You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Bicep跨资源组调用Container Registry报ParentResourceNotFound

跨资源组共享Azure容器注册表(ACR)的Bicep部署问题

问题描述

我通过Bicep部署Azure基础设施,设置两个资源组:一个存放共享资源(App Service计划、Container Registry),另一个存放项目专属资源(应用对应的App Service)。尝试通过linuxFxVersion关联跨资源组的Container Registry时遇到问题:

  • 使用shared.bicep输出的containerRegistryName时,触发ParentResourceNotFound错误,提示“无法对嵌套资源执行请求操作。父资源'crdevopstest'未找到”;
  • 当Container Registry与App Service处于同一资源组时,使用acrResource.name可正常工作。

相关Bicep代码

main.bicep

resource rg 'Microsoft.Resources/resourceGroups@2021-04-01' = {
  name: 'rg-${projectName}-${env}'
  location: resourceLocation
}

resource rgShared 'Microsoft.Resources/resourceGroups@2021-04-01' = if (env != 'dev') {
  name: 'rg-${subscription}-${env}'
  location: resourceLocation
}

module appServiceShared 'shared.bicep' = if (env != 'dev') {
  name:'appShared'
  scope: rgShared
  params: {
    subscription: subscription
    env: env
    appServicePlanSku: appServicePlanSku
    crSku: crSku
  }
}

module appService 'app.bicep' = {
  name: 'app${projectName}'
  scope: rg
  params: {
    applicationName: projectName
    env: env
    appServicePlanSharedId: appServiceShared.outputs.appServicePlanSharedLinuxId
    //appServicePlanSharedName: appServiceShared.outputs.appServicePlanSharedLinuxName
    containerRegistryName: appServiceShared.outputs.containerRegistryName
  }
}

shared.bicep

resource appServicePlanSharedWindows 'Microsoft.Web/serverfarms@2021-01-15' = {
  name: 'plan-${subscription}-${env}-windows'
  location: location
  sku: {
    name: appServicePlanSku
  }
}

resource appServicePlanSharedLinux 'Microsoft.Web/serverfarms@2021-01-15' = {
  name: 'plan-${subscription}-${env}-${appService}'
  location: location
  sku: {
    name: appServicePlanSku
  }
  kind: appService
  properties: {
    reserved: true
  }
}

resource acrResource 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {
  name: 'cr${subscription}'
  location: location
  sku: {
    name: crSku
  }
  properties: {
    adminUserEnabled: true        // TO DO - replace by identity
  }
}

output appServicePlanSharedWindowsId string = appServicePlanSharedWindows.id
output appServicePlanSharedLinuxId string = appServicePlanSharedLinux.id
//output appServicePlanSharedLinuxName string = appServicePlanSharedLinux.name
output containerRegistryName string = acrResource.name

app.bicep

resource acrResource 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {
  name: 'crdevopsnick'
  location: location
  sku: {
    name: 'Basic'
  }
  properties: {
    adminUserEnabled: true        // TO DO - replace by identity
  }
}

resource appServiceApi 'Microsoft.Web/sites@2021-03-01' = {
  name: 'ase-${applicationName}-api-dotnet-${env}'
  location: location
  properties: {
    serverFarmId: appServicePlanSharedId
    httpsOnly: true
    siteConfig: {
      linuxFxVersion: 'DOCKER|${acrResource.name}.azurecr.io/${applicationName}service:latest'
      appSettings: [
        {
          name: 'DOCKER_REGISTRY_SERVER_URL'
          value: 'https://mcr.microsoft.com'
        } 
        {
          name: 'DOCKER_REGISTRY_SERVER_USERNAME'
          value: acrResource.name
        } 
        {
          name: 'DOCKER_REGISTRY_SERVER_PASSWORD'
          value: listCredentials(resourceId('Microsoft.ContainerRegistry/registries', acrResource.name), '2021-06-01-preview').passwords[0].value //acrResource.listCredentials().passwords[0].value
        }
        {
          name: 'WEBSITES_PORT'
          value: '7122'
        }
      ]
    }
  }
}

解答

完全可以从独立资源组中使用共享的Container Registry,你的问题出在app.bicep的两个关键错误上:

  1. 多余的本地ACR资源定义:你在app.bicep中硬编码创建了crdevopsnick的ACR,但实际需要调用的是共享资源组中的ACR,这个本地定义会导致引用混乱。
  2. 跨资源组ACR引用方式错误:当ACR在其他资源组时,不能仅通过名称直接引用,需要通过existing关键字结合资源组范围来关联目标ACR。

修正步骤

1. 修改app.bicep,引用共享资源组的ACR

param applicationName string
param env string
param appServicePlanSharedId string
param containerRegistryName string
param containerRegistryResourceGroup string

// 引用共享资源组中的ACR,而非本地创建
resource acrResource 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' existing = {
  name: containerRegistryName
  scope: resourceGroup(containerRegistryResourceGroup)
}

resource appServiceApi 'Microsoft.Web/sites@2021-03-01' = {
  name: 'ase-${applicationName}-api-dotnet-${env}'
  location: location
  properties: {
    serverFarmId: appServicePlanSharedId
    httpsOnly: true
    siteConfig: {
      linuxFxVersion: 'DOCKER|${acrResource.name}.azurecr.io/${applicationName}service:latest'
      appSettings: [
        {
          name: 'DOCKER_REGISTRY_SERVER_URL'
          value: 'https://${acrResource.name}.azurecr.io' // 修正为共享ACR的地址
        } 
        {
          name: 'DOCKER_REGISTRY_SERVER_USERNAME'
          value: acrResource.name
        } 
        {
          name: 'DOCKER_REGISTRY_SERVER_PASSWORD'
          value: acrResource.listCredentials().passwords[0].value
        }
        {
          name: 'WEBSITES_PORT'
          value: '7122'
        }
      ]
    }
  }
}

2. 更新main.bicep,传递共享资源组参数

module appService 'app.bicep' = {
  name: 'app${projectName}'
  scope: rg
  params: {
    applicationName: projectName
    env: env
    appServicePlanSharedId: appServiceShared.outputs.appServicePlanSharedLinuxId
    containerRegistryName: appServiceShared.outputs.containerRegistryName
    containerRegistryResourceGroup: rgShared.name // 传递共享资源组名称
  }
}

额外注意事项

  • 确保部署账号对共享资源组的ACR拥有Microsoft.ContainerRegistry/registries/listCredentials/action权限,否则无法获取凭据。
  • 建议尽快替换ACR管理员账号为托管标识,提升资源访问安全性。

内容的提问来源于stack exchange,提问作者NiAu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 19:10:33