如何部署Azure托管应用代码工件?遇权限及CI/CD问题求助
Azure托管应用CI/CD部署问题及相关脚本
我是Azure托管应用的新手,已创建包含Azure Function、App Service、Azure SQL、KeyVault和Storage的托管应用定义,所有资源均启用托管标识。我已将应用部署到Azure服务目录并创建相关资源,现尝试推送Azure Function、Azure Web App的代码工件并创建数据库结构。
尝试使用拥有Contributor角色的Azure凭据通过GitHub Actions执行CI/CD时,遇到系统拒绝分配问题;也尝试过配置带user_impersonation权限的应用注册,但不清楚资源创建后如何运行CLI脚本。
微软相关文档描述模糊,仅聚焦于定义部署;ChatGPT存在严重AI幻觉问题,提供了不实信息。
Bicep脚本
@description('Location for all resources.') param location string = resourceGroup().location @description('Environment.') param environment string = 'dev-k' @description('The name of the SQL logical server.') param serverName string = uniqueString('sql', resourceGroup().id) @description('The administrator username of the SQL logical server.') param administratorLogin string = 'DbUser' @description('The administrator password of the SQL logical server.') @secure() param administratorLoginPassword string = '@Abcd9090!' @description('The name of the SQL Database.') var uniqueStringVal = '${environment}-${uniqueString(resourceGroup().id)}' var sqlDBName = 'zeis-${uniqueStringVal}' var keyVaultName = 'kv-${uniqueStringVal}' var functionAppName = 'fn-${uniqueStringVal}-ZesEmployeeManagementEmployeeSync' var appServicePlanName = 'appService-${uniqueStringVal}' var storageAccountName = replace('storage-${uniqueStringVal}', '-', '') resource storageAccount 'Microsoft.Storage/storageAccounts@2022-09-01' = { name: storageAccountName location: location sku: { name: 'Standard_LRS' } kind: 'StorageV2' identity: { type: 'SystemAssigned' } properties: { minimumTlsVersion: 'TLS1_2' } } resource appServicePlan 'Microsoft.Web/serverfarms@2023-12-01' = { name: appServicePlanName location: location sku: { name: 'Y1' capacity: 0 size: 'Y' family: 'Y' tier: 'Dynamic' } } resource functionApp 'Microsoft.Web/sites@2023-12-01' = { name: functionAppName location: location kind: 'functionapp' identity: { type: 'SystemAssigned' } properties: { serverFarmId: appServicePlan.id siteConfig: { appSettings: [ { name: 'FUNCTIONS_WORKER_RUNTIME' value: 'dotnet-isolated' } { name: 'AzureWebJobsStorage' value: 'DefaultEndpointsProtocol=https;AccountName=${storageAccount.name};AccountKey=${storageAccount.listKeys().keys[0].value};EndpointSuffix=core.windows.net' } ] } } } resource keyVault 'Microsoft.KeyVault/vaults@2023-07-01' = { name: keyVaultName location: location properties: { tenantId: subscription().tenantId sku: { family: 'A' name: 'standard' } accessPolicies: [] } } resource keyVaultRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = { scope: keyVault name: guid(resourceGroup().id, '${functionAppName}', 'Contributor') properties: { roleDefinitionId: resourceId('Microsoft.Authorization/roleDefinitions', 'b24988ac-6180-42a0-ab88-20f7382dd24c') // Contributor Role principalId: functionApp.identity.principalId } } resource sqlServer 'Microsoft.Sql/servers@2022-05-01-preview' = { name: serverName location: location identity: { type: 'SystemAssigned' } properties: { administratorLogin: administratorLogin administratorLoginPassword: administratorLoginPassword } } resource sqlDB 'Microsoft.Sql/servers/databases@2023-08-01-preview' = { parent: sqlServer name: sqlDBName location: location sku: { name: 'GP_S_Gen5' tier: 'GeneralPurpose' family: 'Gen5' capacity: 1 } identity: { type: 'None' } properties: { collation: 'SQL_Latin1_General_CP1_CI_AS' maxSizeBytes: 34359738368 autoPauseDelay: 60 catalogCollation: 