You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Data Factory实现ADLS文件压缩至云VM并AES加密需求问询

在Azure Data Factory中实现ADLS文件打包、复制、加密全流程

整体流程

先将ADLS中的.dat/.aud文件打包为ZIP,复制到云VM;接着在VM上把ZIP文件加密为.aes格式,最终移动到VM的目标文件夹。以下是具体实现步骤:

步骤1:配置ADF链接服务

  • 创建Azure Data Lake Storage Gen2链接服务,确保ADF可访问目标ADLS文件夹
  • 创建SSH链接服务(Linux VM)或WinRM链接服务(Windows VM),让ADF能远程执行VM上的命令

步骤2:筛选ADLS中的目标文件

  • 使用Get Metadata活动,数据源选择ADLS目标文件夹,勾选Child Items获取所有文件
  • 添加Filter活动,过滤出后缀为.dat或.aud的文件,过滤表达式:
    @or(endswith(item().name, '.dat'), endswith(item().name, '.aud'))
    

步骤3:打包文件为ZIP(两种可选方案)

方案A:先复制到VM再打包(推荐,操作更简单)

  1. 用Copy Activity将筛选后的.dat/.aud文件全部复制到VM临时目录(如Linux的/tmp/source/,Windows的C:\temp\source\)
  2. 通过Execute Command活动在VM上执行压缩命令:
    • Linux环境:
      zip -j /tmp/output/batch.zip /tmp/source/*.dat /tmp/source/*.aud
      
      (-j参数忽略目录结构,仅打包文件本身)
    • Windows环境:
      Compress-Archive -Path "C:\temp\source\*.dat","C:\temp\source\*.aud" -DestinationPath "C:\temp\output\batch.zip"
      

方案B:ADF侧通过Azure Function打包

若VM临时空间不足,可部署Azure Function完成打包:

  • 编写Python/PowerShell函数,接收ADLS文件列表,下载后打包为ZIP再上传回ADLS临时目录
  • 核心Python代码片段:
    from azure.storage.filedatalake import DataLakeServiceClient
    import zipfile
    import io
    from datetime import datetime
    
    def main(req):
        adls_conn_str = req.params.get('conn_str')
        container = req.params.get('container')
        file_list = req.get_json()['files']
        zip_name = f"batch_{datetime.utcnow().strftime('%Y%m%d%H%M%S')}.zip"
    
        client = DataLakeServiceClient.from_connection_string(adls_conn_str)
        zip_buffer = io.BytesIO()
    
        with zipfile.ZipFile(zip_buffer, 'w', zipfile.ZIP_DEFLATED) as zf:
            for file_path in file_list:
                file_client = client.get_file_client(container, file_path)
                zf.writestr(file_path.split('/')[-1], file_client.download_file().read())
    
        zip_buffer.seek(0)
        client.get_file_client(container, f"temp/{zip_name}").upload_data(zip_buffer, overwrite=True)
        return {"zip_path": f"temp/{zip_name}"}
    
  • 用ADF的Azure Function活动调用该函数,拿到生成的ZIP路径后,通过Copy Activity复制到VM

步骤4:AES加密并移动文件

通过Execute Command活动在VM上执行加密+移动命令:

Linux VM(使用openssl)

# AES-256加密,密码从ADF参数/Key Vault获取
openssl enc -aes-256-cbc -salt -in /tmp/output/batch.zip -out /tmp/encrypted/batch.zip.aes -pass pass:${ADF_PASSWORD_PARAM}

# 移动加密文件到目标目录,清理临时文件
mv /tmp/encrypted/batch.zip.aes /data/final_encrypted/
rm /tmp/output/batch.zip /tmp/source/*

Windows VM(使用PowerShell)

$password = ConvertTo-SecureString "${ADF_PASSWORD_PARAM}" -AsPlainText -Force
$aes = New-Object System.Security.Cryptography.AesManaged
$aes.GenerateKey()
$aes.GenerateIV()

# 执行加密
$inputStream = [System.IO.File]::OpenRead("C:\temp\output\batch.zip")
$outputStream = [System.IO.File]::Create("C:\temp\encrypted\batch.zip.aes")
$cryptoStream = New-Object System.Security.Cryptography.CryptoStream($outputStream, $aes.CreateEncryptor($aes.Key, $aes.IV), [System.Security.Cryptography.CryptoStreamMode]::Write)
$inputStream.CopyTo($cryptoStream)

# 关闭流
$cryptoStream.FlushFinalBlock()
$inputStream.Close()
$outputStream.Close()

# 移动文件并清理临时数据
Move-Item -Path "C:\temp\encrypted\batch.zip.aes" -Destination "C:\data\final_encrypted\"
Remove-Item -Path "C:\temp\output\batch.zip" -Force
Remove-Item -Path "C:\temp\source\*" -Force

关键注意事项

  • 确保VM端口(Linux的22,Windows的5985/5986)对ADF开放,或使用自托管集成Runtime部署在VM所在VNet内,避免网络访问问题
  • 密码等敏感信息不要硬编码,存储在Azure Key Vault中,通过ADF参数引用
  • 打包文件名可添加时间戳(如batch_202405201430.zip),避免重名覆盖
  • 添加If Condition活动判断筛选后的文件列表是否为空,防止空执行报错

内容的提问来源于stack exchange,提问作者sameer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 14:50:02