You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Policy使用existenceCondition检测多告警资源存在性问题求助

Azure Policy:Application Gateway缺失Metric Alerts时自动重建的问题修复

问题描述

我尝试配置Azure Policy,当Application Gateway缺少指定的三个metricAlerts告警规则(FailedRequests、Throughput、UnhealthyHostCount)时自动创建这些规则。采用deployIfNotExists效果并在existenceCondition中使用anyOf逻辑,但未达预期:删除单个告警规则后不会触发重建,且误将不合规资源标记为合规。

问题根源

当前Policy的existenceCondition使用anyOf逻辑,意味着只要三个告警中的任意一个存在,Azure Policy就会判定Application Gateway资源合规,不会执行部署操作。这就导致即使缺失1-2个告警规则,Policy也不会触发修复部署,同时错误地将资源标记为合规。

解决方案

要实现“所有三个告警规则必须存在才合规,缺失任意一个就触发部署”的需求,最可靠的方式是拆分三个独立的deployIfNotExists Policy,每个Policy对应一个告警规则。这样每个Policy单独检查对应告警是否存在,缺失时自动创建。

单个告警规则的Policy示例(以FailedRequests为例)

{
  "mode": "All",
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Network/applicationGateways"
        },
        {
          "field": "tags.nomonitor",
          "exists": false
        }
      ]
    },
    "then": {
      "effect": "deployIfNotExists",
      "details": {
        "type": "microsoft.insights/metricAlerts",
        "resourceGroupName": "[resourceGroup().name]",
        "existenceCondition": {
          "field": "name",
          "equals": "[concat('alert_appgw_failedrequests_', field('Name'))]"
        },
        "roleDefinitionIds": [
          "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c"
        ],
        "deployment": {
          "properties": {
            "mode": "incremental",
            "template": {
              "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
              "contentVersion": "1.0.0.0",
              "parameters": {
                "appgateway_name": {
                  "type": "String"
                },
                "location": {
                  "type": "String"
                }
              },
              "resources": [
                {
                  "type": "microsoft.insights/metricAlerts",
                  "apiVersion": "2018-03-01",
                  "name": "[concat('alert_appgw_failedrequests_', parameters('appgateway_name'))]",
                  "location": "global",
                  "properties": {
                    "description": "Platform alerts - FailedRequests",
                    "severity": 2,
                    "enabled": true,
                    "scopes": [
                      "[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Network/applicationGateways/', parameters('appgateway_name'))]"
                    ],
                    "evaluationFrequency": "PT15M",
                    "windowSize": "PT15M",
                    "criteria": {
                      "allOf": [
                        {
                          "threshold": 10,
                          "name": "Metric1",
                          "metricNamespace": "Microsoft.Network/applicationGateways",
                          "metricName": "FailedRequests",
                          "operator": "GreaterThanOrEqual",
                          "timeAggregation": "Total",
                          "criterionType": "StaticThresholdCriterion"
                        }
                      ],
                      "odata.type": "Microsoft.Azure.Monitor.SingleResourceMultipleMetricCriteria"
                    },
                    "autoMitigate": true,
                    "targetResourceType": "Microsoft.Network/applicationGateways",
                    "targetResourceRegion": "[parameters('location')]",
                    "actions": [
                      {
                        "actionGroupId": "/subscriptions/ec23feef-629f-481d-b69e-a5d7faa5cb26/resourceGroups/DefaultResourceGroup-WUS2/providers/microsoft.insights/actionGroups/ALERT-DL",
                        "webHookProperties": {}
                      }
                    ]
                  }
                }
              ]
            },
            "parameters": {
              "appgateway_name": {
                "value": "[field('Name')]"
              },
              "location": {
                "value": "[field('Location')]"
              }
            }
          }
        }
      }
    }
  },
  "parameters": {}
}

扩展说明

  • 重复上述结构,分别创建针对alert_appgw_throughput_<appgw-name>和alert_appgw_unhealthyhost_<appgw-name>的Policy,修改对应的metricName、阈值等配置即可。
  • 每个Policy独立检查单个告警规则的存在性,当对应告警缺失时,会自动触发部署创建该规则,彻底解决原逻辑中“只要有一个存在就判定合规”的问题。

内容的提问来源于stack exchange,提问作者Murali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 21:15:37