填写GitHub OAuth Client Secret或PAT
  organization = "" # 若使用GitHub组织仓库,填写组织名称;个人仓库留空
}

# 资源组配置
resource "azurerm_resource_group" "deploy_group" {
  name     = "auto-deploy-rg"
  location = "East Asia"
}

# App Service计划
resource "azurerm_app_service_plan" "deploy_plan" {
  name                = "auto-deploy-plan"
  resource_group_name = azurerm_resource_group.deploy_group.name
  location            = azurerm_resource_group.deploy_group.location
  sku {
    tier = "Basic"
    size = "B1"
  }
}

# App Service实例
resource "azurerm_app_service" "deploy_app" {
  name                = "auto-deploy-app-${random_string.suffix.result}"
  resource_group_name = azurerm_resource_group.deploy_group.name
  location            = azurerm_resource_group.deploy_group.location
  app_service_plan_id = azurerm_app_service_plan.deploy_plan.id
}

# 随机字符串避免App Service名称冲突
resource "random_string" "suffix" {
  length  = 4
  special = false
  upper   = false
}

# 配置自动部署:关联GitHub仓库与App Service
resource "azurerm_app_service_deployment_source" "github_deploy" {
  app_id                = azurerm_app_service.deploy_app.id
  repo_url              = "https://github.com/your-username/your-deploy-repo"
  branch                = "main"
  use_manual_integration = false # 开启代码变更自动触发部署
  source_control_token_id = azurerm_source_control_token.github.id
}

variables.tf

variable "github_auth_token" {
  type        = string
  description = "GitHub OAuth Client Secret or Personal Access Token"
  sensitive   = true # 标记为敏感变量,避免输出泄露
}

完整分步实现流程

1. 前置准备

  • 安装Terraform并配置环境变量
  • 通过Azure CLI登录Azure:az login
  • 完成上述GitHub OAuth应用创建与权限配置
  • 确保目标GitHub仓库包含可正常构建的应用代码

2. Terraform部署执行

  1. 创建本地代码目录,将上述main.tf和variables.tf放入目录
  2. 初始化Terraform:terraform init
  3. 预览部署计划:terraform plan,确认资源创建逻辑无误
  4. 执行部署:terraform apply,当提示输入github_auth_token时,填入之前保存的GitHub OAuth Client Secret或PAT
  5. 部署完成后,进入Azure Portal的App Service页面,查看Deployment Center确认已关联GitHub仓库

3. 自动部署验证

  • 修改GitHub仓库代码并提交到指定分支(如main)
  • 回到Azure App Service的Deployment Center,查看是否自动触发部署任务
  • 部署完成后访问App Service域名,验证代码变更已生效

4. 常见问题排查

  • 若仍出现404错误:检查azurerm_source_control_token的name是否与报错提示完全一致;或登录Azure Portal,在App Service > Deployment Center > Manage token中确认是否存在名为GitHub的令牌
  • 自动部署未触发:检查GitHub仓库的Webhook是否已自动创建(仓库Settings > Webhooks),或确认Terraform中use_manual_integration已设为false

内容的提问来源于stack exchange,提问作者Lekha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 23:10:42