You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用azurerm_app_service_connection配置连接字符串类型服务连接器报错求助

解决azurerm_app_service_connection创建SQL服务连接器的报错问题

问题分析

你遇到的报错Expected type object but found type string. Paths in payload: '$.properties.authInfo.secretInfo.secretType',核心原因是认证类型配置错误,同时存在目标资源指向错误、缺少防火墙规则配置的问题,和门户配置不匹配。

修正后的Terraform配置

以下配置完全匹配你在Azure门户中的设置:

resource "azurerm_app_service_connection" "service_connector" {
  name               = "myapp-to-sql-server-north-stage"
  app_service_id     = azurerm_windows_web_app.app_service.id
  # 目标资源改为SQL数据库的ID,而非SQL Server
  target_resource_id = azurerm_mssql_database.mssql_database.id
  client_type        = "dotnet"
  # 启用防火墙规则,对应门户中的"配置防火墙规则以允许访问目标服务"
  firewall_rule_enabled = true

  authentication {
    # 对应门户的认证类型"Connection string"
    type = "connectionString"
    # 构造符合SQL Server格式的连接字符串
    connection_string = "Server=tcp:${azurerm_mssql_server.mssql_server.fully_qualified_domain_name},1433;Initial Catalog=${azurerm_mssql_database.mssql_database.name};Persist Security Info=False;User ID=mydbadminusername;Password=mydbadminpassword;MultipleActiveResultSets=False;Encrypt=True;TrustServerCertificate=False;Connection Timeout=30;"
  }
}

关键修正点说明

  • 目标资源ID修正:门户中选择的服务类型是"SQL数据库",因此target_resource_id必须指向SQL数据库资源,而非SQL Server资源,否则服务连接器无法关联到具体数据库。
  • 认证类型调整:你在门户中选择的是"Connection string"认证类型,因此Terraform中authentication块的type必须设为connectionString,而非secret。secret类型适用于其他场景(如Key Vault凭据),会导致API请求结构不匹配,触发类型错误。
  • 启用防火墙规则:通过firewall_rule_enabled = true参数,自动配置SQL数据库的防火墙规则允许Web App访问,对应门户中的网络配置选项。
  • 连接字符串构造:手动构造符合SQL Server规范的连接字符串,包含用户名、密码、数据库名等信息,和门户中"存储到连接字符串中"的配置一致。

后续优化建议

当前配置中密码为明文,后续可将密码存储到Azure Key Vault,通过以下方式调整认证块:

authentication {
  type = "keyVaultSecret"
  secret_id = azurerm_key_vault_secret.sql_password.id
}

内容的提问来源于stack exchange,提问作者spadeki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 23:05:31