使用Terraform部署Azure应用网关时遇InternalServerError求助
问题
尝试通过Terraform在Azure现有资源组中部署WAF_v2层级的Application Gateway,后端对接已存在的API Management,部署耗时近20分钟后报错:
Error: waiting for create of Application Gateway: (Name "myAppGateway" / Resource Group "csj-hub-euw-chb-rg"): Code="InternalServerError" Message="An error occurred." Details=[]
现有环境信息:
- 目标资源组、承载应用网关的VNET(地址空间10.22.0.0/21)、后端API Management均已存在
- 应用网关所在VNET-A与API Management所在VNET-B已配置虚拟网络对等连接
- 若新建资源组和VNET部署则无此错误,但业务要求必须使用现有资源组和VNET
相关Terraform配置代码:
module "agw_subnet" { source = "../modules/resources-blocks/subnet" subnet_name = "agw_subnet" resource_group_name = module.resource_group.name vnet_name = module.vnet.name subnet_address_prefixes = ["10.22.1.0/24"] } resource "azurerm_web_application_firewall_policy" "exampleWAF" { name = "example_wafpolicy_name" resource_group_name = module.resource_group.name location = module.resource_group.location custom_rules { name = "Rule1" priority = 1 rule_type = "MatchRule" match_conditions { match_variables { variable_name = "RemoteAddr" } operator = "IPMatch" negation_condition = true match_values = ["x.x.x.x"] } action = "Block" } policy_settings { enabled = true mode = "Prevention" request_body_check = true file_upload_limit_in_mb = 100 max_request_body_size_in_kb = 128 } managed_rules { managed_rule_set { type = "OWASP" version = "3.2" } } } resource "azurerm_application_gateway" "app_gw" { name = "myAppGateway" resource_group_name = module.resource_group.name location = module.resource_group.location sku { name = "WAF_v2" tier = "WAF_v2" capacity = 2 } gateway_ip_configuration { name = "my-gateway-ip-configuration" subnet_id = module.agw_subnet.id } frontend_port { name = var.frontend_port_name port = 80 } frontend_ip_configuration { name = var.frontend_ip_configuration_name public_ip_address_id = module.app_gw_pip.id } backend_address_pool { name = "devBackend" ip_addresses = ["10.22.40.19"] } backend_http_settings { name = "devHttpSetting" cookie_based_affinity = "Disabled" port = 80 protocol = "Http" request_timeout = 20 host_name = "xxxx.be" probe_name = "apim-probe" } probe { interval = 30 name = "apim-probe" path = "/status-0123456789abcdef" protocol = "Http" timeout = 30 unhealthy_threshold = 3 pick_host_name_from_backend_http_settings = true match { body = "" status_code = [ "200-399" ] } } http_listener { name = "devListener" frontend_ip_configuration_name = var.frontend_ip_configuration_name frontend_port_name = var.frontend_port_name protocol = "Http" host_name = "xxxx.be" firewall_policy_id = azurerm_web_application_firewall_policy.exampleWAF.id } request_routing_rule { name = "devRule" rule_type = "Basic" priority = 25 http_listener_name = "devListener" backend_address_pool_name = "devBackend" backend_http_settings_name = "devHttpSetting" } firewall_policy_id = var.firewall_policy_id ==""?null : var.firewall_policy_id dynamic "waf_configuration" { for_each = var.waf_configuration content{ enabled = lookup(waf_configuration.value,"enabled",true) file_upload_limit_mb = lookup(waf_configuration.value,"file_upload_limit_mb",30) firewall_mode = lookup(waf_configuration.value,"firewall_mode","Prevention") max_request_body_size_kb = lookup(waf_configuration.value,"max_request_body_size_kb",128) request_body_check = lookup(waf_configuration.value,"request_body_check",true) rule_set_type = lookup(waf_configuration.value,"rule_set_type","OWASP") rule_set_version = lookup(waf_configuration.value,"rule_set_version", "3.1") } } }
排查与解决方案
1. 修复WAF配置冲突
当前配置同时存在独立WAF策略资源和应用网关内置的waf_configuration动态块,这会引发配置冲突,是InternalServerError的常见诱因:
- 移除应用网关中的
firewall_policy_id赋值和dynamic "waf_configuration"块,已通过http_listener关联独立WAF策略,无需重复配置 - 确保WAF策略的规则集版本(OWASP 3.2)与原内置配置无冲突,保持策略一致性
修改后的应用网关核心片段:
resource "azurerm_application_gateway" "app_gw" { name = "myAppGateway" resource_group_name = module.resource_group.name location = module.resource_group.location sku { name = "WAF_v2" tier = "WAF_v2" capacity = 2 } # 网关IP、前端端口、后端池等原有配置保持不变 http_listener { name = "devListener" frontend_ip_configuration_name = var.frontend_ip_configuration_name frontend_port_name = var.frontend_port_name protocol = "Http" host_name = "xxxx.be" firewall_policy_id = azurerm_web_application_firewall_policy.exampleWAF.id } # 移除以下冲突配置: # firewall_policy_id = var.firewall_policy_id ==""?null : var.firewall_policy_id # dynamic "waf_configuration" {...} }
2. 检查现有VNET与资源组状态
- 确认应用网关子网
10.22.1.0/24未被其他资源占用,且子网内有至少8个可用IP(WAF_v2的最低要求) - 验证VNET-A与VNET-B的对等连接状态为已连接,无单向路由限制
- 排查资源组内是否存在同名或残留的应用网关资源,可通过命令
az network application-gateway list -g csj-hub-euw-chb-rg确认
3. 调整Terraform部署逻辑
- 增加显式依赖声明,确保WAF策略完全创建后再部署应用网关:
resource "azurerm_application_gateway" "app_gw" { # 其他配置 depends_on = [azurerm_web_application_firewall_policy.exampleWAF] } - 使用
terraform apply -parallelism=1降低并行部署压力,避免现有资源组内的资源竞争
4. 排查Azure平台侧问题
- 查看资源组的Azure活动日志,筛选应用网关创建事件,获取更详细的错误细节(InternalServerError通常会在活动日志中包含具体子错误)
- 若日志无有效信息,可尝试更换应用网关名称(避免名称残留问题),或临时将SKU容量提升至3后再部署,测试是否为资源配额问题
内容的提问来源于stack exchange,提问作者Gregory
相关产品推荐
相关产品推荐

