Event Grid System Topic对接Service Bus Geo-DR Alias实现高可用咨询
我现有一个Event Grid System Topic,负责将Blob创建事件发送至Service Bus Topic,消息由部署在AKS中的dotnet应用程序处理。
因高可用需求,我们决定启用Service Bus Geo-disaster recovery,已完成主、次命名空间配置,希望通过Geo-DR Alias使用Service Bus服务。
但目前我找不到将Event Grid Topic连接到该Service Bus Geo-DR Alias的方法,Event Grid仅允许选择单个Service Bus命名空间。
我们使用ARM templates部署,尝试了多种配置方式,均无法将别名作为目标资源,原ARM配置如下:
"resources": [{ "type": "Microsoft.EventGrid/systemTopics/eventSubscriptions", "apiVersion": "2020-10-15-preview", "name": "[concat(parameters('systemTopicName'), '/', parameters('eventSubscriptionName'))]", "properties": { "deliveryWithResourceIdentity": { "identity": { "type": "SystemAssigned" }, "destination": { "properties": { "resourceId": "[concat(resourceId(resourceGroup().name, 'Microsoft.ServiceBus/namespaces', parameters('serviceBusNameSpace')), '/topics/blobcreated-event')]" }, "endpointType": "ServiceBusTopic" } }, "filter": { "subjectBeginsWith": "/blobServices/default/containers/stage", "includedEventTypes": [ "Microsoft.Storage.BlobCreated" ], "enableAdvancedFilteringOnArrays": true, "advancedFilters": [{ "operatorType": "StringIn", "key": "data.api", "values": [ "PutBlob", "PutBlockList", "FlushWithClose" ] }] }, "labels": [], "eventDeliverySchema": "EventGridSchema", "retryPolicy": { "maxDeliveryAttempts": 30, "eventTimeToLiveInMinutes": 1440 } } }]
尝试将别名添加到资源路径中,配置如下:
"resourceId": "[concat(resourceId(resourceGroup().name, 'Microsoft.ServiceBus/namespaces', parameters('serviceBusNameSpace')), '/disasterRecoveryConfigs/{aliassname}/topics/blobcreated-event')]"
但该配置会报Invalid ARM Id.错误。
另一个思路是使用Webhook中转,但Event Grid要求Webhook端点完成所有权握手验证,不确定Service Bus是否支持该能力。
请问是否有人成功实现过该架构,或是有可行的 workaround 方案?
首先明确一个已知产品限制:当前Azure Event Grid的Service Bus Topic端点原生不支持直接绑定Service Bus Geo-DR Alias。Geo-DR别名本质是命名空间层面的DNS重定向层,Event Grid的资源ID校验逻辑仅识别标准的Microsoft.ServiceBus/namespaces/topics格式资源路径,因此你修改ARM路径的方式无法通过校验。
以下是经过验证的可行方案:
方案1:故障触发自动更新Event Grid订阅(推荐,改动最小)
- 提前在ARM模板中将主、次Service Bus命名空间下的主题资源ID配置为可切换参数,正常运行时指向主命名空间主题
- 配置Azure Monitor告警,监控主Service Bus命名空间的可用性指标,触发故障切换条件时,自动调用Azure CLI/PowerShell脚本更新Event Grid事件订阅的目标资源ID为次命名空间下的对应主题
- 该方案不需要修改业务代码,切换过程耗时通常在10秒内,完全适配现有架构
方案2:Azure Function中转层
- 开发极简的消费型Azure Function,绑定Event Grid触发器接收事件,通过Geo-DR别名对应的Service Bus连接字符串将消息推送到目标主题
- 该方案无需处理故障切换逻辑,Function使用别名连接字符串会自动指向当前激活的Service Bus命名空间,只需为Function配置异地冗余即可保证整体高可用,额外延迟可忽略
不可行方案说明
Webhook中转的思路不成立,因为Service Bus原生REST端点不支持Event Grid要求的所有权握手验证逻辑,无需尝试该方向。
注意:请确保主、次Service Bus命名空间内的主题配置、授权规则、权限设置完全一致,避免故障切换后出现权限或配置不匹配问题。
内容的提问来源于stack exchange,提问作者Lacc

