You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Key Vault自动化创建配置及秘钥存储需求咨询

Azure Key Vault 自动化实现步骤

步骤1:在指定订阅和资源组创建Key Vault

方法1:使用Azure CLI

# 切换到目标订阅
az account set --subscription "你的订阅ID/订阅名称"

# 若资源组不存在,先创建资源组
az group create --name "你的资源组名称" --location "你的区域(如eastus)"

# 创建Key Vault
az keyvault create --name "你的Key Vault名称" --resource-group "你的资源组名称" --location "你的区域" --sku standard

方法2:使用PowerShell

# 切换到目标订阅
Set-AzContext -Subscription "你的订阅ID/订阅名称"

# 若资源组不存在,先创建资源组
New-AzResourceGroup -Name "你的资源组名称" -Location "你的区域"

# 创建Key Vault
New-AzKeyVault -VaultName "你的Key Vault名称" -ResourceGroupName "你的资源组名称" -Location "你的区域" -Sku Standard

步骤2:读取Excel中的密码并存储为Key Vault密钥

使用PowerShell结合ImportExcel模块实现(仅首次运行需安装模块):

# 安装ImportExcel模块
Install-Module -Name ImportExcel -Scope CurrentUser -Force

# 读取Excel文件(假设Excel包含两列:SecretName(密钥名称)、SecretValue(密码值))
$excelData = Import-Excel -Path "你的Excel文件路径(如C:\secrets.xlsx)"

# 循环将密码存入Key Vault
foreach ($item in $excelData) {
    Set-AzKeyVaultSecret -VaultName "你的Key Vault名称" -Name $item.SecretName -SecretValue (ConvertTo-SecureString $item.SecretValue -AsPlainText -Force)
}

步骤3:配置Key Vault允许应用获取密钥

方法1:使用Azure CLI

# 获取应用的服务主体ID(替换为你的应用名称)
sp_id=$(az ad sp list --display-name "你的应用名称" --query "[0].id" -o tsv)

# 为应用添加Key Vault访问策略,允许获取密钥
az keyvault set-policy --name "你的Key Vault名称" --resource-group "你的资源组名称" --object-id $sp_id --secret-permissions get

方法2:使用PowerShell

# 获取应用的服务主体ID(替换为你的应用名称)
$sp = Get-AzADServicePrincipal -DisplayName "你的应用名称"

# 为应用添加Key Vault访问策略,允许获取密钥
Set-AzKeyVaultAccessPolicy -VaultName "你的Key Vault名称" -ObjectId $sp.Id -PermissionsToSecrets Get

内容的提问来源于stack exchange,提问作者AskMe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 03:22:34