You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Function App无法访问存储账户致运行时不可达问题排查与解决

Azure Function Runtime 不可达问题排查与解决(Terraform部署+存储账户Zip包)

问题描述

基于Python开发Azure Function App,计划通过存储账户中的Zip包部署,所有资源使用Terraform编排。Terraform执行无报错,Azure门户可见全部资源,但Function App无法运行,门户提示*"Azure Functions Runtime is unreachable"*。

已确认Zip包已成功上传且可通过浏览器直接下载,但Function App始终无法正常访问。

通过Terraform创建的核心资源:

  • Function App(复用已有App Service Plan)
  • 用户托管标识(已分配Reader和Storage Blob Data Contributor角色,用于访问KeyVault及存储账户)
  • 存储账户及对应Storage Blob

尝试通过托管标识或存储账户访问密钥配置Function App的存储访问权限,均未解决问题。疑问:是否需要为存储账户创建专用端点?还有哪些排查方向?


编辑1:问题已解决

最终通过为Zip包的存储URL添加SAS令牌解决了Runtime不可达问题,相关代码细节如下:

存储Blob上传的Terraform代码

resource "azurerm_storage_blob" "updater" {
  name                   = "func-name.zip"
  storage_account_name   = azurerm_storage_account.updater.name
  storage_container_name = azurerm_storage_container.updater.name
  type                   = "Block"
  content_md5            = local.updater_md5
  source                 = local.updater_file_path
}

原Function App配置(存在问题)

resource "azurerm_linux_function_app" "updater" {
  name                = "func-app-name"
  // 省略其他配置代码
  app_settings = {
    "WEBSITE_RUN_FROM_PACKAGE" = azurerm_storage_blob.updater.url 
    // 省略其他应用设置
  }
}

修改后的Function App配置(解决问题)

将WEBSITE_RUN_FROM_PACKAGE的取值替换为包含SAS令牌的完整Blob URL:

"WEBSITE_RUN_FROM_PACKAGE" = "https://${azurerm_storage_account.updater.name}.blob.core.windows.net/${azurerm_storage_container.updater.name}/${azurerm_storage_blob.updater.name}${data.azurerm_storage_account_blob_container_sas.updater.sas}"

内容的提问来源于stack exchange,提问作者phanxen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 22:52:52