You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure PostgreSQL添加VNET规则时遇FeatureSwitchNotEnabled错误求助

解决Azure PostgreSQL添加VNET规则时的FeatureSwitchNotEnabled错误

问题场景

在通过Terraform为Azure PostgreSQL数据库添加VNET规则时,触发如下错误:

│ Virtual Network Rule Name: "allow-app-service-access-0"): performing
CreateOrUpdate:
virtualnetworkrules.VirtualNetworkRulesClient#CreateOrUpdate: Failure
sending request: StatusCode=0 -- Original Error:
Code="FeatureSwitchNotEnabled" Message="Requested feature is not
enabled"

现有Terraform配置

resource "azurerm_postgresql_virtual_network_rule" "allow_app_service_access" {
  count = length(var.subnet_whitelist)

  name                                 = "allow-app-service-access-${count.index}"
  resource_group_name                  = var.resource_group_name
  server_name                          = azurerm_postgresql_server.app_postgres_server.name
  subnet_id                            = var.subnet_whitelist[count.index]
  ignore_missing_vnet_service_endpoint = true
}

已执行操作

尝试注册相关功能,但状态始终处于Pending:

az feature register --namespace Microsoft.DBforPostgreSQL  --name "firewallRuleAllowAzureServices"

az feature register --namespace Microsoft.DBforPostgreSQL  --name "vnet"

功能状态查询结果:

{
    "id": "/subscriptions/id/providers/Microsoft.Features/providers/Microsoft.DBforPostgreSQL/features/firewallRuleAllowAzureServices",
    "name": "Microsoft.DBforPostgreSQL/firewallRuleAllowAzureServices",
    "properties": {
      "state": "Pending"
    },
    "type": "Microsoft.Features/providers/features"
  },
  {
    "id": "/subscriptions/id/providers/Microsoft.Features/providers/Microsoft.DBforPostgreSQL/features/vnet",
    "name": "Microsoft.DBforPostgreSQL/vnet",
    "properties": {
      "state": "Pending"
    },
    "type": "Microsoft.Features/providers/features"
  } 

有效解决步骤

  • 等待功能注册完成
    功能注册通常需要10-30分钟,视Azure负载可能更久。定期用以下命令查询状态,直到state变为Registered:

    az feature show --namespace Microsoft.DBforPostgreSQL --name "vnet"
    az feature show --namespace Microsoft.DBforPostgreSQL --name "firewallRuleAllowAzureServices"
    
  • 重新注册资源提供者
    功能注册完成后,必须重新注册Microsoft.DBforPostgreSQL提供者确保变更生效:

    az provider register --namespace Microsoft.DBforPostgreSQL
    

    用以下命令检查状态,直到registrationState变为Registered:

    az provider show --namespace Microsoft.DBforPostgreSQL --query "registrationState"
    
  • 检查服务器SKU类型
    Azure PostgreSQL的基本层(Basic Tier)不支持VNET规则,仅通用层(General Purpose)和内存优化层(Memory Optimized)支持该功能。如果服务器是Basic层,需先升级SKU再操作。

  • 确认子网服务端点配置
    虽然配置中设置了ignore_missing_vnet_service_endpoint = true,但为避免后续连接问题,建议给目标子网启用Microsoft.Sql服务端点:

    az network subnet update --name <subnet-name> --resource-group <rg-name> --vnet-name <vnet-name> --service-endpoints "Microsoft.Sql"
    

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 05:12:21