You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从虚拟机内连接Azure App Configuration并读取配置?

问题排查:Linux虚拟机中Java应用连接Azure App Configuration卡住的解决方法

以下是针对你遇到的问题需要检查的额外配置点及排查步骤:

一、网络连通性验证

Linux虚拟机必须能访问两个关键地址:Azure App Configuration的终端点和Azure AD登录地址(https://login.microsoftonline.com)。在虚拟机终端执行以下命令测试:

# 替换为你的App Configuration实例端点
curl -I https://<你的AppConfig实例名>.azconfig.io
# 测试Azure AD登录地址
curl -I https://login.microsoftonline.com

如果请求失败:

  • 若虚拟机在Azure虚拟网络内,确认是否配置了Azure App Configuration服务端点,或虚拟网络出站规则是否允许443端口的HTTPS请求。
  • 若为本地虚拟机,检查防火墙、企业代理是否拦截了上述地址的流量。

二、环境变量正确性检查

确保运行Java程序时,所需环境变量已正确设置且生效:

# 打印变量值验证
echo $AZURE_TENANT_ID $AZURE_CLIENT_ID $APP_CONFIGURATION_CONNECTION_STRING

注意:临时设置的环境变量仅在当前终端会话生效,若需永久生效可写入~/.bashrc或~/.profile文件,执行source ~/.bashrc刷新后再运行程序。

三、服务主体权限确认

再次验证服务主体的App Configuration Data Reader角色是直接分配到目标App Configuration实例上(而非仅继承自资源组/订阅),可在Azure门户的App Configuration「访问控制(IAM)」页面查看角色分配记录。

四、Java SDK依赖与版本检查

确保使用的Azure SDK版本兼容且依赖完整,以Maven为例,需包含以下核心依赖(使用最新稳定版):

<dependency>
    <groupId>com.azure</groupId>
    <artifactId>azure-data-appconfiguration</artifactId>
    <version>1.5.0</version>
</dependency>
<dependency>
    <groupId>com.azure</groupId>
    <artifactId>azure-identity</artifactId>
    <version>1.12.0</version>
</dependency>

五、添加超时与日志排查

修改代码添加超时配置和异常日志,定位卡住的具体原因:

import com.azure.core.http.HttpClient;
import com.azure.core.http.policy.RetryPolicy;
import com.azure.data.appconfiguration.ConfigurationClient;
import com.azure.data.appconfiguration.ConfigurationClientBuilder;
import com.azure.identity.ClientSecretCredentialBuilder;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import java.time.Duration;

public class ConfigTest {
    private static final Logger logger = LoggerFactory.getLogger(ConfigTest.class);

    public static void main(String[] args) {
        var servicePrincipal = new ClientSecretCredentialBuilder()
                .authorityHost("https://login.microsoftonline.com")
                .tenantId(System.getenv("AZURE_TENANT_ID"))
                .clientId(System.getenv("AZURE_CLIENT_ID"))
                .clientSecret(System.getenv("AZURE_CLIENT_SECRET"))
                .build();

        String appConfigEndpoint = System.getenv("APP_CONFIGURATION_CONNECTION_STRING");

        ConfigurationClient configurationClient = new ConfigurationClientBuilder()
                .credential(servicePrincipal)
                .endpoint(appConfigEndpoint)
                .httpClient(HttpClient.createDefault())
                .retryPolicy(new RetryPolicy())
                .connectionTimeout(Duration.ofSeconds(10))
                .buildClient();

        try {
            String config1 = configurationClient.getConfigurationSetting("config1", System.getenv("ENV")).getValue();
            logger.info("读取配置成功:{}", config1);
        } catch (Exception e) {
            logger.error("读取配置失败", e);
            e.printStackTrace();
        }
    }
}

运行时添加JVM参数开启调试日志:

java -Dorg.slf4j.simpleLogger.defaultLogLevel=debug com.package.ConfigTest

通过日志可查看是否存在认证失败、连接超时等具体错误。

六、代理配置(若虚拟机需通过代理访问外网)

如果虚拟机依赖代理访问互联网,需在运行时添加代理参数:

java -Dhttp.proxyHost=proxy.example.com -Dhttp.proxyPort=8080 -Dhttps.proxyHost=proxy.example.com -Dhttps.proxyPort=8080 com.package.ConfigTest

或在代码中配置HttpClient代理:

import com.azure.core.http.ProxyOptions;
import java.net.InetSocketAddress;

// 省略其他代码
ProxyOptions proxyOptions = new ProxyOptions(ProxyOptions.Type.HTTP, new InetSocketAddress("proxy.example.com", 8080));
HttpClient httpClient = HttpClient.createDefault().proxy(proxyOptions);

ConfigurationClient configurationClient = new ConfigurationClientBuilder()
        .credential(servicePrincipal)
        .endpoint(appConfigEndpoint)
        .httpClient(httpClient)
        .buildClient();

内容的提问来源于stack exchange,提问作者AJ31

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 14:27:57