在App Service Environment v3中创建的App Service访问失败求助
使用Terraform创建的ASEv3中App Service访问报错排查
问题描述
我使用Terraform创建了App Service Environment Version 3(ASEv3)及配套的App Service,配置代码如下。随后通过Visual Studio将一个示例应用部署到该App Service,但访问App Service门户时出现错误(错误截图:
)。本地运行该应用一切正常,不清楚是App Service配置哪里出现问题,寻求帮助。
Terraform配置代码
resource "azurerm_app_service_environment_v3" "example" { name = "example-asev3" resource_group_name = azurerm_resource_group.example.name subnet_id = azurerm_subnet.example.id internal_load_balancing_mode = "Web, Publishing" cluster_setting { name = "DisableTls1.0" value = "1" } cluster_setting { name = "InternalEncryption" value = "true" } cluster_setting { name = "FrontEndSSLCipherSuiteOrder" value = "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" } tags = { env = "production" terraformed = "true" } } resource "azurerm_service_plan" "example" { name = "example" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location os_type = "Linux" sku_name = "I1v2" app_service_environment_id = azurerm_app_service_environment_v3.example.id } resource "azurerm_application_insights" "example" { name = "tf-test-appinsights" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name application_type = "web" } resource "azurerm_app_service" "example" { name = "example-app-service" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name app_service_plan_id = azurerm_app_service_plan.example.id site_config { linux_fx_version = "DOTNETCORE:6.0" always_on = true } }
排查及解决建议
- 网络访问限制:你的ASEv3配置了
internal_load_balancing_mode = "Web, Publishing",属于内部ASE,仅允许虚拟网络内或通过VPN/Express Route接入的设备访问。如果你的客户端不在该网络环境,直接访问会失败。若需公网访问,将该参数改为"None";若保留内部ASE,需确保访问设备处于对应虚拟网络内,或配置私有DNS、VPN连接。 - 应用与配置匹配性:确认部署的应用运行时确实为.NET Core 6.0,与
linux_fx_version = "DOTNETCORE:6.0"一致。同时查看App Service的日志流或诊断日志,排查是否存在启动依赖缺失、端口配置错误等问题。 - SSL套件兼容性:你自定义了SSL套件,若浏览器不支持配置的
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256套件,会导致连接失败。可临时注释FrontEndSSLCipherSuiteOrder配置,重新部署ASEv3后测试。 - 资源状态验证:检查Azure门户中ASEv3和服务计划的状态是否为运行中,确认服务计划已成功关联到ASEv3。
内容的提问来源于stack exchange,提问作者Asterix
相关产品推荐
相关产品推荐

