You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中禁用Azure App Configuration的公共访问权限

解决方案

你需要使用v3.0.0及以上版本的azurerm Terraform Provider,azurerm_app_configuration资源内置了public_network_access_enabled参数用于控制公共网络访问权限,将该参数设置为false即可实现禁用公共访问的需求。

完整配置示例

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = ">= 3.0.0"
    }
  }
}

provider "azurerm" {
  features {}
}

# 示例资源组
resource "azurerm_resource_group" "example" {
  name     = "example-resources"
  location = "West Europe"
}

# 禁用公共访问的App Configuration
resource "azurerm_app_configuration" "example" {
  name                       = "example-appconfig"
  resource_group_name        = azurerm_resource_group.example.name
  location                   = azurerm_resource_group.example.location
  sku                        = "standard"
  public_network_access_enabled = false

  # 若需要开启部分公网IP白名单访问,可将上方参数改为true并添加以下配置
  # network_acls {
  #   default_action = "Deny"
  #   allowed_ips = ["你的公网IP段/32"]
  # }
}

# 私有端点配置示例
resource "azurerm_private_endpoint" "example" {
  name                = "example-appconfig-pe"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  subnet_id           = azurerm_subnet.example.id # 替换为你的业务子网资源ID

  private_service_connection {
    name                           = "appconfig-psc"
    private_connection_resource_id = azurerm_app_configuration.example.id
    subresource_names              = ["configurationStores"]
    is_manual_connection           = false
  }
}

注意事项

  • 只有Standard及以上层级的App Configuration资源支持网络访问控制、私有端点和禁用公共访问功能,基础层(Free)sku不支持该配置
  • 配置完成执行terraform apply后,可在Azure门户对应App Configuration的「网络」页中确认公共访问状态

内容的提问来源于stack exchange,提问作者Thanh Nguyen Van

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 14:27:08