Azure Bicep跨资源组调用Container Registry报ParentResourceNotFound
跨资源组共享Azure容器注册表(ACR)的Bicep部署问题
问题描述
我通过Bicep部署Azure基础设施,设置两个资源组:一个存放共享资源(App Service计划、Container Registry),另一个存放项目专属资源(应用对应的App Service)。尝试通过linuxFxVersion关联跨资源组的Container Registry时遇到问题:
- 使用
shared.bicep输出的containerRegistryName时,触发ParentResourceNotFound错误,提示“无法对嵌套资源执行请求操作。父资源'crdevopstest'未找到”; - 当Container Registry与App Service处于同一资源组时,使用
acrResource.name可正常工作。
相关Bicep代码
main.bicep
resource rg 'Microsoft.Resources/resourceGroups@2021-04-01' = { name: 'rg-${projectName}-${env}' location: resourceLocation } resource rgShared 'Microsoft.Resources/resourceGroups@2021-04-01' = if (env != 'dev') { name: 'rg-${subscription}-${env}' location: resourceLocation } module appServiceShared 'shared.bicep' = if (env != 'dev') { name:'appShared' scope: rgShared params: { subscription: subscription env: env appServicePlanSku: appServicePlanSku crSku: crSku } } module appService 'app.bicep' = { name: 'app${projectName}' scope: rg params: { applicationName: projectName env: env appServicePlanSharedId: appServiceShared.outputs.appServicePlanSharedLinuxId //appServicePlanSharedName: appServiceShared.outputs.appServicePlanSharedLinuxName containerRegistryName: appServiceShared.outputs.containerRegistryName } }
shared.bicep
resource appServicePlanSharedWindows 'Microsoft.Web/serverfarms@2021-01-15' = { name: 'plan-${subscription}-${env}-windows' location: location sku: { name: appServicePlanSku } } resource appServicePlanSharedLinux 'Microsoft.Web/serverfarms@2021-01-15' = { name: 'plan-${subscription}-${env}-${appService}' location: location sku: { name: appServicePlanSku } kind: appService properties: { reserved: true } } resource acrResource 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = { name: 'cr${subscription}' location: location sku: { name: crSku } properties: { adminUserEnabled: true // TO DO - replace by identity } } output appServicePlanSharedWindowsId string = appServicePlanSharedWindows.id output appServicePlanSharedLinuxId string = appServicePlanSharedLinux.id //output appServicePlanSharedLinuxName string = appServicePlanSharedLinux.name output containerRegistryName string = acrResource.name
app.bicep
resource acrResource 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = { name: 'crdevopsnick' location: location sku: { name: 'Basic' } properties: { adminUserEnabled: true // TO DO - replace by identity } } resource appServiceApi 'Microsoft.Web/sites@2021-03-01' = { name: 'ase-${applicationName}-api-dotnet-${env}' location: location properties: { serverFarmId: appServicePlanSharedId httpsOnly: true siteConfig: { linuxFxVersion: 'DOCKER|${acrResource.name}.azurecr.io/${applicationName}service:latest' appSettings: [ { name: 'DOCKER_REGISTRY_SERVER_URL' value: 'https://mcr.microsoft.com' } { name: 'DOCKER_REGISTRY_SERVER_USERNAME' value: acrResource.name } { name: 'DOCKER_REGISTRY_SERVER_PASSWORD' value: listCredentials(resourceId('Microsoft.ContainerRegistry/registries', acrResource.name), '2021-06-01-preview').passwords[0].value //acrResource.listCredentials().passwords[0].value } { name: 'WEBSITES_PORT' value: '7122' } ] } } }
解答
完全可以从独立资源组中使用共享的Container Registry,你的问题出在app.bicep的两个关键错误上:
- 多余的本地ACR资源定义:你在
app.bicep中硬编码创建了crdevopsnick的ACR,但实际需要调用的是共享资源组中的ACR,这个本地定义会导致引用混乱。 - 跨资源组ACR引用方式错误:当ACR在其他资源组时,不能仅通过名称直接引用,需要通过
existing关键字结合资源组范围来关联目标ACR。
修正步骤
1. 修改app.bicep,引用共享资源组的ACR
param applicationName string param env string param appServicePlanSharedId string param containerRegistryName string param containerRegistryResourceGroup string // 引用共享资源组中的ACR,而非本地创建 resource acrResource 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' existing = { name: containerRegistryName scope: resourceGroup(containerRegistryResourceGroup) } resource appServiceApi 'Microsoft.Web/sites@2021-03-01' = { name: 'ase-${applicationName}-api-dotnet-${env}' location: location properties: { serverFarmId: appServicePlanSharedId httpsOnly: true siteConfig: { linuxFxVersion: 'DOCKER|${acrResource.name}.azurecr.io/${applicationName}service:latest' appSettings: [ { name: 'DOCKER_REGISTRY_SERVER_URL' value: 'https://${acrResource.name}.azurecr.io' // 修正为共享ACR的地址 } { name: 'DOCKER_REGISTRY_SERVER_USERNAME' value: acrResource.name } { name: 'DOCKER_REGISTRY_SERVER_PASSWORD' value: acrResource.listCredentials().passwords[0].value } { name: 'WEBSITES_PORT' value: '7122' } ] } } }
2. 更新main.bicep,传递共享资源组参数
module appService 'app.bicep' = { name: 'app${projectName}' scope: rg params: { applicationName: projectName env: env appServicePlanSharedId: appServiceShared.outputs.appServicePlanSharedLinuxId containerRegistryName: appServiceShared.outputs.containerRegistryName containerRegistryResourceGroup: rgShared.name // 传递共享资源组名称 } }
额外注意事项
- 确保部署账号对共享资源组的ACR拥有
Microsoft.ContainerRegistry/registries/listCredentials/action权限,否则无法获取凭据。 - 建议尽快替换ACR管理员账号为托管标识,提升资源访问安全性。
内容的提问来源于stack exchange,提问作者NiAu
相关产品推荐
相关产品推荐

