You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨租户添加Kusto跟随集群是否可行?PowerShell脚本疑问

跨租户配置Kusto跟随集群的可行性及实现方案

核心结论

跨租户配置Kusto跟随集群是支持的,但默认New-AzKustoAttachedDatabaseConfiguration命令未显式提供租户参数,需通过上下文切换、跨租户权限配置来完成操作。

关键操作步骤

  • 配置跨租户权限:在Leader集群所在租户中,为Follower集群的管理身份/服务主体授予Microsoft.Kusto/clusters/attachedDatabaseConfigurations/write或更宽泛的Kusto资源权限,确保Follower侧有权访问Leader集群。
  • 切换PowerShell上下文到Follower租户:
    Connect-AzAccount -TenantId <Follower租户ID>
    Set-AzContext -Subscription <Follower集群订阅ID> -Tenant <Follower租户ID>
    
  • 跨租户获取Leader集群资源ID:获取Leader集群信息时需指定其所在租户ID,避免因上下文问题无法访问跨租户资源:
    $getleadercluster = Get-AzKustoCluster -Name $LeaderClustername -ResourceGroupName $LeaderClusterResourceGroup -SubscriptionId $LeaderClusterSubscriptionID -TenantId <Leader租户ID> -ErrorAction Stop
    
  • 执行附加数据库配置:保留原脚本核心逻辑,确保当前上下文处于Follower租户,且Leader集群资源ID正确、权限配置到位。

修正后的完整示例脚本

# 配置参数
$FollowerClustername = 'myfollower'
$FollowerClusterSubscriptionID = '9999999-9999-4e39-a325-5c3385999992'
$FollowerResourceGroupName = 'myresourcegroup'
$FollowerTenantId = '<Follower租户GUID>' # 新增Follower租户ID

$DatabaseName = "master"  
$LeaderClustername = 'mastercluster'
$LeaderClusterSubscriptionID = '11111111-8fb5-4e39-a325-999999999'
$LeaderClusterResourceGroup = 'myresourcegroup'
$LeaderTenantId = '<Leader租户GUID>' # 新增Leader租户ID

$DefaultPrincipalsModificationKind = 'Union'

# 切换到Follower租户上下文
Connect-AzAccount -TenantId $FollowerTenantId
Set-AzContext -Subscription $FollowerClusterSubscriptionID -Tenant $FollowerTenantId

# 获取Leader集群资源(指定Leader租户)
$getleadercluster = Get-AzKustoCluster -Name $LeaderClustername -ResourceGroupName $LeaderClusterResourceGroup -SubscriptionId $LeaderClusterSubscriptionID -TenantId $LeaderTenantId -ErrorAction Stop
$LeaderClusterResourceid = $getleadercluster.Id
$Location = $getleadercluster.Location

# 创建附加数据库配置
New-AzKustoAttachedDatabaseConfiguration -ClusterName $FollowerClustername `
    -Name  "myconfig" `
    -ResourceGroupName $FollowerResourceGroupName `
    -SubscriptionId $FollowerClusterSubscriptionID `
    -DatabaseName $DatabaseName `
    -ClusterResourceId $LeaderClusterResourceid `
    -DefaultPrincipalsModificationKind $DefaultPrincipalsModificationKind `
    -Location $Location `
    -TableLevelSharingPropertyMaterializedViewsToInclude "*_view"  `
    -TableLevelSharingPropertyTablesToInclude "someother" `
    -TableLevelSharingPropertyExternalTablesToExclude "*" `
    -ErrorAction Stop

注意事项

  • 需确保两个租户间网络连通,可通过VNet对等或开放公网访问权限实现。
  • 若使用服务主体,需在两个租户中均注册该主体并授予对应权限。

内容的提问来源于stack exchange,提问作者Werner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 01:52:39