You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure容器注册表Webhook推送至Linux应用服务的非基本认证方式咨询

Azure容器注册表Webhook替代基本认证的方案

除了Kudu基本认证,你可以通过系统托管身份或**Entra ID服务主体(应用注册)**实现ACR Webhook到App Service Kudu端点的认证,以下是具体实现步骤及Terraform配置:


一、使用系统托管身份认证

1. 为ACR启用系统托管身份

ACR的系统托管身份需要Premium SKU支持,先开启身份:

resource "azurerm_container_registry" "cr_mycontainerregistry" {
  name                = "mycontainerregistry"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  sku                 = "Premium"

  identity {
    type = "SystemAssigned"
  }
}

2. 为ACR身份分配Kudu访问权限

给ACR的系统身份授予Website Contributor角色,使其有权调用Kudu的Webhook端点:

resource "azurerm_role_assignment" "acr_webhook_kudu_access" {
  scope                = azurerm_linux_web_app.webapp_myapp.id
  role_definition_name = "Website Contributor"
  principal_id         = azurerm_container_registry.cr_mycontainerregistry.identity[0].principal_id
}

3. 配置Webhook使用系统身份

修改Webhook配置,添加身份块指定使用ACR的系统托管身份,无需在URI中携带用户名密码:

resource "azurerm_container_registry_webhook" "cr_webhook_myapp" {
  name                = "myappnamewebhook"
  resource_group_name = azurerm_container_registry.cr_mycontainerregistry.resource_group_name
  registry_name       = azurerm_container_registry.cr_mycontainerregistry.name
  location            = azurerm_container_registry.cr_mycontainerregistry.location

  service_uri = "https://${azurerm_linux_web_app.webapp_myapp.name}.scm.azurewebsites.net/api/registry/webhook"

  status      = "enabled"
  scope       = "myapp:latest"
  actions     = ["push"]
  
  identity {
    type         = "SystemAssigned"
    identity_ids = [azurerm_container_registry.cr_mycontainerregistry.id]
  }

  tags = {
    source = "terraform"
  }
}

二、使用Entra ID服务主体认证

1. 创建服务主体(应用注册)

创建用于Webhook认证的服务主体:

resource "azuread_application" "webhook_sp" {
  display_name = "acr-webhook-kudu-sp"
}

resource "azuread_service_principal" "webhook_sp" {
  client_id = azuread_application.webhook_sp.client_id
}

resource "azuread_service_principal_password" "webhook_sp" {
  service_principal_id = azuread_service_principal.webhook_sp.id
  end_date             = timeadd(timestamp(), "8760h") # 有效期1年
}

2. 为服务主体分配Kudu访问权限

同样授予Website Contributor角色:

resource "azurerm_role_assignment" "sp_kudu_access" {
  scope                = azurerm_linux_web_app.webapp_myapp.id
  role_definition_name = "Website Contributor"
  principal_id         = azuread_service_principal.webhook_sp.id
}

3. 配置Webhook使用服务主体令牌

通过自定义头部传递Bearer令牌,建议用Terraform的azuread_access_token数据源动态获取令牌:

data "azuread_access_token" "kudu_token" {
  client_id         = azuread_application.webhook_sp.client_id
  client_secret     = azuread_service_principal_password.webhook_sp.value
  scope             = "https://management.azure.com/.default"
  tenant_id         = data.azurerm_client_config.current.tenant_id
}

resource "azurerm_container_registry_webhook" "cr_webhook_myapp" {
  name                = "myappnamewebhook"
  resource_group_name = azurerm_container_registry.cr_mycontainerregistry.resource_group_name
  registry_name       = azurerm_container_registry.cr_mycontainerregistry.name
  location            = azurerm_container_registry.cr_mycontainerregistry.location

  service_uri = "https://${azurerm_linux_web_app.webapp_myapp.name}.scm.azurewebsites.net/api/registry/webhook"

  status      = "enabled"
  scope       = "myapp:latest"
  actions     = ["push"]
  
  custom_headers = {
    Authorization = "Bearer ${data.azuread_access_token.kudu_token.access_token}"
  }

  tags = {
    source = "terraform"
  }
}

关键注意事项

  • ACR系统托管身份仅支持Premium SKU,若当前是Basic/Standard需先升级。
  • 权限验证:确保分配的角色包含Microsoft.Web/sites/scm/action权限,Website Contributor已覆盖该权限。
  • 测试验证:配置完成后可在Azure门户手动触发Webhook测试,确认返回200状态码。

内容的提问来源于stack exchange,提问作者Francois Denis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 15:19:54