You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot迁移Azure:R2DBC场景下访问令牌自动管理方案咨询

解决方案:使用Azure托管标识自动获取并刷新R2DBC访问令牌

因为你无法获取Client Secrets,**Azure托管标识(Managed Identity)**是最适合的无密码方案,它能让应用在Azure内部自动获取令牌,无需手动维护密钥,同时自动处理令牌刷新。以下是具体实现步骤:


1. 配置Azure托管标识

  • 登录Azure门户,找到你的应用服务(或VM/AKS等部署资源),在标识选项卡中启用系统分配托管标识。
  • 给该托管标识授予数据库的访问权限:
    • 以Azure SQL为例:先在数据库的安全性 > Active Directory管理员中设置AAD管理员,再执行SQL创建用户并授权:
      CREATE USER [你的应用服务名称] FROM EXTERNAL PROVIDER;
      ALTER ROLE db_datareader ADD MEMBER [你的应用服务名称];
      ALTER ROLE db_datawriter ADD MEMBER [你的应用服务名称];
      

2. 添加依赖

在pom.xml中添加Spring Azure和R2DBC相关依赖(根据你的数据库调整驱动):

<dependencies>
    <!-- Spring Azure 托管标识支持 -->
    <dependency>
        <groupId>com.azure.spring</groupId>
        <artifactId>spring-cloud-azure-starter</artifactId>
        <version>4.15.0</version> <!-- 使用最新稳定版 -->
    </dependency>
    <!-- R2DBC 核心 -->
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-data-r2dbc</artifactId>
    </dependency>
    <!-- 数据库R2DBC驱动,以SQL Server为例 -->
    <dependency>
        <groupId>com.microsoft.sqlserver</groupId>
        <artifactId>mssql-r2dbc</artifactId>
        <version>1.3.5</version>
    </dependency>
</dependencies>

3. 配置应用

修改application.yml,无需手动配置password,启用托管标识即可:

spring:
  r2dbc:
    url: r2dbc:sqlserver://<你的数据库主机>:1433;databaseName=<你的数据库名称>
    username: <托管标识的客户端ID> # 可在Azure门户的托管标识详情页获取
azure:
  credential:
    managed-identity-enabled: true

4. 实现自动令牌刷新的R2DBC连接工厂

创建配置类,动态获取最新令牌作为密码,确保每次连接都使用有效令牌:

import com.azure.identity.DefaultAzureCredential;
import com.azure.identity.DefaultAzureCredentialBuilder;
import io.r2dbc.spi.ConnectionFactory;
import io.r2dbc.spi.ConnectionFactoryOptions;
import io.r2dbc.spi.ConnectionFactories;
import org.springframework.boot.autoconfigure.r2dbc.R2dbcProperties;
import org.springframework.boot.context.properties.EnableConfigurationProperties;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.r2dbc.connection.lookup.AbstractRoutingConnectionFactory;
import reactor.core.publisher.Mono;

import java.util.Map;

@Configuration
@EnableConfigurationProperties(R2dbcProperties.class)
public class R2dbcManagedIdentityConfig {

    private final R2dbcProperties r2dbcProperties;
    private final DefaultAzureCredential azureCredential;

    public R2dbcManagedIdentityConfig(R2dbcProperties r2dbcProperties) {
        this.r2dbcProperties = r2dbcProperties;
        // 自动使用托管标识获取令牌
        this.azureCredential = new DefaultAzureCredentialBuilder().build();
    }

    @Bean
    public ConnectionFactory connectionFactory() {
        return new TokenRefreshingConnectionFactory();
    }

    private class TokenRefreshingConnectionFactory extends AbstractRoutingConnectionFactory {

        @Override
        protected Mono<Object> determineCurrentLookupKey() {
            // 每次获取连接时,请求最新的访问令牌
            return Mono.fromCompletionStage(azureCredential.getToken(
                    new com.azure.core.credential.TokenRequestContext()
                            .addScopes("https://database.windows.net/.default") // Azure SQL的权限范围,其他数据库需调整
            )).map(token -> {
                // 用最新令牌构建连接工厂
                ConnectionFactory delegate = ConnectionFactories.get(
                        ConnectionFactoryOptions.builder()
                                .from(ConnectionFactoryOptions.parse(r2dbcProperties.getUrl()))
                                .option(ConnectionFactoryOptions.USER, r2dbcProperties.getUsername())
                                .option(ConnectionFactoryOptions.PASSWORD, token.getToken())
                                .build()
                );
                setTargetConnectionFactories(Map.of(token, delegate));
                return token;
            });
        }
    }
}

关键说明

  • 令牌自动刷新:DefaultAzureCredential会自动处理令牌的缓存和刷新,过期前会自动获取新令牌,无需手动干预。
  • 无密码特性:整个流程不需要Client Secrets,完全依赖Azure托管标识的身份验证,符合你的权限限制。
  • 数据库适配:如果使用PostgreSQL/MySQL on Azure,需要调整权限范围(scope)和驱动依赖,比如PostgreSQL的scope是https://ossrdbms-aad.database.windows.net/.default。

内容的提问来源于stack exchange,提问作者Darin Soeung

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 18:53:19