You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Bicep配置函数应用时无法设置ipSecurityRestrictions

问题

我在Azure Bicep模块中定义了用于配置函数应用的资源:

resource functionAppAppsettings 'Microsoft.Web/sites/config@2018-11-01' = {
  name: '${functionAppName}/appsettings'
  properties: {
    AzureWebJobsStorage: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}'
    WEBSITE_CONTENTAZUREFILECONNECTIONSTRING: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}'
    FUNCTIONS_EXTENSION_VERSION: '~3'
    FUNCTIONS_WORKER_RUNTIME: 'dotnet'
    APPINSIGHTS_INSTRUMENTATIONKEY: appInsightsKey
    WEBSITE_CONTENTSHARE: toLower(functionAppName)
    ipSecurityRestrictions: [
      {
        ipAddress: '${pcPublicIp}/32'
        action: 'Allow'
        tag: 'Default'
        priority: 101
        name: 'laptop ip'
        description: 'Allow requests from test laptop'
      }
    ]
  }
}

当注释掉ipSecurityRestrictions配置块时,部署可正常运行;但保留该块时,会出现以下错误:

"Code": "BadRequest",
  "Message": "The parameter properties has an invalid value.",
  "Target": null,
  "Details": [
    {
      "Message": "The parameter properties has an invalid value."
    },
    {
      "Code": "BadRequest"
    },
    {
      "ErrorEntity": {
        "ExtendedCode": "51008",
        "MessageTemplate": "The parameter {0} has an invalid value.",
        "Parameters": [
          "properties"
        ],
        "Code": "BadRequest",
        "Message": "The parameter properties has an invalid value."
      }
    }

其中pcPublicIp是包含IPv4地址的字符串,请问哪里配置错误了?

解决方案

问题出在ipSecurityRestrictions的配置位置错误:

  • ipSecurityRestrictions是函数应用站点级Web配置(Microsoft.Web/sites/config@2018-11-01,类型为web)的属性,而非应用设置(appsettings)的属性。把它放在appsettings的properties里,Azure会识别为无效参数,导致部署失败。

修正方法是单独定义函数应用的web配置资源,将ipSecurityRestrictions移到其中:

// 原有的appsettings资源,移除ipSecurityRestrictions
resource functionAppAppsettings 'Microsoft.Web/sites/config@2018-11-01' = {
  name: '${functionAppName}/appsettings'
  properties: {
    AzureWebJobsStorage: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}'
    WEBSITE_CONTENTAZUREFILECONNECTIONSTRING: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}'
    FUNCTIONS_EXTENSION_VERSION: '~3'
    FUNCTIONS_WORKER_RUNTIME: 'dotnet'
    APPINSIGHTS_INSTRUMENTATIONKEY: appInsightsKey
    WEBSITE_CONTENTSHARE: toLower(functionAppName)
  }
}

// 新增web配置资源,配置ipSecurityRestrictions
resource functionAppWebConfig 'Microsoft.Web/sites/config@2018-11-01' = {
  name: '${functionAppName}/web'
  properties: {
    ipSecurityRestrictions: [
      {
        ipAddress: '${pcPublicIp}/32'
        action: 'Allow'
        tag: 'Default'
        priority: 101
        name: 'laptop ip'
        description: 'Allow requests from test laptop'
      }
    ]
  }
}

内容的提问来源于stack exchange,提问作者Rob Bowman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 09:05:27