You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep创建ADF链接服务缺失encryptedCredential属性致连接失败

问题描述

通过Bicep文件创建Azure Data Factory(ADF)到存储账户的链接服务,部署后测试连接失败。但通过ADF UI手动编辑并选择存储账户后,连接测试正常。对比两者配置发现,UI生成的内容包含encryptedCredential属性。当前使用账户密钥认证,不想将凭据存入密钥保管库或硬编码到Bicep文件中,请问如何通过Bicep部署即可直接生效的链接服务?

相关Bicep代码

主文件代码

module Storage 'linked_services/linked_services.bicep' = {
  name: 'AzureFileStorage'
  params: {
    name: '${factoryName}/AzureFileStorage'
    referenceName: 'STORAGECONNECTION'
    storageType: 'AzureFileStorage'
    typeProperties: {
      connectionString: AzureFileStorage_connectionString
      fileShare: 'datafiles'
    }
  }
  dependsOn: [
    factoryName_STORAGECONNECTION
  ]
}

resource storageAccount 'Microsoft.Storage/storageAccounts@2023-05-01' = {
  name: storageAccountName
  location: location
  tags: {
    Application: tags.Application
    Environment: tags.Environment
  }
  sku: {
    name: 'Standard_LRS'
    tier: 'Standard'
  }
  kind: 'StorageV2'
  properties: {
    publicNetworkAccess: 'Enabled'
    minimumTlsVersion: 'TLS1_2'
    allowBlobPublicAccess: true
    allowSharedKeyAccess: true
    bypass: 'AzureServices'
    defaultAction: 'Deny'
    supportsHttpsTrafficOnly: true
    encryption: {
      services: {
        file: {
          keyType: 'Account'
          enabled: true
        }
        blob: {
          keyType: 'Account'
          enabled: true
        }
      }
      keySource: 'Microsoft.Storage'
    }
    accessTier: 'Hot'
  }
}

resource datafiles 'Microsoft.Storage/storageAccounts/fileServices/shares@2023-05-01' = {
  name: '${storageAccount.name}/default/${storageAccountName}'
  properties: {
    accessTier: 'TransactionOptimized'
    shareQuota: 5120
  }
  dependsOn: [
    storageAccount
  ]
}

linked_services.bicep代码

param referenceName string
param storageType string
param name string
param typeProperties object

resource linkedService 'Microsoft.DataFactory/factories/linkedServices@2018-06-01' = {
  name: name
  properties: {
    type: storageType
    connectVia: {
      referenceName: referenceName
      type: 'IntegrationRuntimeReference'
    }
    typeProperties: typeProperties
  }
}
解决方案

方案1:使用托管身份认证(推荐)

这是无需硬编码密钥、无需依赖encryptedCredential的最佳实践,通过ADF的系统托管身份直接访问存储账户:

  1. 给ADF托管身份分配存储权限
    在主Bicep文件中添加角色分配资源,为ADF的系统托管身份分配存储文件数据参与者角色(该角色拥有文件共享的读写权限):
// 为ADF系统托管身份分配存储账户的文件数据参与者角色
resource adfStorageRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(storageAccount.id, factory.id, 'b7e6dc6d-18f0-45b8-974a-58d759871111')
  scope: storageAccount
  properties: {
    // 存储文件数据参与者角色的固定ID
    roleDefinitionId: '/subscriptions/${subscription().subscriptionId}/providers/Microsoft.Authorization/roleDefinitions/b7e6dc6d-18f0-45b8-974a-58d759871111'
    principalId: factory.identity.principalId
    principalType: 'ServicePrincipal'
  }
  dependsOn: [
    storageAccount
    factory
  ]
}
  1. 修改链接服务配置
    更新主文件中链接服务的typeProperties,使用托管身份认证替代连接字符串:
typeProperties: {
  accountName: storageAccount.name
  fileShare: 'datafiles'
  authenticationType: 'ManagedServiceIdentity'
}
  1. 更新依赖关系
    修改模块的dependsOn,确保角色分配完成后再部署链接服务:
dependsOn: [
  factoryName_STORAGECONNECTION
  adfStorageRoleAssignment
]

方案2:自动生成encryptedCredential(适用于坚持使用账户密钥的场景)

如果必须使用账户密钥认证,需要提前生成encryptedCredential并传入Bicep:

  1. 生成encryptedCredential
    使用Azure CLI命令生成加密后的凭据(替换占位符为实际资源名称):
az datafactory linked-service create --factory-name <你的ADF名称> --name <链接服务名称> --properties '{
  "type": "AzureFileStorage",
  "typeProperties": {
    "connectionString": "<存储账户连接字符串>",
    "fileShare": "datafiles"
  },
  "connectVia": {
    "referenceName": "STORAGECONNECTION",
    "type": "IntegrationRuntimeReference"
  }
}' --query 'properties.typeProperties.encryptedCredential' -o tsv
  1. 传入Bicep配置
    将生成的encryptedCredential值作为参数传入链接服务的typeProperties:
typeProperties: {
  connectionString: AzureFileStorage_connectionString
  fileShare: 'datafiles'
  encryptedCredential: '<生成的加密凭据值>'
}

原因说明

ADF UI在保存链接服务时,会自动调用后台API生成encryptedCredential,对连接字符串进行加密后存储;而直接通过Bicep部署时,如果未提供该属性,ADF无法验证凭据有效性,导致连接测试失败。

内容的提问来源于stack exchange,提问作者user2328273

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 13:05:24