'SQL_Latin1_General_CP1_CI_AS' availabilityZone: 'NoPreference' readScale: 'Disabled' } } // resource symbolicname 'Microsoft.Graph/applications@v1.0' = { // api: { // acceptMappedClaims: true // preAuthorizedApplications: [ // { // appId: 'string' // delegatedPermissionIds: [ // 'string' // ] // } // ] // } // appRoles: [ // { // allowedMemberTypes: [ // 'string' // ] // description: 'string' // displayName: 'string' // id: 'string' // isEnabled: bool // value: 'string' // } // ] // defaultRedirectUri: 'string' // description: 'string' // disabledByMicrosoftStatus: 'string' // displayName: 'string' // groupMembershipClaims: 'string' // identifierUris: [ // 'string' // ] // info: { // marketingUrl: 'string' // privacyStatementUrl: 'string' // supportUrl: 'string' // termsOfServiceUrl: 'string' // } // requestSignatureVerification: { // allowedWeakAlgorithms: 'string' // isSignedRequestRequired: bool // } // requiredResourceAccess: [ // { // resourceAccess: [ // { // id: 'string' // type: 'string' // } // ] // resourceAppId: 'string' // } // ] // samlMetadataUrl: 'string' // serviceManagementReference: 'string' // servicePrincipalLockConfiguration: { // allProperties: bool // credentialsWithUsageSign: bool // credentialsWithUsageVerify: bool // isEnabled: bool // tokenEncryptionKeyId: bool // } // signInAudience: 'string' // spa: { // redirectUris: [ // 'string' // ] // } // tags: [ // 'string' // ] // tokenEncryptionKeyId: 'string' // uniqueName: 'string' // verifiedPublisher: { // displayName: 'devkapp' // verifiedPublisherId: 'string' // } // }
Azure凭据生成脚本
az ad sp create-for-rbac --name "" --role contributor --scopes /subscriptions/$subscriptionId --json-auth
GitHub Actions工作流脚本
name: Deploy DotNet project to Azure Function App on: push: branches: ["main"] env: AZURE_FUNCTIONAPP_NAME: 'fn-dev-k-jziuqfqqrrrci-ZesEmployeeManagementEmployeeSync' # set this to your function app name on Azure AZURE_FUNCTIONAPP_PACKAGE_PATH: './ZesEmployeeManagement' # set this to the path to your function app project, defaults to the repository root DOTNET_VERSION: '8.0.x' # set this to the dotnet version to use (e.g. '2.1.x', '3.1.x', '5.0.x') AZURE_CREDENTIALS: '{"clientId":"","clientSecret":"","tenantId":"", "subscriptionId": ""}' jobs: build-and-deploy: runs-on: windows-latest # For Linux, use ubuntu-latest environment: dev steps: - name: 'Checkout GitHub Action' uses: actions/checkout@v4 - name: Setup DotNet ${{ env.DOTNET_VERSION }} Environment uses: actions/setup-dotnet@v3 with: dotnet-version: ${{ env.DOTNET_VERSION }} - name: 'Resolve Project Dependencies Using Dotnet' shell: powershell # For Linux, use bash run: | pushd './${{ env.AZURE_FUNCTIONAPP_PACKAGE_PATH }}' dotnet build --configuration Release --output ./output popd - name: Log in to Azure uses: azure/login@v2 with: creds: ${{ env.AZURE_CREDENTIALS }} - name: Upload to Blob Storage uses: azure/CLI@v1 with: inlineScript: | az storage blob upload \ --account-name {storage} \ --container-name {container} \ --file functionapp.zip \ --name functionapp.zip \ --auth-mode login # Configure Function App to use the package from Blob Storage - name: Set WEBSITE_RUN_FROM_PACKAGE run: | az webapp config appsettings set \ --name {functionName} \ --resource-group {resourceGroup} \ --settings WEBSITE_RUN_FROM_PACKAGE=https://{storage}.blob.core.windows.net/{container}/functionapp.zip
内容的提问来源于stack exchange,提问作者Khalil
相关产品推荐
相关产品推荐

