Azure Linux Function App配置v2认证未生效问题排查
问题
我尝试创建启用v2认证的Linux Function App,使用HashiCorp的azurerm provider(对应资源为azurerm_linux_function_app)。编写Terraform模块时,在auth_settings中设置runtime_version为"~2"以启用v2认证,并配置Active Directory相关参数。执行terraform apply时,计划显示配置正确,但实际创建的应用仍为v1认证,请问哪里操作错误导致v2认证未生效?
模块代码
resource "azurerm_linux_function_app" "function_app" { name = var.name resource_group_name = var.resource_group_name location = var.location storage_account_name = var.storage_account_name service_plan_id = var.service_plan_id app_settings = var.app_settings auth_settings { enabled = var.auth_settings_enabled runtime_version = "~2" // auth v2 dynamic "active_directory" { for_each = auth_settings_enabled ? [1] : [] content { client_id = var.auth_active_directory.client_id client_secret = var.auth_active_directory.client_secret allowed_audiences = var.auth_active_directory.allowed_audiences } } } }
模块调用代码
module "function_app" { source = "./function-app-module" // standard vars like name etc here... auth_settings_enabled = true auth_active_directory = { client_id = var.clientid client_secret = var.clientsecret allowed_audiences = [ var.audience ] } }
Terraform Apply计划输出
2022-10-06T12:14:13.9619896Z [32m+[0m [0mauth_settings { 2022-10-06T12:14:13.9620448Z [32m+[0m [0m[1m[0mallowed_external_redirect_urls[0m[0m = (known after apply) 2022-10-06T12:14:13.9621080Z [32m+[0m [0m[1m[0mdefault_provider[0m[0m = (known after apply) 2022-10-06T12:14:13.9621641Z [32m+[0m [0m[1m[0menabled[0m[0m = true 2022-10-06T12:14:13.9622161Z [32m+[0m [0m[1m[0mruntime_version[0m[0m = "~2" 2022-10-06T12:14:13.9622721Z [32m+[0m [0m[1m[0mtoken_refresh_extension_hours[0m[0m = 72 2022-10-06T12:14:13.9623295Z [32m+[0m [0m[1m[0mtoken_store_enabled[0m[0m = false 2022-10-06T12:14:13.9623984Z [32m+[0m [0m[1m[0munauthenticated_client_action[0m[0m = (known after apply) 2022-10-06T12:14:13.9624219Z 2022-10-06T12:14:13.9624606Z [32m+[0m [0mactive_directory { 2022-10-06T12:14:13.9625101Z [32m+[0m [0m[1m[0mallowed_audiences[0m[0m = [ 2022-10-06T12:14:13.9625660Z [32m+[0m [0m"00000-0000-0000-0000-00000", 2022-10-06T12:14:13.9625962Z ] 2022-10-06T12:14:13.9626510Z [32m+[0m [0m[1m[0mclient_id[0m[0m = "00000-0000-0000-0000-00000" 2022-10-06T12:14:13.9627114Z [32m+[0m [0m[1m[0mclient_secret[0m[0m = (sensitive value) 2022-10-06T12:14:13.9627435Z } 2022-10-06T12:14:13.9627654Z } 2022-10-06T12:14:13.9627743Z
实际创建的应用仍为v1认证(截图显示)。
解决方案
核心问题是:Linux Function App的v2认证不能通过auth_settings块的runtime_version参数配置,该参数仅对Windows平台生效,Linux平台需要通过应用设置启用v2认证。
具体修复步骤
- 删除
auth_settings块中的runtime_version = "~2"配置,该参数对Linux资源无效,Azure后台会直接忽略。 - 在
app_settings中添加WEBSITE_AUTH_USE_V2 = "true"配置项,这是Linux平台启用v2认证的正确方式。
修改后的模块代码
resource "azurerm_linux_function_app" "function_app" { name = var.name resource_group_name = var.resource_group_name location = var.location storage_account_name = var.storage_account_name service_plan_id = var.service_plan_id app_settings = merge(var.app_settings, { "WEBSITE_AUTH_USE_V2" = "true" // 强制启用v2认证引擎 }) auth_settings { enabled = var.auth_settings_enabled dynamic "active_directory" { for_each = var.auth_settings_enabled ? [1] : [] content { client_id = var.auth_active_directory.client_id client_secret = var.auth_active_directory.client_secret allowed_audiences = var.auth_active_directory.allowed_audiences } } } }
补充说明
Azure对Windows和Linux平台的App Service/Function App认证配置逻辑存在差异:
- Windows平台支持通过ARM模板或Terraform的
auth_settings块设置runtime_version切换认证版本; - Linux平台则依赖应用设置
WEBSITE_AUTH_USE_V2来启用v2认证引擎,即使Terraform计划显示runtime_version = "~2",也不会对Linux资源产生实际作用。
内容的提问来源于stack exchange,提问作者michasaucer
相关产品推荐
相关产品推荐

