You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform azurerm配置Azure Linux Web App的Azure Pipelines部署选项

问题描述

已通过Terraform创建了Azure Linux Web App,希望在其中运行容器并通过Azure Pipelines发布镜像。当前使用的Terraform App Service模块代码如下:

resource "azurerm_linux_web_app" "main_app" {
  name                = var.app_service_name
  location            = var.location
  resource_group_name = var.resource_group_name
  service_plan_id     = var.app_service_plan_id

  site_config {
    ftps_state                              = var.app_service_config.site_config.ftps_state
    http2_enabled                           = var.app_service_config.site_config.http2_enabled
    minimum_tls_version                     = var.app_service_config.site_config.minimum_tls_version
    linux_fx_version                        = var.linux_fx_version
    always_on                               = var.app_service_config.site_config.always_on
    container_registry_use_managed_identity = var.app_service_config.site_config.container_registry_use_managed_identity

    dynamic "application_stack" {
      for_each = var.docker_image_name != null ? [1] : []
      content {
        docker_image_name   = var.docker_image_name
        docker_registry_url = var.docker_registry_url
      }
    }

    app_settings = var.app_settings_map

    identity {
      type = var.identity_type
    }

    tags = {
      environment = var.env
      app         = var.app
    }
  }
}

已配置docker_image_name和docker_registry_url为Azure容器注册表中的值,身份类型为SystemAssigned,且container_registry_use_managed_identity设为true。Web App已正常运行,但希望将镜像部署方式从自动拉取更新改为通过Azure Pipelines发布(即Azure部署中心中指定的对应选项),请问如何通过Terraform的azurerm provider在azurerm_linux_web_app资源中配置该选项?

解决方案

要切换为Azure Pipelines发布模式,需要通过Web App的应用设置覆盖自动拉取行为,并启用SCM部署支持,具体操作如下:

  1. 添加关键应用设置
    在site_config的app_settings中加入以下两个配置项:
  • DOCKER_ENABLE_CI: 设置为"false",关闭Web App自动监听容器注册表镜像更新并拉取的功能
  • WEBSITE_WEBDEPLOY_USE_SCM: 设置为"true",启用基于SCM(站点控制管理器)的外部部署模式,对应Azure Pipelines的发布流程
  1. 修改Terraform代码
    可以通过merge函数将新配置合并到原有app_settings_map中,避免覆盖已有配置:
resource "azurerm_linux_web_app" "main_app" {
  name                = var.app_service_name
  location            = var.location
  resource_group_name = var.resource_group_name
  service_plan_id     = var.app_service_plan_id

  site_config {
    ftps_state                              = var.app_service_config.site_config.ftps_state
    http2_enabled                           = var.app_service_config.site_config.http2_enabled
    minimum_tls_version                     = var.app_service_config.site_config.minimum_tls_version
    linux_fx_version                        = var.linux_fx_version
    always_on                               = var.app_service_config.site_config.always_on
    container_registry_use_managed_identity = var.app_service_config.site_config.container_registry_use_managed_identity

    dynamic "application_stack" {
      for_each = var.docker_image_name != null ? [1] : []
      content {
        docker_image_name   = var.docker_image_name
        docker_registry_url = var.docker_registry_url
      }
    }

    # 合并原有配置与新的部署模式配置
    app_settings = merge(var.app_settings_map, {
      DOCKER_ENABLE_CI = "false"
      WEBSITE_WEBDEPLOY_USE_SCM = "true"
    })

    identity {
      type = var.identity_type
    }

    tags = {
      environment = var.env
      app         = var.app
    }
  }
}
  1. 配置说明
  • DOCKER_ENABLE_CI=false:默认情况下,当Web App关联容器注册表时,会自动启用镜像更新触发的自动部署,关闭此配置后将停止自动拉取
  • WEBSITE_WEBDEPLOY_USE_SCM=true:开启后,允许Azure Pipelines通过SCM接口推送镜像部署指令,对应Azure部署中心中选择Azure Pipelines的部署模式

完成配置后,执行terraform apply更新Web App,即可切换为通过Azure Pipelines手动/触发式发布镜像的模式。

内容的提问来源于stack exchange,提问作者Orbyter in cloud

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 17:40:36