Azure Policy使用existenceCondition检测多告警资源存在性问题求助
Azure Policy:Application Gateway缺失Metric Alerts时自动重建的问题修复
问题描述
我尝试配置Azure Policy,当Application Gateway缺少指定的三个metricAlerts告警规则(FailedRequests、Throughput、UnhealthyHostCount)时自动创建这些规则。采用deployIfNotExists效果并在existenceCondition中使用anyOf逻辑,但未达预期:删除单个告警规则后不会触发重建,且误将不合规资源标记为合规。
问题根源
当前Policy的existenceCondition使用anyOf逻辑,意味着只要三个告警中的任意一个存在,Azure Policy就会判定Application Gateway资源合规,不会执行部署操作。这就导致即使缺失1-2个告警规则,Policy也不会触发修复部署,同时错误地将资源标记为合规。
解决方案
要实现“所有三个告警规则必须存在才合规,缺失任意一个就触发部署”的需求,最可靠的方式是拆分三个独立的deployIfNotExists Policy,每个Policy对应一个告警规则。这样每个Policy单独检查对应告警是否存在,缺失时自动创建。
单个告警规则的Policy示例(以FailedRequests为例)
{ "mode": "All", "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Network/applicationGateways" }, { "field": "tags.nomonitor", "exists": false } ] }, "then": { "effect": "deployIfNotExists", "details": { "type": "microsoft.insights/metricAlerts", "resourceGroupName": "[resourceGroup().name]", "existenceCondition": { "field": "name", "equals": "[concat('alert_appgw_failedrequests_', field('Name'))]" }, "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c" ], "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "appgateway_name": { "type": "String" }, "location": { "type": "String" } }, "resources": [ { "type": "microsoft.insights/metricAlerts", "apiVersion": "2018-03-01", "name": "[concat('alert_appgw_failedrequests_', parameters('appgateway_name'))]", "location": "global", "properties": { "description": "Platform alerts - FailedRequests", "severity": 2, "enabled": true, "scopes": [ "[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Network/applicationGateways/', parameters('appgateway_name'))]" ], "evaluationFrequency": "PT15M", "windowSize": "PT15M", "criteria": { "allOf": [ { "threshold": 10, "name": "Metric1", "metricNamespace": "Microsoft.Network/applicationGateways", "metricName": "FailedRequests", "operator": "GreaterThanOrEqual", "timeAggregation": "Total", "criterionType": "StaticThresholdCriterion" } ], "odata.type": "Microsoft.Azure.Monitor.SingleResourceMultipleMetricCriteria" }, "autoMitigate": true, "targetResourceType": "Microsoft.Network/applicationGateways", "targetResourceRegion": "[parameters('location')]", "actions": [ { "actionGroupId": "/subscriptions/ec23feef-629f-481d-b69e-a5d7faa5cb26/resourceGroups/DefaultResourceGroup-WUS2/providers/microsoft.insights/actionGroups/ALERT-DL", "webHookProperties": {} } ] } } ] }, "parameters": { "appgateway_name": { "value": "[field('Name')]" }, "location": { "value": "[field('Location')]" } } } } } } }, "parameters": {} }
扩展说明
- 重复上述结构,分别创建针对
alert_appgw_throughput_<appgw-name>和alert_appgw_unhealthyhost_<appgw-name>的Policy,修改对应的metricName、阈值等配置即可。 - 每个Policy独立检查单个告警规则的存在性,当对应告警缺失时,会自动触发部署创建该规则,彻底解决原逻辑中“只要有一个存在就判定合规”的问题。
内容的提问来源于stack exchange,提问作者Murali
相关产品推荐
相关产品推荐

