如何用Terraform配置Azure Application Gateway对接ASE托管App Service实现路径路由
解答
认知澄清
- 你对ASE v3和Swift连接的理解完全正确:ASE v3会将所有绑定的App Service直接部署到你指定的私有子网中,支持通过NSG、路由表实现完全的网络管控;而
azurerm_app_service_virtual_network_swift_connection是多租户App Service的VNet集成能力,仅支持App Service访问VNet内资源,不会将App Service本身部署到用户子网中。 - 你当前的ASE+私有子网+NSG/路由表的部署方案是合理的,逻辑和AWS上私有子网部署业务、公网负载均衡做入口的架构一致,符合Azure PaaS安全部署最佳实践。
方案选型说明
你需要实现基于URL路径的七层流量转发,选择Application Gateway是最优解:
- Azure Load Balancer是四层负载均衡产品,不支持URL路径、域名等七层路由能力,无法满足你的需求
- Application Gateway搭配内部ILB模式的ASE v3是官方推荐的公网入口架构,同时支持WAF防护、路径路由、SSL卸载等能力,完全适配你的场景
配置修改步骤(打通Application Gateway与ASE)
1. 新增Application Gateway专属子网
Azure要求Application Gateway必须部署在独立的专属子网,不能与ASE共用子网,最小子网段为/24,在现有VNet下新增子网配置如下:
resource "azurerm_subnet" "agw" { name = "application-gateway" resource_group_name = azurerm_resource_group.networking.name virtual_network_name = azurerm_virtual_network.vnet.name address_prefixes = ["10.1.2.0/24"] }
修改Application Gateway配置中的网关IP配置,指向该子网:
gateway_ip_configuration { name = "subnet" subnet_id = azurerm_subnet.agw.id }
2. 配置ASE为内部ILB模式(可选但推荐)
如果需要App Service完全无公网暴露,在azurerm_app_service_environment_v3资源中添加内部负载均衡配置:
resource "azurerm_app_service_environment_v3" "frontend" { # 原有配置保持不变 internal_load_balancing_mode = "Web, Publishing" }
3. 调整Application Gateway后端配置
如果使用ILB模式的ASE,直接将ASE的内部IP作为后端地址,比使用域名更稳定:
backend_address_pool { name = "AppService" ip_addresses = [azurerm_app_service_environment_v3.frontend.internal_ip_address] }
4. 优化健康检查与后端设置
调整后端超时时间,开启自动传递Host头:
backend_http_settings { name = "http" cookie_based_affinity = "Disabled" port = 80 protocol = "Http" request_timeout = 30 # 原配置1秒过短,容易触发超时 probe_name = "probe" pick_host_name_from_backend_address = true # 自动传递Host头到后端App Service }
5. 配置URL路径路由
将原有的Basic类型路由规则修改为PathBasedRouting,即可实现按路径转发到不同App Service:
# 先新增其他业务对应的后端地址池、健康检查、后端HTTP设置,示例为/api路径转发到API服务 backend_address_pool { name = "ApiService" ip_addresses = [azurerm_app_service_environment_v3.frontend.internal_ip_address] } backend_http_settings { name = "http-api" cookie_based_affinity = "Disabled" port = 80 protocol = "Http" request_timeout = 30 probe_name = "api-probe" pick_host_name_from_backend_address = true } probe { name = "api-probe" protocol = "http" path = "/api/health" host = "${azurerm_app_service.api.name}.azurewebsites.net" interval = 30 timeout = 30 unhealthy_threshold = 3 } # 修改路由规则为路径路由 request_routing_rule { name = "http" rule_type = "PathBasedRouting" http_listener_name = "http" backend_address_pool_name = "AppService" # 根路径默认转发到前端服务 backend_http_settings_name = "http" path_map { name = "path-routing" path_rule { name = "api-rule" paths = ["/api/*"] backend_address_pool_name = "ApiService" backend_http_settings_name = "http-api" } # 可新增更多路径规则对应不同App Service } }
6. 收紧NSG安全规则
将原有放行所有入站的规则修改为仅允许Application Gateway子网访问ASE子网的80端口,避免未授权访问:
resource "azurerm_network_security_group" "frontend" { name = "${local.prefix}-frontend-sg" location = azurerm_resource_group.frontend.location resource_group_name = azurerm_resource_group.frontend.name security_rule { name = "allow-agw-inbound" priority = 100 direction = "Inbound" access = "Allow" protocol = "Tcp" source_port_range = "*" destination_port_range = "80" source_address_prefix = azurerm_subnet.agw.address_prefixes[0] destination_address_prefix = "*" } }
内容的提问来源于stack exchange,提问作者P09
相关产品推荐
相关产品推荐

