You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Linux Function App配置v2认证未生效问题排查

问题

我尝试创建启用v2认证的Linux Function App,使用HashiCorp的azurerm provider(对应资源为azurerm_linux_function_app)。编写Terraform模块时,在auth_settings中设置runtime_version为"~2"以启用v2认证,并配置Active Directory相关参数。执行terraform apply时,计划显示配置正确,但实际创建的应用仍为v1认证,请问哪里操作错误导致v2认证未生效?

模块代码

resource "azurerm_linux_function_app" "function_app" {
  name                 = var.name
  resource_group_name  = var.resource_group_name
  location             = var.location
  storage_account_name = var.storage_account_name
  service_plan_id      = var.service_plan_id
  app_settings         = var.app_settings

  auth_settings {
    enabled          = var.auth_settings_enabled
    runtime_version = "~2" // auth v2
    dynamic "active_directory" {
      for_each = auth_settings_enabled ? [1] : []
      content {
        client_id         = var.auth_active_directory.client_id
        client_secret     = var.auth_active_directory.client_secret
        allowed_audiences = var.auth_active_directory.allowed_audiences
      }
    }
  }
}

模块调用代码

module "function_app" {
  source = "./function-app-module"

  // standard vars like name etc here...

  auth_settings_enabled = true
  auth_active_directory = {
    client_id         = var.clientid
    client_secret     = var.clientsecret
    allowed_audiences = [ var.audience ]
  }
}

Terraform Apply计划输出

2022-10-06T12:14:13.9619896Z       [32m+[0m [0mauth_settings {
2022-10-06T12:14:13.9620448Z           [32m+[0m [0m[1m[0mallowed_external_redirect_urls[0m[0m = (known after apply)
2022-10-06T12:14:13.9621080Z           [32m+[0m [0m[1m[0mdefault_provider[0m[0m               = (known after apply)
2022-10-06T12:14:13.9621641Z           [32m+[0m [0m[1m[0menabled[0m[0m                        = true
2022-10-06T12:14:13.9622161Z           [32m+[0m [0m[1m[0mruntime_version[0m[0m                = "~2"
2022-10-06T12:14:13.9622721Z           [32m+[0m [0m[1m[0mtoken_refresh_extension_hours[0m[0m  = 72
2022-10-06T12:14:13.9623295Z           [32m+[0m [0m[1m[0mtoken_store_enabled[0m[0m            = false
2022-10-06T12:14:13.9623984Z           [32m+[0m [0m[1m[0munauthenticated_client_action[0m[0m  = (known after apply)
2022-10-06T12:14:13.9624219Z 
2022-10-06T12:14:13.9624606Z           [32m+[0m [0mactive_directory {
2022-10-06T12:14:13.9625101Z               [32m+[0m [0m[1m[0mallowed_audiences[0m[0m = [
2022-10-06T12:14:13.9625660Z                   [32m+[0m [0m"00000-0000-0000-0000-00000",
2022-10-06T12:14:13.9625962Z                 ]
2022-10-06T12:14:13.9626510Z               [32m+[0m [0m[1m[0mclient_id[0m[0m         = "00000-0000-0000-0000-00000"
2022-10-06T12:14:13.9627114Z               [32m+[0m [0m[1m[0mclient_secret[0m[0m     = (sensitive value)
2022-10-06T12:14:13.9627435Z             }
2022-10-06T12:14:13.9627654Z         }
2022-10-06T12:14:13.9627743Z 

实际创建的应用仍为v1认证(截图显示)。


解决方案

核心问题是:Linux Function App的v2认证不能通过auth_settings块的runtime_version参数配置,该参数仅对Windows平台生效,Linux平台需要通过应用设置启用v2认证。

具体修复步骤

  1. 删除auth_settings块中的runtime_version = "~2"配置,该参数对Linux资源无效,Azure后台会直接忽略。
  2. 在app_settings中添加WEBSITE_AUTH_USE_V2 = "true"配置项,这是Linux平台启用v2认证的正确方式。

修改后的模块代码

resource "azurerm_linux_function_app" "function_app" {
  name                 = var.name
  resource_group_name  = var.resource_group_name
  location             = var.location
  storage_account_name = var.storage_account_name
  service_plan_id      = var.service_plan_id
  app_settings = merge(var.app_settings, {
    "WEBSITE_AUTH_USE_V2" = "true" // 强制启用v2认证引擎
  })

  auth_settings {
    enabled = var.auth_settings_enabled
    dynamic "active_directory" {
      for_each = var.auth_settings_enabled ? [1] : []
      content {
        client_id         = var.auth_active_directory.client_id
        client_secret     = var.auth_active_directory.client_secret
        allowed_audiences = var.auth_active_directory.allowed_audiences
      }
    }
  }
}

补充说明

Azure对Windows和Linux平台的App Service/Function App认证配置逻辑存在差异:

  • Windows平台支持通过ARM模板或Terraform的auth_settings块设置runtime_version切换认证版本;
  • Linux平台则依赖应用设置WEBSITE_AUTH_USE_V2来启用v2认证引擎,即使Terraform计划显示runtime_version = "~2",也不会对Linux资源产生实际作用。

内容的提问来源于stack exchange,提问作者michasaucer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 13:35:33