You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改Azure SDK for C++示例以连接至Private Endpoint

使用Azure SDK for C++通过私有端点连接ADLS Gen2存储账户

问题描述

我正在使用Azure SDK for C++,尝试连接至私有端点(Private Endpoint)。我拥有带应用注册密钥的ADLS Gen2存储账户,目前可通过OAuth连接ADLS,请问如何修改以下示例代码以实现私有端点连接?

原示例代码:

// Copyright (c) Microsoft Corporation.
// Licensed under the MIT License.

#include <azure/identity/client_secret_credential.hpp>
#include <azure/service/client.hpp>

#include <iostream>

// The following environment variables must be set before running the sample.
// * AZURE_TENANT_ID: Tenant ID for the Azure account.
// * AZURE_CLIENT_ID: The Client ID to authenticate the request.
// * AZURE_CLIENT_SECRET: The client secret.
std::string GetTenantId() { return std::getenv("AZURE_TENANT_ID"); }
std::string GetClientId() { return std::getenv("AZURE_CLIENT_ID"); }
std::string GetClientSecret() { return std::getenv("AZURE_CLIENT_SECRET"); }

int main()
{
  try
  {
    // Step 1: Initialize Client Secret Credential.
    auto clientSecretCredential = std::make_shared<Azure::Identity::ClientSecretCredential>(
        GetTenantId(), GetClientId(), GetClientSecret());

    // Step 2: Pass the credential to an Azure Service Client.
    Azure::Service::Client azureServiceClient("serviceUrl", clientSecretCredential);

    // Step 3: Start using the Azure Service Client.
    azureServiceClient.DoSomething();

    std::cout << "Success!" << std::endl;
  }
  catch (const Azure::Core::Credentials::AuthenticationException& exception)
  {
    // Step 4: Handle authentication errors, if needed
    // (invalid credential parameters, insufficient permissions).
    std::cout << "Authentication error: " << exception.what() << std::endl;
    return 1;
  }

  return 0;
}

修改方案

要实现私有端点连接,需针对URL、客户端选型和配置做以下关键调整:

1. 替换服务URL为私有端点专属域名

私有端点会为ADLS Gen2存储账户分配私有域名,格式为 <存储账户名>.privatelink.dfs.core.windows.net,将原代码中的占位符serviceUrl替换为该私有域名。

2. 使用ADLS Gen2专属客户端

原示例中的Azure::Service::Client是通用占位类,实际需使用Azure存储SDK提供的DataLakeFileSystemClient或DataLakeServiceClient。

3. 配置客户端选项(可选但推荐)

通过ClientOptions禁用重定向、配置DNS解析策略,确保请求始终路由到私有端点,避免意外跳转到公共网络。

修改后的完整代码

// Copyright (c) Microsoft Corporation.
// Licensed under the MIT License.

#include <azure/identity/client_secret_credential.hpp>
#include <azure/storage/files/datalake.hpp>

#include <iostream>

// 需提前设置以下环境变量
// * AZURE_TENANT_ID: Azure账户租户ID
// * AZURE_CLIENT_ID: 应用注册客户端ID
// * AZURE_CLIENT_SECRET: 应用注册客户端密钥
// * STORAGE_ACCOUNT_NAME: ADLS Gen2存储账户名称
std::string GetTenantId() { return std::getenv("AZURE_TENANT_ID"); }
std::string GetClientId() { return std::getenv("AZURE_CLIENT_ID"); }
std::string GetClientSecret() { return std::getenv("AZURE_CLIENT_SECRET"); }
std::string GetStorageAccountName() { return std::getenv("STORAGE_ACCOUNT_NAME"); }

int main()
{
  try
  {
    // 初始化客户端密钥凭据
    auto clientSecretCredential = std::make_shared<Azure::Identity::ClientSecretCredential>(
        GetTenantId(), GetClientId(), GetClientSecret());

    // 构建私有端点URL
    std::string privateEndpointUrl = "https://" + GetStorageAccountName() + ".privatelink.dfs.core.windows.net";

    // 配置客户端选项,确保请求路由到私有端点
    Azure::Core::ClientOptions clientOptions;
    // 禁用重定向,防止跳转到公共端点
    clientOptions.Retry.DisableRedirects = true;

    // 初始化ADLS Gen2文件系统客户端(替换为你的目标文件系统名称)
    Azure::Storage::Files::DataLake::DataLakeFileSystemClient fileSystemClient(
        privateEndpointUrl + "/your-file-system-name",
        clientSecretCredential,
        Azure::Storage::Files::DataLake::DataLakeClientOptions(clientOptions));

    // 测试连接:获取文件系统属性
    auto properties = fileSystemClient.GetProperties();
    std::cout << "成功连接私有端点!文件系统ETag: " << properties.ETag << std::endl;
  }
  catch (const Azure::Core::Credentials::AuthenticationException& exception)
  {
    std::cout << "认证错误: " << exception.what() << std::endl;
    return 1;
  }
  catch (const Azure::Storage::StorageException& exception)
  {
    std::cout << "存储服务错误: " << exception.what() << std::endl;
    return 1;
  }

  return 0;
}

额外注意事项

  • 运行代码的主机需接入私有端点所在的虚拟网络,或通过VPN/ExpressRoute建立连接,否则无法解析私有端点域名。
  • 存储账户防火墙需配置为允许私有网络流量访问,或直接禁用公共网络访问(仅允许私有端点)。
  • 应用注册需拥有ADLS Gen2的对应权限(如Storage Blob Data Contributor)。

内容的提问来源于stack exchange,提问作者John Doe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 13:39:55