使用Bicep部署Azure Container App失败:修订版配置超时
Azure Container App配置ACR注册表后部署失败的解决方法
问题描述
我使用如下Bicep模板部署Azure Container App,应用采用系统分配(SystemAssigned)身份,使用公共镜像mcr.microsoft.com/azuredocs/containerapps-helloworld:latest。模板中配置ACR私有仓库的注册表信息后,每次部署都会在10分钟后失败,报错提示"Failed to provision revision for container app";移除注册表配置段则可在1分钟内部署成功。该应用后续需通过流水线使用私有ACR镜像更新,请问如何通过Bicep正确配置注册表以避免部署失败?
原Bicep模板代码
resource containerApp 'Microsoft.App/containerApps@2023-04-01-preview' = { name: containerAppName location: location identity: { type: 'SystemAssigned' } properties: { environmentId: '/subscriptions/134343-32343-2343-83b5-exy3sd2343/resourceGroups/infra-rg/providers/Microsoft.App/managedEnvironments/my-env' configuration: { activeRevisionsMode: 'Single' ingress: { allowInsecure: false external: true targetPort: 5173 } registries: [ { server: '${acrName}.azurecr.io' identity: 'system' } ] } template: { containers: [ { name: 'my-app' command: [] image: 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest' resources: { cpu: json('0.25') memory: '.5Gi' } } ] } } }
报错信息
{ "status": "Failed", "error": { "code": "DeploymentFailed", "message": "At least one resource deployment operation failed. Please list deployment operations for details.", "details": [ { "code": "Conflict", "message": "{ \"status\": \"Failed\", \"error\": { \"code\": \"ResourceDeploymentFailure\", \"message\": \"The resource write operation failed to complete successfully, because it reached terminal provisioning state\", \"code\": \"ContainerAppOperationError\", \"message\": \"Failed to provision revision for container app 'my-capp'. Error details: Operation expired.\" } }" } ] } }
解决方案
问题根源
即使当前使用的是公共镜像,Azure在部署时仍会验证registries配置的有效性。由于Container App的系统分配身份没有ACR的访问权限,导致验证过程超时,最终部署失败。
正确配置步骤
为系统身份分配ACR拉取权限
在Bicep中添加角色分配资源,给Container App的系统身份分配AcrPull角色(如果后续需要推送镜像,可使用AcrPush角色)。保留正确的注册表配置
原模板中的registries段配置本身无误,但必须确保ACR服务器地址正确,且identity指定为system。
修正后的完整Bicep模板
// 引用现有ACR资源(如果ACR在当前部署中,可直接定义;否则用existing关键字) resource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' existing = { name: acrName } // 部署Container App resource containerApp 'Microsoft.App/containerApps@2023-04-01-preview' = { name: containerAppName location: location identity: { type: 'SystemAssigned' } properties: { environmentId: '/subscriptions/134343-32343-2343-83b5-exy3sd2343/resourceGroups/infra-rg/providers/Microsoft.App/managedEnvironments/my-env' configuration: { activeRevisionsMode: 'Single' ingress: { allowInsecure: false external: true targetPort: 5173 } registries: [ { server: acr.properties.loginServer identity: 'system' } ] } template: { containers: [ { name: 'my-app' command: [] image: 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest' resources: { cpu: json('0.25') memory: '.5Gi' } } ] } } } // 为Container App系统身份分配ACR拉取权限 resource containerAppAcrRoleAssign 'Microsoft.Authorization/roleAssignments@2022-04-01' = { name: guid(acr.id, containerApp.id, 'AcrPull') scope: acr properties: { roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', '7f951dda-4ed3-4680-a7ca-43fe172d538d') // AcrPull角色固定ID principalId: containerApp.identity.principalId principalType: 'ServicePrincipal' } }
额外说明
7f951dda-4ed3-4680-a7ca-43fe172d538d是AcrPull角色的固定ID,可直接使用。- 如果ACR和Container App不在同一资源组,需确保部署用户拥有在ACR资源范围内创建角色分配的权限。
- 部署完成后,后续切换到私有ACR镜像时,无需修改注册表配置,系统身份已具备拉取权限。
内容的提问来源于stack exchange,提问作者Coder
相关产品推荐
相关产品推荐

