You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

带访问限制与vNet集成的Azure Function App部署异常求助

从Azure DevOps部署至带VNet集成的Function App异常排查

当前环境配置

  • 访问限制:Function App已将AzureDevOps服务标签加入入站白名单
  • VNet集成:Function App开启出站VNet集成,绑定的存储账户仅允许该集成VNet访问
  • 子网配置:集成子网已启用Storage服务端点
  • NSG规则:子网NSG入站允许AzureDevOps服务标签,出站允许Storage服务标签

部署流程与日志

通过Azure DevOps构建流水线生成Function App的zip工件,再通过发布流水线部署。部署任务日志显示成功:

2023-04-13T14:02:07.5017872Z ##[section]Starting: Azure Function App Deploy: FA-TST-xxx
2023-04-13T14:02:07.5148220Z ==============================================================================
2023-04-13T14:02:07.5148398Z Task         : Azure Functions Deploy
2023-04-13T14:02:07.5148471Z Description  : Update a function app with .NET, Python, JavaScript, PowerShell, Java based web applications
2023-04-13T14:02:07.5148597Z Version      : 2.219.0
2023-04-13T14:02:07.5148656Z Author       : Microsoft Corporation
2023-04-13T14:02:07.5148738Z Help         : https://aka.ms/azurefunctiontroubleshooting
2023-04-13T14:02:07.5148818Z ==============================================================================
2023-04-13T14:02:09.8559391Z Got service connection details for Azure App Service:'FA-TST-xxx'
2023-04-13T14:02:43.1629721Z (node:1428) [DEP0005] DeprecationWarning: Buffer() is deprecated due to security and usability issues. Please use the Buffer.alloc(), Buffer.allocUnsafe(), or Buffer.from() methods instead.
2023-04-13T14:02:45.4392949Z NOTE: Function app is VNet integrated.
2023-04-13T14:02:50.5646873Z Trying to update App Service Application settings. Data: {"WEBSITE_RUN_FROM_PACKAGE":"1"}
2023-04-13T14:02:50.5647155Z Deleting App Service Application settings. Data: ["WEBSITE_RUN_FROM_ZIP"]
2023-04-13T14:02:50.5647620Z App Service Application settings are already present.
2023-04-13T14:02:51.8678122Z Validating deployment package for functions app before Zip Deploy
2023-04-13T14:02:52.4037017Z Package deployment using ZIP Deploy initiated.
2023-04-13T14:03:20.6923999Z Deploy logs can be viewed at https://fa-tst-xxx.scm.azurewebsites.net/api/deployments/4bc45377e91c44ca2e18c4451549c1e5/log
2023-04-13T14:03:20.6924440Z The web package has been deployed to App Service. Please note that the package mount or extraction errors will be logged in the deployment logs in the location above.
2023-04-13T14:03:20.6924780Z NOTE: Run From Package makes wwwroot read-only, so you will receive an error when writing files to this directory.
2023-04-13T14:03:24.2067507Z Successfully added release annotation to the Application Insight : AI-TST-xxx
2023-04-13T14:03:24.6058941Z App Service Application URL: https://fa-tst-xxx.azurewebsites.net
2023-04-13T14:03:24.6219120Z ##[section]Finishing: Azure Function App Deploy: FA-TST-xxx

Function App的部署详情日志同样显示成功:

[{"log_time":"2023-04-13T14:02:54.4683117Z","id":"1b1ed1bc-12c6-493f-be3f-3f0a1659c4e0","message":"Updating submodules.","type":0,"details_url":null},{"log_time":"2023-04-13T14:02:54.5776418Z","id":"7e37471f-2272-4c07-b5e7-4ea17b4a8a4f","message":"Preparing deployment for commit id '4ec45877c9'.","type":0,"details_url":null},{"log_time":"2023-04-13T14:02:54.827664Z","id":"2a19b2f9-0223-4a13-aa8a-618790ced6e4","message":"Skipping build. Project type: Run-From-Zip","type":0,"details_url":null},{"log_time":"2023-04-13T14:02:54.9214344Z","id":"fa294e85-d78b-4f63-8de9-1ce1f1ee50ec","message":"Skipping post build. Project type: Run-From-Zip","type":0,"details_url":null},{"log_time":"2023-04-13T14:02:55.01516Z","id":"6118ea98-86be-4323-beb3-b9e5bd0fcc5f","message":"Triggering recycle (preview mode disabled).","type":0,"details_url":null},{"log_time":"2023-04-13T14:02:55.1558172Z","id":"16064a20-a8e2-4239-bbb3-3bd955624757","message":"Deployment successful.","type":0,"details_url":null}]

异常现象

  • 部署日志均显示成功,但Azure门户中Function App的函数列表无任何变更
  • 关闭VNet集成并允许存储账户公网访问后,部署可正常生效,门户能看到更新后的函数
  • 尝试为存储账户所在子网添加多条入站NSG规则(AzureResourceManager、AzureDevOps、AppService、AppServiceManagement服务标签),问题依旧

排查思路

  1. 检查存储账户的VNet访问规则:确认存储账户的防火墙规则中,是否包含Function App集成子网的完整CIDR范围,而非仅依赖服务端点。服务端点仅保证流量走VNet,但仍需存储账户明确允许该子网访问
  2. 验证Run-From-Package的存储路径:当Function App启用WEBSITE_RUN_FROM_PACKAGE时,包文件实际存储在绑定的存储账户中。需确认Function App是否能通过VNet正常访问存储账户中的包文件,可通过Kudu站点查看包的挂载状态
  3. 检查NSG的出站规则优先级:确保允许Storage服务标签的出站规则优先级高于默认拒绝规则,且规则覆盖存储账户所在区域的Storage服务
  4. 确认VNet集成的子网配置:检查集成子网是否未被其他资源占用,且子网的Microsoft.Web/serverFarms服务端点已启用(仅针对VNet集成的子网,而非存储账户的子网)
  5. 查看Function App的启动日志:在Kudu的LogFiles\Application\Functions\Host路径下查看主机启动日志,确认是否存在无法读取存储账户中函数元数据的错误
  6. 排查部署机制的流量路径:Zip Deploy的流量是通过SCM站点(*.scm.azurewebsites.net)传输的,需确认SCM站点的访问限制是否也配置了AzureDevOps服务标签的白名单,且SCM站点是否继承了Function App的VNet集成配置(部分场景下SCM可能未启用VNet集成,导致部署后无法同步元数据到存储账户)

内容的提问来源于stack exchange,提问作者ABF

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 10:22:05