Azure ARM模板获取App Service出站IP配置MySQL防火墙规则报错求解
问题根因
ARM模板的parameters仅支持传入部署前可确定的静态值,不支持reference这类运行时执行的动态函数。你将获取出站IP的split逻辑放在parameter定义中,ARM无法在参数校验阶段正确执行该表达式,导致最终拿到的不是拆分后的IP字符串数组,每个IP值被额外包裹了方括号,不符合MySQL防火墙规则要求的纯IP格式,所以触发InvalidParameterValue错误。
修复步骤
- 第一步:将出站IP的获取逻辑从parameters迁移到variables中,variables支持运行时动态计算的表达式
"variables": { "webAppOutboundIpAddresses": "[split(reference(concat('Microsoft.Web/sites/', parameters('wpsitename'))).properties.possibleOutboundIpAddresses, ',')]" }
- 第二步:修改防火墙规则资源中的取值逻辑,将原
parameters('webAppOutboundIpAddresses')替换为variables('webAppOutboundIpAddresses'),同时添加对App Service的部署依赖,确保获取IP时App Service已经部署完成
{ "type": "Microsoft.DBforMySQL/servers/firewallRules", "apiVersion": "2017-12-01", "name": "[concat(parameters('sqlServerName'), '/Allow WebApp Outbound IP ', copyIndex('webAppOutboundIPAddressesCopy'))]", "dependsOn": [ "[concat('Microsoft.Web/sites/', parameters('wpsitename'))]" ], "properties": { "startIpAddress": "[variables('webAppOutboundIpAddresses')[copyIndex('webAppOutboundIPAddressesCopy')]]", "endIpAddress": "[variables('webAppOutboundIpAddresses')[copyIndex('webAppOutboundIPAddressesCopy')]]" }, "copy": { "name": "webAppOutboundIPAddressesCopy", "count": "[length(variables('webAppOutboundIpAddresses'))]" } }
内容的提问来源于stack exchange,提问作者Arun Pillai
相关产品推荐
相关产品推荐

