You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform配置Azure Application Gateway对接ASE托管App Service实现路径路由

解答

认知澄清

  • 你对ASE v3和Swift连接的理解完全正确:ASE v3会将所有绑定的App Service直接部署到你指定的私有子网中,支持通过NSG、路由表实现完全的网络管控;而azurerm_app_service_virtual_network_swift_connection是多租户App Service的VNet集成能力,仅支持App Service访问VNet内资源,不会将App Service本身部署到用户子网中。
  • 你当前的ASE+私有子网+NSG/路由表的部署方案是合理的,逻辑和AWS上私有子网部署业务、公网负载均衡做入口的架构一致,符合Azure PaaS安全部署最佳实践。

方案选型说明

你需要实现基于URL路径的七层流量转发,选择Application Gateway是最优解:

  • Azure Load Balancer是四层负载均衡产品,不支持URL路径、域名等七层路由能力,无法满足你的需求
  • Application Gateway搭配内部ILB模式的ASE v3是官方推荐的公网入口架构,同时支持WAF防护、路径路由、SSL卸载等能力,完全适配你的场景

配置修改步骤(打通Application Gateway与ASE)

1. 新增Application Gateway专属子网

Azure要求Application Gateway必须部署在独立的专属子网,不能与ASE共用子网,最小子网段为/24,在现有VNet下新增子网配置如下:

resource "azurerm_subnet" "agw" {
  name                 = "application-gateway"
  resource_group_name  = azurerm_resource_group.networking.name
  virtual_network_name = azurerm_virtual_network.vnet.name
  address_prefixes     = ["10.1.2.0/24"]
}

修改Application Gateway配置中的网关IP配置,指向该子网:

gateway_ip_configuration {
  name      = "subnet"
  subnet_id = azurerm_subnet.agw.id
}

2. 配置ASE为内部ILB模式(可选但推荐)

如果需要App Service完全无公网暴露,在azurerm_app_service_environment_v3资源中添加内部负载均衡配置:

resource "azurerm_app_service_environment_v3" "frontend" {
  # 原有配置保持不变
  internal_load_balancing_mode = "Web, Publishing"
}

3. 调整Application Gateway后端配置

如果使用ILB模式的ASE,直接将ASE的内部IP作为后端地址,比使用域名更稳定:

backend_address_pool {
  name = "AppService"
  ip_addresses = [azurerm_app_service_environment_v3.frontend.internal_ip_address]
}

4. 优化健康检查与后端设置

调整后端超时时间,开启自动传递Host头:

backend_http_settings {
  name                  = "http"
  cookie_based_affinity = "Disabled"
  port                  = 80
  protocol              = "Http"
  request_timeout       = 30 # 原配置1秒过短,容易触发超时
  probe_name            = "probe"
  pick_host_name_from_backend_address = true # 自动传递Host头到后端App Service
}

5. 配置URL路径路由

将原有的Basic类型路由规则修改为PathBasedRouting,即可实现按路径转发到不同App Service:

# 先新增其他业务对应的后端地址池、健康检查、后端HTTP设置,示例为/api路径转发到API服务
backend_address_pool {
  name = "ApiService"
  ip_addresses = [azurerm_app_service_environment_v3.frontend.internal_ip_address]
}

backend_http_settings {
  name                  = "http-api"
  cookie_based_affinity = "Disabled"
  port                  = 80
  protocol              = "Http"
  request_timeout       = 30
  probe_name            = "api-probe"
  pick_host_name_from_backend_address = true
}

probe {
  name                = "api-probe"
  protocol            = "http"
  path                = "/api/health"
  host                = "${azurerm_app_service.api.name}.azurewebsites.net"
  interval            = 30
  timeout             = 30
  unhealthy_threshold = 3
}

# 修改路由规则为路径路由
request_routing_rule {
  name                       = "http"
  rule_type                  = "PathBasedRouting"
  http_listener_name         = "http"
  backend_address_pool_name  = "AppService" # 根路径默认转发到前端服务
  backend_http_settings_name = "http"

  path_map {
    name = "path-routing"

    path_rule {
      name                       = "api-rule"
      paths                      = ["/api/*"]
      backend_address_pool_name  = "ApiService"
      backend_http_settings_name = "http-api"
    }
    # 可新增更多路径规则对应不同App Service
  }
}

6. 收紧NSG安全规则

将原有放行所有入站的规则修改为仅允许Application Gateway子网访问ASE子网的80端口,避免未授权访问:

resource "azurerm_network_security_group" "frontend" {
  name                = "${local.prefix}-frontend-sg"
  location            = azurerm_resource_group.frontend.location
  resource_group_name = azurerm_resource_group.frontend.name

  security_rule {
    name                       = "allow-agw-inbound"
    priority                   = 100
    direction                  = "Inbound"
    access                     = "Allow"
    protocol                   = "Tcp"
    source_port_range          = "*"
    destination_port_range     = "80"
    source_address_prefix      = azurerm_subnet.agw.address_prefixes[0]
    destination_address_prefix = "*"
  }
}

内容的提问来源于stack exchange,提问作者P09

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 19:15:03