Terraform配置Azure应用服务时应用设置含冒号/短横线报错
Azure应用服务/Function Terraform配置:App Setting含冒号报错的解决办法
问题背景
我使用Terraform编写Azure应用服务与Azure Function的配置脚本,两者均包含app_settings。最初创建时,我们在设置名称中使用了冒号:和短横线-,旧版本Terraform(0.14.2)对此支持,但升级到新版本Terraform(0.14.9)与Azurerm Provider(3.0.0)后,执行terraform apply时出现报错。
配置示例
resource "azurerm_windows_web_app" "hermes_core_api" { name = var.functions_app_r2_name[terraform.workspace] location = azurerm_resource_group.ermes_core_resource_group.location resource_group_name = azurerm_resource_group.ermes_core_resource_group.name service_plan_id = azurerm_service_plan.example_priorityfunc_service_plan.id site_config { ftps_state = "AllAllowed" } app_settings = { "Serilog:WriteTo:0:Args:licenseKey" = data.azurerm_key_vault_secret.New_Relic_Key.value "WEBSITE_RUN_FROM_PACKAGE" = "0" # other settings snipped } # connection strings and other stuff snipped too }
报错信息
│ Error: creating Windows Web App: (Site Name "func-usw1-hermes-r2-core-dev" / Resource Group "RGP-USW1-HERMES-CORE-DEV"): web.AppsClient#CreateOrUpdate: Failure sending request: StatusCode=400 -- Original Error: Code="BadRequest" Message="AppSetting with name 'Serilog:WriteTo:0:Args:licenseKey' is not allowed." Details=[{"Message":"AppSetting with name 'Serilog:WriteTo:0:Args:licenseKey' is not allowed."},{"Code":"BadRequest"},{"ErrorEntity":{"Code":"BadRequest","ExtendedCode":"04072","Message":"AppSetting with name 'Serilog:WriteTo:0:Args:licenseKey' is not allowed.","MessageTemplate":"AppSetting with name '{0}' is not allowed.","Parameters":["Serilog:WriteTo:0:Args:licenseKey"]}}] │ │ with azurerm_windows_web_app.hermes_core_api, │ on hermes_core_api.tf line 4, in resource "azurerm_windows_web_app" "hermes_core_api": │ 4: resource "azurerm_windows_web_app" "hermes_core_api" {
问题原因
这并非Terraform本身的限制,而是新版Azurerm Provider(3.0.0+)严格对齐了Azure平台的App Setting命名规则。Azure应用服务官方规定,App Setting名称仅允许包含字母、数字、下划线_、点.和短横线-,冒号:属于非法字符。旧版Provider未做严格校验,请求能侥幸通过,但新版Provider或Azure后端API收紧了校验逻辑,导致现在报错。
解决办法
1. Serilog配置的适配方案
Serilog原生支持从环境变量读取层级配置,只需将带冒号的配置名转换为下划线分隔的大写形式,Serilog会自动映射回原层级结构,无需修改应用代码:
app_settings = { "SERILOG_WRITETO_0_ARGS_LICENSEKEY" = data.azurerm_key_vault_secret.New_Relic_Key.value "WEBSITE_RUN_FROM_PACKAGE" = "0" # 其他Serilog配置项同理转换 }
2. 禁止尝试字符编码
不要对冒号做URL编码或其他转义操作——Azure会将转义后的字符当作配置名的一部分,Serilog等框架无法识别,反而会导致配置失效。
3. 自定义配置项处理
自有应用的配置项直接修改名称,将冒号替换为下划线(大小写可根据应用读取逻辑调整),确保符合Azure的命名规则。
内容的提问来源于stack exchange,提问作者Jake
相关产品推荐
相关产品推荐

