向Azure FrontDoor标准版配置多路由时触发BadRequest错误
问题场景
我们使用Azure Front Door(Standard版),计划通过单个AFD实例托管多个SPA应用及对应后端API,尝试在单个端点下添加两条路由(分别绑定不同自定义域名和源组)。第一条路由创建成功,第二条执行时触发BadRequest错误:
(BadRequest) The route domains, paths and protocols configuration has a conflict. More information: Domain: endpoint01, Path pattern: /Applications, Protocol: Http cannot be added to Route frontend01 as this combination already exists in Endpoint endpoint01, Route backend01..
Code: BadRequest
使用的两条az-cli命令:
命令1:
az afd route create -g resource-group-01 --profile-name profile-01 --endpoint-name endpoint01 --route-name backend01 --patterns-to-match /* --origin-group origingroup1 --supported-protocols Http Https --custom-domains backend-custom-domain --forwarding-protocol MatchRequest --https-redirect Enabled --link-to-default-domain Enabled
命令2:
az afd route create -g resource-group-01 --profile-name profile-01 --endpoint-name endpoint01 --route-name frontend01 --patterns-to-match /* --origin-group origingroup1--supported-protocols Http Https --custom-domains frontend-custom-domain --forwarding-protocol MatchRequest --https-redirect Enabled --link-to-default-domain Enabled
冲突原因
核心问题在于两条路由都启用了--link-to-default-domain Enabled,导致AFD的默认端点域名(endpoint01)被同时关联到两条路由上。而两条路由的路径模式(/*)、支持的协议(Http/Https)完全相同,AFD不允许同一端点下,同一域名+路径+协议的组合重复绑定到不同路由。
尽管你指定了不同的自定义域名,但--link-to-default-domain Enabled会强制将默认域名加入路由的关联域名列表,这就造成了默认域名+/*+Http/Https的组合重复,触发冲突。
解决方案
1. 关闭自定义域名路由的默认域名关联
对于绑定自定义域名的路由,将--link-to-default-domain设置为Disabled,让路由仅关联指定的自定义域名,避免涉及默认端点域名,消除冲突。
2. 修正命令语法错误
第二条命令中origingroup1--supported-protocols存在空格缺失问题,需补充空格;同时根据你的架构预期,应为前端路由配置独立的源组(示例中改为origingroup2)。
修正后的命令:
命令1(后端路由):
az afd route create -g resource-group-01 --profile-name profile-01 --endpoint-name endpoint01 --route-name backend01 --patterns-to-match /* --origin-group origingroup1 --supported-protocols Http Https --custom-domains backend-custom-domain --forwarding-protocol MatchRequest --https-redirect Enabled --link-to-default-domain Disabled
命令2(前端路由):
az afd route create -g resource-group-01 --profile-name profile-01 --endpoint-name endpoint01 --route-name frontend01 --patterns-to-match /* --origin-group origingroup2 --supported-protocols Http Https --custom-domains frontend-custom-domain --forwarding-protocol MatchRequest --https-redirect Enabled --link-to-default-domain Disabled
3. 后续负载均衡扩展建议
若要实现应用负载均衡,可为每个应用的前端/后端分别创建独立源组,在源组内添加多个源,并配置AFD的负载均衡规则(如轮询、加权轮询等)。
内容的提问来源于stack exchange,提问作者ossentoo

