如何修改Azure SDK for C++示例以连接至Private Endpoint
使用Azure SDK for C++通过私有端点连接ADLS Gen2存储账户
问题描述
我正在使用Azure SDK for C++,尝试连接至私有端点(Private Endpoint)。我拥有带应用注册密钥的ADLS Gen2存储账户,目前可通过OAuth连接ADLS,请问如何修改以下示例代码以实现私有端点连接?
原示例代码:
// Copyright (c) Microsoft Corporation. // Licensed under the MIT License. #include <azure/identity/client_secret_credential.hpp> #include <azure/service/client.hpp> #include <iostream> // The following environment variables must be set before running the sample. // * AZURE_TENANT_ID: Tenant ID for the Azure account. // * AZURE_CLIENT_ID: The Client ID to authenticate the request. // * AZURE_CLIENT_SECRET: The client secret. std::string GetTenantId() { return std::getenv("AZURE_TENANT_ID"); } std::string GetClientId() { return std::getenv("AZURE_CLIENT_ID"); } std::string GetClientSecret() { return std::getenv("AZURE_CLIENT_SECRET"); } int main() { try { // Step 1: Initialize Client Secret Credential. auto clientSecretCredential = std::make_shared<Azure::Identity::ClientSecretCredential>( GetTenantId(), GetClientId(), GetClientSecret()); // Step 2: Pass the credential to an Azure Service Client. Azure::Service::Client azureServiceClient("serviceUrl", clientSecretCredential); // Step 3: Start using the Azure Service Client. azureServiceClient.DoSomething(); std::cout << "Success!" << std::endl; } catch (const Azure::Core::Credentials::AuthenticationException& exception) { // Step 4: Handle authentication errors, if needed // (invalid credential parameters, insufficient permissions). std::cout << "Authentication error: " << exception.what() << std::endl; return 1; } return 0; }
修改方案
要实现私有端点连接,需针对URL、客户端选型和配置做以下关键调整:
1. 替换服务URL为私有端点专属域名
私有端点会为ADLS Gen2存储账户分配私有域名,格式为 <存储账户名>.privatelink.dfs.core.windows.net,将原代码中的占位符serviceUrl替换为该私有域名。
2. 使用ADLS Gen2专属客户端
原示例中的Azure::Service::Client是通用占位类,实际需使用Azure存储SDK提供的DataLakeFileSystemClient或DataLakeServiceClient。
3. 配置客户端选项(可选但推荐)
通过ClientOptions禁用重定向、配置DNS解析策略,确保请求始终路由到私有端点,避免意外跳转到公共网络。
修改后的完整代码
// Copyright (c) Microsoft Corporation. // Licensed under the MIT License. #include <azure/identity/client_secret_credential.hpp> #include <azure/storage/files/datalake.hpp> #include <iostream> // 需提前设置以下环境变量 // * AZURE_TENANT_ID: Azure账户租户ID // * AZURE_CLIENT_ID: 应用注册客户端ID // * AZURE_CLIENT_SECRET: 应用注册客户端密钥 // * STORAGE_ACCOUNT_NAME: ADLS Gen2存储账户名称 std::string GetTenantId() { return std::getenv("AZURE_TENANT_ID"); } std::string GetClientId() { return std::getenv("AZURE_CLIENT_ID"); } std::string GetClientSecret() { return std::getenv("AZURE_CLIENT_SECRET"); } std::string GetStorageAccountName() { return std::getenv("STORAGE_ACCOUNT_NAME"); } int main() { try { // 初始化客户端密钥凭据 auto clientSecretCredential = std::make_shared<Azure::Identity::ClientSecretCredential>( GetTenantId(), GetClientId(), GetClientSecret()); // 构建私有端点URL std::string privateEndpointUrl = "https://" + GetStorageAccountName() + ".privatelink.dfs.core.windows.net"; // 配置客户端选项,确保请求路由到私有端点 Azure::Core::ClientOptions clientOptions; // 禁用重定向,防止跳转到公共端点 clientOptions.Retry.DisableRedirects = true; // 初始化ADLS Gen2文件系统客户端(替换为你的目标文件系统名称) Azure::Storage::Files::DataLake::DataLakeFileSystemClient fileSystemClient( privateEndpointUrl + "/your-file-system-name", clientSecretCredential, Azure::Storage::Files::DataLake::DataLakeClientOptions(clientOptions)); // 测试连接:获取文件系统属性 auto properties = fileSystemClient.GetProperties(); std::cout << "成功连接私有端点!文件系统ETag: " << properties.ETag << std::endl; } catch (const Azure::Core::Credentials::AuthenticationException& exception) { std::cout << "认证错误: " << exception.what() << std::endl; return 1; } catch (const Azure::Storage::StorageException& exception) { std::cout << "存储服务错误: " << exception.what() << std::endl; return 1; } return 0; }
额外注意事项
- 运行代码的主机需接入私有端点所在的虚拟网络,或通过VPN/ExpressRoute建立连接,否则无法解析私有端点域名。
- 存储账户防火墙需配置为允许私有网络流量访问,或直接禁用公共网络访问(仅允许私有端点)。
- 应用注册需拥有ADLS Gen2的对应权限(如Storage Blob Data Contributor)。
内容的提问来源于stack exchange,提问作者John Doe
相关产品推荐
相关产品推荐

