跨租户添加Kusto跟随集群是否可行?PowerShell脚本疑问
跨租户配置Kusto跟随集群的可行性及实现方案
核心结论
跨租户配置Kusto跟随集群是支持的,但默认New-AzKustoAttachedDatabaseConfiguration命令未显式提供租户参数,需通过上下文切换、跨租户权限配置来完成操作。
关键操作步骤
- 配置跨租户权限:在Leader集群所在租户中,为Follower集群的管理身份/服务主体授予
Microsoft.Kusto/clusters/attachedDatabaseConfigurations/write或更宽泛的Kusto资源权限,确保Follower侧有权访问Leader集群。 - 切换PowerShell上下文到Follower租户:
Connect-AzAccount -TenantId <Follower租户ID> Set-AzContext -Subscription <Follower集群订阅ID> -Tenant <Follower租户ID> - 跨租户获取Leader集群资源ID:获取Leader集群信息时需指定其所在租户ID,避免因上下文问题无法访问跨租户资源:
$getleadercluster = Get-AzKustoCluster -Name $LeaderClustername -ResourceGroupName $LeaderClusterResourceGroup -SubscriptionId $LeaderClusterSubscriptionID -TenantId <Leader租户ID> -ErrorAction Stop - 执行附加数据库配置:保留原脚本核心逻辑,确保当前上下文处于Follower租户,且Leader集群资源ID正确、权限配置到位。
修正后的完整示例脚本
# 配置参数 $FollowerClustername = 'myfollower' $FollowerClusterSubscriptionID = '9999999-9999-4e39-a325-5c3385999992' $FollowerResourceGroupName = 'myresourcegroup' $FollowerTenantId = '<Follower租户GUID>' # 新增Follower租户ID $DatabaseName = "master" $LeaderClustername = 'mastercluster' $LeaderClusterSubscriptionID = '11111111-8fb5-4e39-a325-999999999' $LeaderClusterResourceGroup = 'myresourcegroup' $LeaderTenantId = '<Leader租户GUID>' # 新增Leader租户ID $DefaultPrincipalsModificationKind = 'Union' # 切换到Follower租户上下文 Connect-AzAccount -TenantId $FollowerTenantId Set-AzContext -Subscription $FollowerClusterSubscriptionID -Tenant $FollowerTenantId # 获取Leader集群资源(指定Leader租户) $getleadercluster = Get-AzKustoCluster -Name $LeaderClustername -ResourceGroupName $LeaderClusterResourceGroup -SubscriptionId $LeaderClusterSubscriptionID -TenantId $LeaderTenantId -ErrorAction Stop $LeaderClusterResourceid = $getleadercluster.Id $Location = $getleadercluster.Location # 创建附加数据库配置 New-AzKustoAttachedDatabaseConfiguration -ClusterName $FollowerClustername ` -Name "myconfig" ` -ResourceGroupName $FollowerResourceGroupName ` -SubscriptionId $FollowerClusterSubscriptionID ` -DatabaseName $DatabaseName ` -ClusterResourceId $LeaderClusterResourceid ` -DefaultPrincipalsModificationKind $DefaultPrincipalsModificationKind ` -Location $Location ` -TableLevelSharingPropertyMaterializedViewsToInclude "*_view" ` -TableLevelSharingPropertyTablesToInclude "someother" ` -TableLevelSharingPropertyExternalTablesToExclude "*" ` -ErrorAction Stop
注意事项
- 需确保两个租户间网络连通,可通过VNet对等或开放公网访问权限实现。
- 若使用服务主体,需在两个租户中均注册该主体并授予对应权限。
内容的提问来源于stack exchange,提问作者Werner
相关产品推荐
相关产品推荐

