通过Terraform中ARM模板部署的Logic App如何自动绑定API连接
问题原因
你遇到的需要手动更新Logic App连接的问题核心有2个:
- 创建
Microsoft.Web/connections类型的API连接时,没有传入连接要求的完整身份验证参数(比如Event Hub的连接字符串、Log Analytics的共享密钥),导致连接创建后实际处于未授权状态,需要手动补全凭据 - Logic App工作流配置中的连接引用键名、连接ID和实际创建的连接资源属性不匹配,且连接ID硬编码没有和前置连接资源做动态关联,导致引用失效
解决方法
按以下步骤调整配置即可实现自动化配置,无需后续手动更新:
1. 完善API连接的身份验证配置
在连接的ARM模板中补充对应连接器要求的敏感/非敏感参数,完成预授权
2. 给连接部署添加output输出资源ID,动态传递给Logic App
避免硬编码连接ID导致的路径不匹配问题,同时添加依赖确保连接创建完成后再部署Logic App
3. 修正工作流中连接引用的键名,确保和$connections配置中的键名完全匹配
修正后完整配置示例
// 定义敏感变量,建议实际使用时对接Azure Key Vault存储凭据 variable "eventhub_connection_string" { type = string sensitive = true } variable "log_analytics_shared_key" { type = string sensitive = true } variable "resource_group_name" { type = string default = "Resourcegrpname" } variable "location" { type = string default = "qwerty" } variable "subscription_id" { type = string default = "1111" } // 第一个连接:Event Hubs resource "azurerm_template_deployment" "exampleeventhub" { name = "acctesttemplate-44" resource_group_name = var.resource_group_name template_body = <<DEPLOY { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "connections_eventhubs_name": { "defaultValue": "eventhubs", "type": "String" }, "eventhub_connection_string": { "type": "SecureString" } }, "resources": [ { "type": "Microsoft.Web/connections", "apiVersion": "2016-06-01", "name": "[parameters('connections_eventhubs_name')]", "location": "${var.location}", "kind": "V1", "properties": { "displayName": "eventhubconnection", "customParameterValues": { "connectionString": "[parameters('eventhub_connection_string')]" }, "api": { "name": "[parameters('connections_eventhubs_name')]", "id": "[concat('/subscriptions/${var.subscription_id}/providers/Microsoft.Web/locations/${var.location}/managedApis/', parameters('connections_eventhubs_name'))]", "type": "Microsoft.Web/locations/managedApis" } } } ], "outputs": { "eventhub_connection_id": { "type": "String", "value": "[resourceId('Microsoft.Web/connections', parameters('connections_eventhubs_name'))]" } } } DEPLOY parameters = { eventhub_connection_string = var.eventhub_connection_string } deployment_mode = "Incremental" } // 第二个连接:Log Analytics Data Collector resource "azurerm_template_deployment" "exampledatacollector" { name = "acctesttemplate-45" resource_group_name = var.resource_group_name template_body = <<DEPLOY { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "connections_thengadatacollector_name": { "defaultValue": "thengadatacollector", "type": "String" }, "log_analytics_workspace_id": { "type": "String" }, "log_analytics_shared_key": { "type": "SecureString" } }, "resources": [ { "type": "Microsoft.Web/connections", "apiVersion": "2016-06-01", "name": "[parameters('connections_thengadatacollector_name')]", "location": "${var.location}", "kind": "V1", "properties": { "displayName": "azuredatacollector", "nonSecretParameterValues": { "username": "[parameters('log_analytics_workspace_id')]" }, "customParameterValues": { "password": "[parameters('log_analytics_shared_key')]" }, "api": { "name": "[parameters('connections_thengadatacollector_name')]", "id": "[concat('/subscriptions/${var.subscription_id}/providers/Microsoft.Web/locations/${var.location}/managedApis/', parameters('connections_thengadatacollector_name'))]", "type": "Microsoft.Web/locations/managedApis" } } } ], "outputs": { "datacollector_connection_id": { "type": "String", "value": "[resourceId('Microsoft.Web/connections', parameters('connections_thengadatacollector_name'))]" } } } DEPLOY parameters = { log_analytics_workspace_id = "764a2b1e-431d-4e90-87b1-ea6a34dac48f" log_analytics_shared_key = var.log_analytics_shared_key } deployment_mode = "Incremental" } // Logic App资源 resource "azurerm_template_deployment" "example" { name = "acctesttemplate-46" resource_group_name = var.resource_group_name // 依赖前置连接资源创建完成再部署 depends_on = [ azurerm_template_deployment.exampleeventhub, azurerm_template_deployment.exampledatacollector ] template_body = <<DEPLOY { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "workflows_logicapp_name": { "defaultValue": "logicapp", "type": "String" }, "connections_thengadatacollector_externalid": { "type": "String" }, "connections_eventhubs_externalid": { "type": "String" } }, "resources": [ { "type": "Microsoft.Logic/workflows", "apiVersion": "2017-07-01", "name": "[parameters('workflows_logicapp_name')]", "location": "${var.location}", "properties": { "state": "Enabled", "definition": { "$schema": "https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#", "contentVersion": "1.0.0.0", "parameters": { "$connections": { "defaultValue": {}, "type": "Object" } }, "triggers": { "When_events_are_available_in_Event_Hub": { "recurrence": { "frequency": "Minute", "interval": 3 }, "splitOn": "@triggerBody()", "type": "ApiConnection", "inputs": { "host": { "connection": { "name": "@parameters('$connections')['eventhubs']['connectionId']" } }, "method": "get", "path": "/@{encodeURIComponent('thengaeventhub')}/events/batch/head", "queries": { "contentType": "application/octet-stream", "maximumEventsCount": 50 } } } }, "actions": { "Send_Data_2": { "runAfter": {}, "type": "ApiConnection", "inputs": { "body": "@base64ToString(triggerBody()?['ContentData'])", "headers": { "Log-Type": "testcustimlog" }, "host": { "connection": { "name": "@parameters('$connections')['thengadatacollector']['connectionId']" } }, "method": "post", "path": "/api/logs" } } } }, "parameters": { "$connections": { "value": { "thengadatacollector": { "connectionId": "[parameters('connections_thengadatacollector_externalid')]", "connectionName": "thengadatacollector", "id": "/subscriptions/${var.subscription_id}/providers/Microsoft.Web/locations/${var.location}/managedApis/thengadatacollector" }, "eventhubs": { "connectionId": "[parameters('connections_eventhubs_externalid')]", "connectionName": "eventhubs", "id": "/subscriptions/${var.subscription_id}/providers/Microsoft.Web/locations/${var.location}/managedApis/eventhubs" } } } } } } ] } DEPLOY parameters = { // 动态传入前置连接资源的实际ID connections_thengadatacollector_externalid = azurerm_template_deployment.exampledatacollector.outputs.datacollector_connection_id.value connections_eventhubs_externalid = azurerm_template_deployment.exampleeventhub.outputs.eventhub_connection_id.value } deployment_mode = "Incremental" }
注意事项
- 所有schema地址需要加双引号,否则会导致ARM模板解析错误
- 工作流中引用的连接键名需要和
$connections.value下的键名完全一致,原配置中多了_1后缀会导致引用不匹配 - 敏感参数需要标记为sensitive,避免明文泄露到Terraform状态文件之外的地方
内容的提问来源于stack exchange,提问作者VVN
相关产品推荐
相关产品推荐

