如何通过Terraform配置Azure Function App启用网络注入功能
Terraform 配置Azure Function App启用网络注入操作指南
前置要求
你需要提前完成以下资源准备:
- 已创建目标虚拟网络
- 已为Function App VNet集成创建专属子网,子网需完成
Microsoft.Web/serverFarms委托配置
核心配置说明
Azure Function App的网络注入(即VNet集成)对应azurerm_linux_function_app/azurerm_windows_function_app资源的以下配置项:
virtual_network_subnet_id:填写已完成委托的子网ID,绑定后自动启用VNet网络注入能力vnet_route_all_enabled:设置为true时将Function App所有出站流量都路由到VNet,对应控制台中"全部路由"选项- 若需禁用公网访问,可额外配置
public_network_access_enabled = false
完整配置示例
# 配置AzureRM Provider terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = "~>3.0" } } } provider "azurerm" { features {} } # 示例资源组 resource "azurerm_resource_group" "example" { name = "example-resources" location = "West Europe" } # 示例虚拟网络 resource "azurerm_virtual_network" "example" { name = "example-vnet" address_space = ["10.0.0.0/16"] location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name } # 已配置委托的Function App专属子网 resource "azurerm_subnet" "func_injection" { name = "func-injection-subnet" resource_group_name = azurerm_resource_group.example.name virtual_network_name = azurerm_virtual_network.example.name address_prefixes = ["10.0.1.0/24"] # 配置子网委托,允许Web服务使用该子网 delegation { name = "func-delegation" service_delegation { name = "Microsoft.Web/serverFarms" actions = ["Microsoft.Network/virtualNetworks/subnets/join/action"] } } } # 示例App Service Plan(注意:弹性Premium计划、专用计划支持VNet集成,消费计划仅支持部分区域的VNet集成) resource "azurerm_service_plan" "example" { name = "example-asp" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location os_type = "Linux" sku_name = "P1v3" # 选择支持VNet集成的SKU } # 示例存储账户(Function App必备依赖) resource "azurerm_storage_account" "example" { name = "examplestoragefunc" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location account_tier = "Standard" account_replication_type = "LRS" } # 启用网络注入的Linux Function App resource "azurerm_linux_function_app" "example" { name = "example-func-app" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location service_plan_id = azurerm_service_plan.example.id storage_account_name = azurerm_storage_account.example.name storage_account_access_key = azurerm_storage_account.example.primary_access_key # 核心网络注入配置 virtual_network_subnet_id = azurerm_subnet.func_injection.id vnet_route_all_enabled = true # 开启全部出站流量走VNet site_config {} }
注意事项
- 消费级SKU的Function App仅支持部分区域的VNet集成,建议优先选择弹性Premium或专用级SKU
- 子网不能同时分配给其他服务,需为Function App VNet集成预留专属子网
- 子网地址段最小为/26(64个IP地址),建议根据实际扩容需求预留足够地址空间
内容的提问来源于stack exchange,提问作者Daniel Vega Ruiz
相关产品推荐
相关产品推荐

