You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep environment()函数配置防火墙规则TargetFqdns时部署失败

应用防火墙规则targetFqdns替换environment()函数后部署失败排查

问题背景

为替换应用防火墙规则中硬编码的targetFqdns列表,尝试使用Bicep的environment()函数动态生成域名,但部署失败。

原硬编码配置:

targetFqdns: [
    '*.blob.core.windows.net'
    'login.microsoftonline.com'
    'management.core.windows.net'
    'management.azure.com'
    'graph.windows.net'
]

错误的替换代码:

targetFqdns: [ 
    '*.blob.${environment().suffixes.storage}' // '*.blob.core.windows.net'
    '${environment().authentication.loginEndpoint}' // 'login.microsoftonline.com'
    '${environment().authentication.audiences}' // 'management.core.windows.net'
    '${environment().resourceManager}' // 'management.azure.com'
    '${environment().graphAudience}' // 'graph.windows.net'
]

部署报错:

{
    "status": "Failed",
    "error": {
        "code": "DeploymentFailed",
        "message": "At least one resource deployment operation failed. Please list deployment operations for details. Please see https://aka.ms/DeployOperations for usage details.",
        "details": [
            {
                "code": "BadRequest",
                "message": "{\r\n  \"Message\": \"The request is invalid.\",\r\n  \"ModelState\": {\r\n    \"resource\": [\r\n      \"{\\\"Status\\\":\\\"Failed\\\",\\\"Error\\\":{\\\"Code\\\":\\\"FirewallPolicyApplicationRuleInvalidTargetFqdn\\\",\\\"Message\\\":\\\"Firewall Policy Application Rule dev-firewall-rule has invalid target fqdn https://login.microsoftonline.com/\\\",\\\"Target\\\":null}}\"\r\n    ]\r\n  }\r\n}"
            }
        ]
    }
}

错误原因分析

核心问题是部分environment()属性返回值不符合防火墙规则对targetFqdns的格式要求:

  1. environment().authentication.loginEndpoint:返回完整URL(如https://login.microsoftonline.com/),包含协议前缀和末尾斜杠,不是纯域名
  2. environment().authentication.audiences:返回数组(如公有云中为["https://management.core.windows.net/"]),直接赋值会导致格式错误
  3. environment().resourceManager:返回完整URL(如https://management.azure.com/),包含协议前缀和末尾斜杠
  4. environment().graphAudience:返回完整URL(如https://graph.windows.net/),包含协议前缀和末尾斜杠

修正后的代码

通过字符串处理提取纯域名,同时处理数组取值,修正后的配置如下:

targetFqdns: [ 
    // 存储域名后缀无需额外处理
    '*.blob.${environment().suffixes.storage}'
    // 提取loginEndpoint的纯域名
    '${replace(environment().authentication.loginEndpoint, 'https://', '').trimEnd('/')}'
    // 从audiences数组取第一个元素并提取纯域名
    '${replace(environment().authentication.audiences[0], 'https://', '').trimEnd('/')}'
    // 提取resourceManager的纯域名
    '${replace(environment().resourceManager, 'https://', '').trimEnd('/')}'
    // 提取graphAudience的纯域名
    '${replace(environment().graphAudience, 'https://', '').trimEnd('/')}'
]

验证说明

修正后,environment()函数生成的内容会与原硬编码的纯域名完全匹配:

  • *.blob.${environment().suffixes.storage} → *.blob.core.windows.net
  • 处理后的loginEndpoint → login.microsoftonline.com
  • 处理后的audiences[0] → management.core.windows.net
  • 处理后的resourceManager → management.azure.com
  • 处理后的graphAudience → graph.windows.net

内容的提问来源于stack exchange,提问作者Nadia Hansen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 19:05:32