Azure Bicep配置函数应用时无法设置ipSecurityRestrictions
问题
我在Azure Bicep模块中定义了用于配置函数应用的资源:
resource functionAppAppsettings 'Microsoft.Web/sites/config@2018-11-01' = { name: '${functionAppName}/appsettings' properties: { AzureWebJobsStorage: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}' WEBSITE_CONTENTAZUREFILECONNECTIONSTRING: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}' FUNCTIONS_EXTENSION_VERSION: '~3' FUNCTIONS_WORKER_RUNTIME: 'dotnet' APPINSIGHTS_INSTRUMENTATIONKEY: appInsightsKey WEBSITE_CONTENTSHARE: toLower(functionAppName) ipSecurityRestrictions: [ { ipAddress: '${pcPublicIp}/32' action: 'Allow' tag: 'Default' priority: 101 name: 'laptop ip' description: 'Allow requests from test laptop' } ] } }
当注释掉ipSecurityRestrictions配置块时,部署可正常运行;但保留该块时,会出现以下错误:
"Code": "BadRequest", "Message": "The parameter properties has an invalid value.", "Target": null, "Details": [ { "Message": "The parameter properties has an invalid value." }, { "Code": "BadRequest" }, { "ErrorEntity": { "ExtendedCode": "51008", "MessageTemplate": "The parameter {0} has an invalid value.", "Parameters": [ "properties" ], "Code": "BadRequest", "Message": "The parameter properties has an invalid value." } }
其中pcPublicIp是包含IPv4地址的字符串,请问哪里配置错误了?
解决方案
问题出在ipSecurityRestrictions的配置位置错误:
ipSecurityRestrictions是函数应用站点级Web配置(Microsoft.Web/sites/config@2018-11-01,类型为web)的属性,而非应用设置(appsettings)的属性。把它放在appsettings的properties里,Azure会识别为无效参数,导致部署失败。
修正方法是单独定义函数应用的web配置资源,将ipSecurityRestrictions移到其中:
// 原有的appsettings资源,移除ipSecurityRestrictions resource functionAppAppsettings 'Microsoft.Web/sites/config@2018-11-01' = { name: '${functionAppName}/appsettings' properties: { AzureWebJobsStorage: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}' WEBSITE_CONTENTAZUREFILECONNECTIONSTRING: 'DefaultEndpointsProtocol=https;AccountName=${storageAccountName};EndpointSuffix=${environment().suffixes.storage};AccountKey=${listKeys(storageAccountId, '2019-06-01').keys[0].value}' FUNCTIONS_EXTENSION_VERSION: '~3' FUNCTIONS_WORKER_RUNTIME: 'dotnet' APPINSIGHTS_INSTRUMENTATIONKEY: appInsightsKey WEBSITE_CONTENTSHARE: toLower(functionAppName) } } // 新增web配置资源,配置ipSecurityRestrictions resource functionAppWebConfig 'Microsoft.Web/sites/config@2018-11-01' = { name: '${functionAppName}/web' properties: { ipSecurityRestrictions: [ { ipAddress: '${pcPublicIp}/32' action: 'Allow' tag: 'Default' priority: 101 name: 'laptop ip' description: 'Allow requests from test laptop' } ] } }
内容的提问来源于stack exchange,提问作者Rob Bowman
相关产品推荐
相关产品推荐

