You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于订阅标签配置Azure Policy的技术咨询

解决方案:利用Azure Policy引用订阅标签约束资源配置
  • 核心逻辑:Azure Policy允许直接通过内置表达式读取订阅级标签,无需为资源维护或继承标签,以此作为资源配置校验的基准值。

  • 具体实现方案:

    1. 先确保目标订阅已配置好对应标签(例如Location = North Europe)
    2. 创建自定义Azure Policy,在规则中使用[subscription().tags['Location']]表达式获取订阅标签值,用来约束资源的位置配置
  • 示例Policy定义(强制资源位置匹配订阅Location标签):

    {
      "mode": "Indexed",
      "policyRule": {
        "if": {
          "allOf": [
            {
              "field": "location",
              "notEquals": "[subscription().tags['Location']]"
            },
            {
              "field": "type",
              "notIn": [
                "Microsoft.AzureActiveDirectory/b2cDirectories",
                "Microsoft.Blueprint/blueprints",
                "Microsoft.Blueprint/blueprintAssignments",
                "Microsoft.Compute/virtualMachines/extensions"
                // 按需添加无需校验的资源类型
              ]
            }
          ]
        },
        "then": {
          "effect": "deny"
        }
      },
      "parameters": {}
    }
    
  • 补充说明:

    • 若需避免订阅未设置标签时的误拦截,可在规则中添加标签存在性判断:{ "field": "subscription().tags['Location']", "exists": true }
    • 可将effect调整为audit(仅记录不符合规则的资源)或modify(自动修正资源位置,部分资源类型支持该操作)
    • 该逻辑同样适用于其他订阅标签,只需替换表达式中的标签名称即可

内容的提问来源于stack exchange,提问作者user23587070

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 11:49:50