如何在Terraform中禁用Azure App Configuration的公共访问权限
解决方案
你需要使用v3.0.0及以上版本的azurerm Terraform Provider,azurerm_app_configuration资源内置了public_network_access_enabled参数用于控制公共网络访问权限,将该参数设置为false即可实现禁用公共访问的需求。
完整配置示例
terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = ">= 3.0.0" } } } provider "azurerm" { features {} } # 示例资源组 resource "azurerm_resource_group" "example" { name = "example-resources" location = "West Europe" } # 禁用公共访问的App Configuration resource "azurerm_app_configuration" "example" { name = "example-appconfig" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location sku = "standard" public_network_access_enabled = false # 若需要开启部分公网IP白名单访问,可将上方参数改为true并添加以下配置 # network_acls { # default_action = "Deny" # allowed_ips = ["你的公网IP段/32"] # } } # 私有端点配置示例 resource "azurerm_private_endpoint" "example" { name = "example-appconfig-pe" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location subnet_id = azurerm_subnet.example.id # 替换为你的业务子网资源ID private_service_connection { name = "appconfig-psc" private_connection_resource_id = azurerm_app_configuration.example.id subresource_names = ["configurationStores"] is_manual_connection = false } }
注意事项
- 只有Standard及以上层级的App Configuration资源支持网络访问控制、私有端点和禁用公共访问功能,基础层(Free)sku不支持该配置
- 配置完成执行
terraform apply后,可在Azure门户对应App Configuration的「网络」页中确认公共访问状态
内容的提问来源于stack exchange,提问作者Thanh Nguyen Van
相关产品推荐
相关产品推荐

