使用ARM模板更新Azure应用网关重写规则遇部署错误求助
解决ARM模板增量模式更新应用网关重写规则时的模板属性缺失错误
问题原因
你遇到的错误本质是:ARM模板在增量模式下更新现有资源时,必须包含该资源的所有必填属性。即便你只想更新重写规则,模板里也不能只提供rewriteRuleSets——因为ARM会将这种不完整的资源定义视为要创建新的应用网关,而新网关缺少IP配置等必填项,因此触发错误。
解决方案
方案1:通过资源引用获取完整配置并合并更新内容
使用reference()函数拉取应用网关的现有完整配置,仅修改rewriteRuleSets部分,这样既保留所有必填属性,又能实现局部更新。修改后的模板如下:
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "applicationGatewayName": { "type": "string" }, "location": { "type": "string" }, "rewriteSetName": { "type": "string" } }, "variables": { "existingGateway": "[reference(resourceId('Microsoft.Network/applicationGateways', parameters('applicationGatewayName')), '2020-05-01')]" }, "resources": [ { "type": "Microsoft.Network/applicationGateways", "apiVersion": "2020-05-01", "name": "[parameters('applicationGatewayName')]", "location": "[parameters('location')]", "properties": { // 保留现有网关的所有必填属性 "sku": "[variables('existingGateway').sku]", "gatewayIPConfigurations": "[variables('existingGateway').gatewayIPConfigurations]", "frontendIPConfigurations": "[variables('existingGateway').frontendIPConfigurations]", "frontendPorts": "[variables('existingGateway').frontendPorts]", "backendAddressPools": "[variables('existingGateway').backendAddressPools]", "backendHttpSettingsCollection": "[variables('existingGateway').backendHttpSettingsCollection]", "httpListeners": "[variables('existingGateway').httpListeners]", "requestRoutingRules": "[variables('existingGateway').requestRoutingRules]", // 更新重写规则集:替换或新增目标规则集 "rewriteRuleSets": "[concat( // 过滤掉要更新的规则集 filter(variables('existingGateway').rewriteRuleSets, item => item.name != parameters('rewriteSetName')), // 添加新的规则集内容 [ { "name": "[parameters('rewriteSetName')]", "properties": { "rewriteRules": [ { "ruleSequence": 300, "conditions": [], "name": "security-response-headers", "actionSet": { "requestHeaderConfigurations": [], "responseHeaderConfigurations": [ { "headerName": "Permissions-Policy", "headerValue": "accelerometers=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()" } ] } } ] } } ] )]" } } ], "outputs": {} }
方案2:使用Azure CLI/PowerShell直接更新(更简便)
对于仅更新重写规则这类局部操作,使用CLI或PowerShell比ARM模板更高效,无需处理完整资源配置:
Azure CLI命令示例
# 向现有规则集添加重写规则 az network application-gateway rewrite-rule set update \ --gateway-name <你的应用网关名称> \ --name <你的规则集名称> \ --resource-group <资源组名称> \ --add rewriteRules "{\"name\":\"security-response-headers\",\"ruleSequence\":300,\"actionSet\":{\"responseHeaderConfigurations\":[{\"headerName\":\"Permissions-Policy\",\"headerValue\":\"accelerometers=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()\"}]}}"
PowerShell命令示例
# 获取现有应用网关 $gw = Get-AzApplicationGateway -Name <你的应用网关名称> -ResourceGroupName <资源组名称> # 创建新的重写规则 $responseHeaderConfig = New-AzApplicationGatewayRewriteRuleHeaderConfiguration -HeaderName "Permissions-Policy" -HeaderValue "accelerometers=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()" $actionSet = New-AzApplicationGatewayRewriteRuleActionSet -ResponseHeaderConfiguration $responseHeaderConfig $rewriteRule = New-AzApplicationGatewayRewriteRule -Name "security-response-headers" -RuleSequence 300 -ActionSet $actionSet # 更新规则集 $gw = Add-AzApplicationGatewayRewriteRule -ApplicationGateway $gw -Name <你的规则集名称> -RewriteRule $rewriteRule # 提交更新 Set-AzApplicationGateway -ApplicationGateway $gw
内容的提问来源于stack exchange,提问作者quikbeam
相关产品推荐
相关产品推荐

