You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep部署Azure Container App失败:修订版配置超时

Azure Container App配置ACR注册表后部署失败的解决方法

问题描述

我使用如下Bicep模板部署Azure Container App,应用采用系统分配(SystemAssigned)身份,使用公共镜像mcr.microsoft.com/azuredocs/containerapps-helloworld:latest。模板中配置ACR私有仓库的注册表信息后,每次部署都会在10分钟后失败,报错提示"Failed to provision revision for container app";移除注册表配置段则可在1分钟内部署成功。该应用后续需通过流水线使用私有ACR镜像更新,请问如何通过Bicep正确配置注册表以避免部署失败?

原Bicep模板代码

resource containerApp 'Microsoft.App/containerApps@2023-04-01-preview' = {
  name: containerAppName
  location: location
  identity: {
    type: 'SystemAssigned'
  }
  properties: {
    environmentId: '/subscriptions/134343-32343-2343-83b5-exy3sd2343/resourceGroups/infra-rg/providers/Microsoft.App/managedEnvironments/my-env'
    configuration: {
      activeRevisionsMode: 'Single'
      ingress: {
        allowInsecure: false
        external: true
        targetPort: 5173
      }
      registries: [
        {
          server: '${acrName}.azurecr.io'
          identity: 'system'
        } 
      ] 
    }
    template: {
      containers: [
        {
          name: 'my-app'
          command: []
          image: 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
          resources: {
            cpu: json('0.25')
            memory: '.5Gi'
          }
        }
      ]
    }
  }
}

报错信息

{
  "status": "Failed",
  "error": {
    "code": "DeploymentFailed",
    "message": "At least one resource deployment operation failed. Please list deployment operations for details.",
    "details": [
      {
        "code": "Conflict",
        "message": "{
          \"status\": \"Failed\",
          \"error\": {
            \"code\": \"ResourceDeploymentFailure\",
            \"message\": \"The resource write operation failed to complete successfully, because it reached terminal provisioning state\",
            \"code\": \"ContainerAppOperationError\",
            \"message\": \"Failed to provision revision for container app 'my-capp'. Error details: Operation expired.\"
          }
        }"
      }
    ]
  }
}

解决方案

问题根源

即使当前使用的是公共镜像,Azure在部署时仍会验证registries配置的有效性。由于Container App的系统分配身份没有ACR的访问权限,导致验证过程超时,最终部署失败。

正确配置步骤

  1. 为系统身份分配ACR拉取权限
    在Bicep中添加角色分配资源,给Container App的系统身份分配AcrPull角色(如果后续需要推送镜像,可使用AcrPush角色)。

  2. 保留正确的注册表配置
    原模板中的registries段配置本身无误,但必须确保ACR服务器地址正确,且identity指定为system。

修正后的完整Bicep模板

// 引用现有ACR资源(如果ACR在当前部署中,可直接定义;否则用existing关键字)
resource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' existing = {
  name: acrName
}

// 部署Container App
resource containerApp 'Microsoft.App/containerApps@2023-04-01-preview' = {
  name: containerAppName
  location: location
  identity: {
    type: 'SystemAssigned'
  }
  properties: {
    environmentId: '/subscriptions/134343-32343-2343-83b5-exy3sd2343/resourceGroups/infra-rg/providers/Microsoft.App/managedEnvironments/my-env'
    configuration: {
      activeRevisionsMode: 'Single'
      ingress: {
        allowInsecure: false
        external: true
        targetPort: 5173
      }
      registries: [
        {
          server: acr.properties.loginServer
          identity: 'system'
        } 
      ] 
    }
    template: {
      containers: [
        {
          name: 'my-app'
          command: []
          image: 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
          resources: {
            cpu: json('0.25')
            memory: '.5Gi'
          }
        }
      ]
    }
  }
}

// 为Container App系统身份分配ACR拉取权限
resource containerAppAcrRoleAssign 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(acr.id, containerApp.id, 'AcrPull')
  scope: acr
  properties: {
    roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', '7f951dda-4ed3-4680-a7ca-43fe172d538d') // AcrPull角色固定ID
    principalId: containerApp.identity.principalId
    principalType: 'ServicePrincipal'
  }
}

额外说明

  • 7f951dda-4ed3-4680-a7ca-43fe172d538d是AcrPull角色的固定ID,可直接使用。
  • 如果ACR和Container App不在同一资源组,需确保部署用户拥有在ACR资源范围内创建角色分配的权限。
  • 部署完成后,后续切换到私有ACR镜像时,无需修改注册表配置,系统身份已具备拉取权限。

内容的提问来源于stack exchange,提问作者Coder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 15:02:02