You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置Azure应用服务时应用设置含冒号/短横线报错

Azure应用服务/Function Terraform配置:App Setting含冒号报错的解决办法

问题背景

我使用Terraform编写Azure应用服务与Azure Function的配置脚本,两者均包含app_settings。最初创建时,我们在设置名称中使用了冒号:和短横线-,旧版本Terraform(0.14.2)对此支持,但升级到新版本Terraform(0.14.9)与Azurerm Provider(3.0.0)后,执行terraform apply时出现报错。

配置示例

resource "azurerm_windows_web_app" "hermes_core_api" {
  name = var.functions_app_r2_name[terraform.workspace]
  location = azurerm_resource_group.ermes_core_resource_group.location
  resource_group_name = azurerm_resource_group.ermes_core_resource_group.name
  service_plan_id = azurerm_service_plan.example_priorityfunc_service_plan.id

  site_config {
      ftps_state = "AllAllowed" 
  }   

  app_settings = {
      "Serilog:WriteTo:0:Args:licenseKey" = data.azurerm_key_vault_secret.New_Relic_Key.value
      "WEBSITE_RUN_FROM_PACKAGE"          = "0"
      # other settings snipped
  }
  # connection strings and other stuff snipped too
}

报错信息

│ Error: creating Windows Web App: (Site Name "func-usw1-hermes-r2-core-dev" / Resource Group "RGP-USW1-HERMES-CORE-DEV"): web.AppsClient#CreateOrUpdate: Failure sending request: StatusCode=400 -- Original Error: Code="BadRequest" Message="AppSetting with name 'Serilog:WriteTo:0:Args:licenseKey' is not allowed." Details=[{"Message":"AppSetting with name 'Serilog:WriteTo:0:Args:licenseKey' is not allowed."},{"Code":"BadRequest"},{"ErrorEntity":{"Code":"BadRequest","ExtendedCode":"04072","Message":"AppSetting with name 'Serilog:WriteTo:0:Args:licenseKey' is not allowed.","MessageTemplate":"AppSetting with name '{0}' is not allowed.","Parameters":["Serilog:WriteTo:0:Args:licenseKey"]}}]
│
│   with azurerm_windows_web_app.hermes_core_api,
│   on hermes_core_api.tf line 4, in resource "azurerm_windows_web_app" "hermes_core_api":
│    4: resource "azurerm_windows_web_app" "hermes_core_api" {

问题原因

这并非Terraform本身的限制,而是新版Azurerm Provider(3.0.0+)严格对齐了Azure平台的App Setting命名规则。Azure应用服务官方规定,App Setting名称仅允许包含字母、数字、下划线_、点.和短横线-,冒号:属于非法字符。旧版Provider未做严格校验,请求能侥幸通过,但新版Provider或Azure后端API收紧了校验逻辑,导致现在报错。

解决办法

1. Serilog配置的适配方案

Serilog原生支持从环境变量读取层级配置,只需将带冒号的配置名转换为下划线分隔的大写形式,Serilog会自动映射回原层级结构,无需修改应用代码:

app_settings = {
    "SERILOG_WRITETO_0_ARGS_LICENSEKEY" = data.azurerm_key_vault_secret.New_Relic_Key.value
    "WEBSITE_RUN_FROM_PACKAGE"          = "0"
    # 其他Serilog配置项同理转换
}

2. 禁止尝试字符编码

不要对冒号做URL编码或其他转义操作——Azure会将转义后的字符当作配置名的一部分,Serilog等框架无法识别,反而会导致配置失效。

3. 自定义配置项处理

自有应用的配置项直接修改名称,将冒号替换为下划线(大小写可根据应用读取逻辑调整),确保符合Azure的命名规则。


内容的提问来源于stack exchange,提问作者Jake

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 04:54:25