You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署azurerm_linux_function_app时VNet集成循环变更问题

解决Terraform配置Linux Function App VNet集成循环变更问题

问题原因

使用azurerm_app_service_virtual_network_swift_connection为Linux Function App配置VNet集成后,Azure会自动在azurerm_linux_function_app的site_config中填充virtual_network_subnet_id属性。但你的配置未显式声明该属性,导致Terraform每次运行时都将其识别为"意外添加"的配置,提议移除;移除后,azurerm_app_service_virtual_network_swift_connection资源又会检测到VNet集成缺失,提议重新创建,最终形成循环变更。

解决方案

方案1:显式声明virtual_network_subnet_id

在azurerm_linux_function_app的site_config中显式指定virtual_network_subnet_id,与Swift连接资源使用同一个子网ID,让Terraform确认该属性是预期配置:

resource "azurerm_subnet" "this" {
  name                 = "name"
  resource_group_name  = azurerm_resource_group.rg.name
  virtual_network_name = azurerm_virtual_network.vnet.name
  address_prefixes     = ["10.0.5.128/26"]
  service_endpoints    = ["Microsoft.AzureCosmosDB"]
  delegation {
    name = "name-delegation"

    service_delegation {
      name    = "Microsoft.Web/serverFarms"
      actions = ["Microsoft.Network/virtualNetworks/subnets/action"]
    }
  }
}

resource "azurerm_linux_function_app" "this" {
  name                       = "name"
  resource_group_name        = azurerm_resource_group.rg.name
  location                   = azurerm_resource_group.rg.location
  storage_account_name       = azurerm_storage_account.this.name
  storage_account_access_key = azurerm_storage_account.this.primary_access_key
  service_plan_id            = azurerm_service_plan.this.id
  https_only                 = true
  site_config {
    vnet_route_all_enabled = true
    # 显式添加子网ID,与Swift连接资源保持一致
    virtual_network_subnet_id = azurerm_subnet.this.id
    cors {
      allowed_origins = ["https://portal.azure.com"]
    }
    application_stack {
      node_version = "18"
    }
  }
  app_settings = {
  }
  depends_on = [azurerm_cosmosdb_account.db]
}

resource "azurerm_app_service_virtual_network_swift_connection" "this" {
  app_service_id = azurerm_linux_function_app.this.id
  subnet_id      = azurerm_subnet.this.id
}

方案2:忽略virtual_network_subnet_id的变更

如果不想在Function App配置中显式声明子网ID,可以通过lifecycle块让Terraform忽略site_config中virtual_network_subnet_id的变化,避免误判为需要移除的配置:

resource "azurerm_subnet" "this" {
  name                 = "name"
  resource_group_name  = azurerm_resource_group.rg.name
  virtual_network_name = azurerm_virtual_network.vnet.name
  address_prefixes     = ["10.0.5.128/26"]
  service_endpoints    = ["Microsoft.AzureCosmosDB"]
  delegation {
    name = "name-delegation"

    service_delegation {
      name    = "Microsoft.Web/serverFarms"
      actions = ["Microsoft.Network/virtualNetworks/subnets/action"]
    }
  }
}

resource "azurerm_linux_function_app" "this" {
  name                       = "name"
  resource_group_name        = azurerm_resource_group.rg.name
  location                   = azurerm_resource_group.rg.location
  storage_account_name       = azurerm_storage_account.this.name
  storage_account_access_key = azurerm_storage_account.this.primary_access_key
  service_plan_id            = azurerm_service_plan.this.id
  https_only                 = true
  site_config {
    vnet_route_all_enabled = true
    cors {
      allowed_origins = ["https://portal.azure.com"]
    }
    application_stack {
      node_version = "18"
    }
  }
  app_settings = {
  }
  depends_on = [azurerm_cosmosdb_account.db]

  # 忽略自动添加的virtual_network_subnet_id属性变更
  lifecycle {
    ignore_changes = [
      site_config[0].virtual_network_subnet_id
    ]
  }
}

resource "azurerm_app_service_virtual_network_swift_connection" "this" {
  app_service_id = azurerm_linux_function_app.this.id
  subnet_id      = azurerm_subnet.this.id
}

验证修改

应用上述任一方案后,运行terraform apply,后续执行terraform plan时将不再出现循环变更提示,VNet集成状态会保持稳定。

内容的提问来源于stack exchange,提问作者Bonen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 00:07:43