You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署Azure应用网关时遇InternalServerError求助

问题

尝试通过Terraform在Azure现有资源组中部署WAF_v2层级的Application Gateway,后端对接已存在的API Management,部署耗时近20分钟后报错:

Error: waiting for create of Application Gateway: (Name "myAppGateway" / Resource Group "csj-hub-euw-chb-rg"): Code="InternalServerError" Message="An error occurred." Details=[]

现有环境信息:

  • 目标资源组、承载应用网关的VNET(地址空间10.22.0.0/21)、后端API Management均已存在
  • 应用网关所在VNET-A与API Management所在VNET-B已配置虚拟网络对等连接
  • 若新建资源组和VNET部署则无此错误,但业务要求必须使用现有资源组和VNET

相关Terraform配置代码:

module "agw_subnet" {
  source = "../modules/resources-blocks/subnet"

  subnet_name             = "agw_subnet"
  resource_group_name     = module.resource_group.name
  vnet_name               = module.vnet.name
  subnet_address_prefixes = ["10.22.1.0/24"]
}

resource "azurerm_web_application_firewall_policy" "exampleWAF" {
  name                = "example_wafpolicy_name"
  resource_group_name = module.resource_group.name
  location            = module.resource_group.location

  custom_rules {
    name      = "Rule1"
    priority  = 1
    rule_type = "MatchRule"

    match_conditions {
      match_variables {
        variable_name = "RemoteAddr"
      }

      operator           = "IPMatch"
      negation_condition = true
      match_values       = ["x.x.x.x"]
    }

    action = "Block"
  }

  policy_settings {
    enabled                     = true
    mode                        = "Prevention"
    request_body_check          = true
    file_upload_limit_in_mb     = 100
    max_request_body_size_in_kb = 128
  }

  managed_rules {
    managed_rule_set {
      type    = "OWASP"
      version = "3.2"
    }
  }
}

resource "azurerm_application_gateway" "app_gw" {
  name                = "myAppGateway"
  resource_group_name = module.resource_group.name
  location            = module.resource_group.location

  sku {
    name     = "WAF_v2"
    tier     = "WAF_v2"
    capacity = 2
  }

  gateway_ip_configuration {
    name      = "my-gateway-ip-configuration"
    subnet_id = module.agw_subnet.id
  }

  frontend_port {
    name = var.frontend_port_name
    port = 80
  }

  frontend_ip_configuration {
    name                 = var.frontend_ip_configuration_name
    public_ip_address_id = module.app_gw_pip.id
  }

  backend_address_pool {
    name = "devBackend"
    ip_addresses = ["10.22.40.19"] 
  }

  backend_http_settings {
    name                  = "devHttpSetting"
    cookie_based_affinity = "Disabled"
    port                  = 80
    protocol              = "Http"
    request_timeout       = 20
    host_name             = "xxxx.be"
    probe_name            = "apim-probe"
  }

  probe {
    interval                                  = 30
    name                                      = "apim-probe"
    path                                      = "/status-0123456789abcdef"
    protocol                                  = "Http"
    timeout                                   = 30
    unhealthy_threshold                       = 3
    pick_host_name_from_backend_http_settings = true
    match {
      body = ""
      status_code = [
        "200-399"
      ]
    }
  }

  http_listener {
    name                           = "devListener"
    frontend_ip_configuration_name = var.frontend_ip_configuration_name
    frontend_port_name             = var.frontend_port_name
    protocol                       = "Http"
    host_name                      = "xxxx.be"
    firewall_policy_id             =  azurerm_web_application_firewall_policy.exampleWAF.id
  }

  request_routing_rule {
    name                       = "devRule"
    rule_type                  = "Basic"
    priority                   = 25
    http_listener_name         = "devListener"
    backend_address_pool_name  = "devBackend"
    backend_http_settings_name = "devHttpSetting"
  }


  firewall_policy_id = var.firewall_policy_id ==""?null : var.firewall_policy_id

  dynamic "waf_configuration"  {
    for_each =  var.waf_configuration
      content{
            enabled                  = lookup(waf_configuration.value,"enabled",true)
            file_upload_limit_mb     = lookup(waf_configuration.value,"file_upload_limit_mb",30)
            firewall_mode            = lookup(waf_configuration.value,"firewall_mode","Prevention")
            max_request_body_size_kb = lookup(waf_configuration.value,"max_request_body_size_kb",128)
            request_body_check       = lookup(waf_configuration.value,"request_body_check",true)
            rule_set_type            = lookup(waf_configuration.value,"rule_set_type","OWASP")
            rule_set_version         = lookup(waf_configuration.value,"rule_set_version", "3.1")
      }
  }
}

排查与解决方案

1. 修复WAF配置冲突

当前配置同时存在独立WAF策略资源和应用网关内置的waf_configuration动态块,这会引发配置冲突,是InternalServerError的常见诱因:

  • 移除应用网关中的firewall_policy_id赋值和dynamic "waf_configuration"块,已通过http_listener关联独立WAF策略,无需重复配置
  • 确保WAF策略的规则集版本(OWASP 3.2)与原内置配置无冲突,保持策略一致性

修改后的应用网关核心片段:

resource "azurerm_application_gateway" "app_gw" {
  name                = "myAppGateway"
  resource_group_name = module.resource_group.name
  location            = module.resource_group.location

  sku {
    name     = "WAF_v2"
    tier     = "WAF_v2"
    capacity = 2
  }

  # 网关IP、前端端口、后端池等原有配置保持不变

  http_listener {
    name                           = "devListener"
    frontend_ip_configuration_name = var.frontend_ip_configuration_name
    frontend_port_name             = var.frontend_port_name
    protocol                       = "Http"
    host_name                      = "xxxx.be"
    firewall_policy_id             = azurerm_web_application_firewall_policy.exampleWAF.id
  }

  # 移除以下冲突配置:
  # firewall_policy_id = var.firewall_policy_id ==""?null : var.firewall_policy_id
  # dynamic "waf_configuration" {...}
}

2. 检查现有VNET与资源组状态

  • 确认应用网关子网10.22.1.0/24未被其他资源占用,且子网内有至少8个可用IP(WAF_v2的最低要求)
  • 验证VNET-A与VNET-B的对等连接状态为已连接,无单向路由限制
  • 排查资源组内是否存在同名或残留的应用网关资源,可通过命令az network application-gateway list -g csj-hub-euw-chb-rg确认

3. 调整Terraform部署逻辑

  • 增加显式依赖声明,确保WAF策略完全创建后再部署应用网关:
    resource "azurerm_application_gateway" "app_gw" {
      # 其他配置
      depends_on = [azurerm_web_application_firewall_policy.exampleWAF]
    }
    
  • 使用terraform apply -parallelism=1降低并行部署压力,避免现有资源组内的资源竞争

4. 排查Azure平台侧问题

  • 查看资源组的Azure活动日志,筛选应用网关创建事件,获取更详细的错误细节(InternalServerError通常会在活动日志中包含具体子错误)
  • 若日志无有效信息,可尝试更换应用网关名称(避免名称残留问题),或临时将SKU容量提升至3后再部署,测试是否为资源配额问题

内容的提问来源于stack exchange,提问作者Gregory

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 22:11:02