如何通过Terraform创建基于工作区的Azure Application Insights并关联函数应用
用Terraform创建基于工作区的Application Insights并关联Azure Function
问题背景
我通过Terraform完成了Azure Function与Application Insights的关联配置,但Application Insights后台提示:
迁移此资源到基于工作区的Application Insights,以获得Log Analytics的全部功能支持,包括客户管理密钥和承诺层级。点击此处了解更多并一键迁移。
需要直接通过Terraform创建基于工作区的Application Insights,避免事后手动迁移。
现有代码
Azure Function配置
resource "azurerm_linux_function_app" "t_funcapp" { name = "t-function-app" location = local.resource_location resource_group_name = local.resource_group_name service_plan_id = azurerm_service_plan.t_app_service_plan.id storage_account_name = azurerm_storage_account.t_funcstorage.name storage_account_access_key = azurerm_storage_account.t_funcstorage.primary_access_key site_config { application_stack { java_version = "11" } remote_debugging_enabled = false ftps_state = "AllAllowed" } app_settings = { APPINSIGHTS_INSTRUMENTATIONKEY = "${azurerm_application_insights.t_appinsights.instrumentation_key}" } depends_on = [ azurerm_resource_group.t_rg, azurerm_service_plan.t_app_service_plan, azurerm_storage_account.t_funcstorage, azurerm_application_insights.t_appinsights ] }
Application Insights配置
resource "azurerm_application_insights" "t_appinsights" { name = "t-appinsights" location = local.resource_location resource_group_name = local.resource_group_name application_type = "web" depends_on = [ azurerm_log_analytics_workspace.t_workspace ] } output "instrumentation_key" { value = azurerm_application_insights.t_appinsights.instrumentation_key } output "app_id" { value = azurerm_application_insights.t_appinsights.app_id }
解决方案
核心是在azurerm_application_insights资源中添加workspace_id参数,关联已创建的Log Analytics工作区,直接生成基于工作区的Application Insights资源。同时推荐更新Azure Function的应用设置,使用连接字符串替代 instrumentation key。
修改后的Application Insights代码
resource "azurerm_application_insights" "t_appinsights" { name = "t-appinsights" location = local.resource_location resource_group_name = local.resource_group_name application_type = "web" # 关联Log Analytics工作区,创建基于工作区的Application Insights workspace_id = azurerm_log_analytics_workspace.t_workspace.id depends_on = [ azurerm_log_analytics_workspace.t_workspace ] } output "instrumentation_key" { value = azurerm_application_insights.t_appinsights.instrumentation_key } output "app_id" { value = azurerm_application_insights.t_appinsights.app_id } # 新增连接字符串输出,用于Function App配置 output "connection_string" { value = azurerm_application_insights.t_appinsights.connection_string }
修改后的Azure Function代码(推荐配置)
resource "azurerm_linux_function_app" "t_funcapp" { name = "t-function-app" location = local.resource_location resource_group_name = local.resource_group_name service_plan_id = azurerm_service_plan.t_app_service_plan.id storage_account_name = azurerm_storage_account.t_funcstorage.name storage_account_access_key = azurerm_storage_account.t_funcstorage.primary_access_key site_config { application_stack { java_version = "11" } remote_debugging_enabled = false ftps_state = "AllAllowed" } app_settings = { # 微软推荐使用连接字符串替代instrumentation key,适配基于工作区的资源 APPLICATIONINSIGHTS_CONNECTION_STRING = azurerm_application_insights.t_appinsights.connection_string # 如需兼容旧逻辑,可保留instrumentation key配置 # APPINSIGHTS_INSTRUMENTATIONKEY = azurerm_application_insights.t_appinsights.instrumentation_key } depends_on = [ azurerm_resource_group.t_rg, azurerm_service_plan.t_app_service_plan, azurerm_storage_account.t_funcstorage, azurerm_application_insights.t_appinsights ] }
关键说明
- 添加
workspace_id后,创建的Application Insights会直接绑定到指定的Log Analytics工作区,属于原生基于工作区的资源,不会触发迁移提示 APPLICATIONINSIGHTS_CONNECTION_STRING是微软针对基于工作区的Application Insights推荐的配置方式,包含更完整的连接信息- 确保Log Analytics工作区与Application Insights处于同一Azure区域(平台强制要求)
内容的提问来源于stack exchange,提问作者Satya Panigrahy
相关产品推荐
相关产品推荐

