Azure容器注册表Webhook推送至Linux应用服务的非基本认证方式咨询
Azure容器注册表Webhook替代基本认证的方案
除了Kudu基本认证,你可以通过系统托管身份或**Entra ID服务主体(应用注册)**实现ACR Webhook到App Service Kudu端点的认证,以下是具体实现步骤及Terraform配置:
一、使用系统托管身份认证
1. 为ACR启用系统托管身份
ACR的系统托管身份需要Premium SKU支持,先开启身份:
resource "azurerm_container_registry" "cr_mycontainerregistry" { name = "mycontainerregistry" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location sku = "Premium" identity { type = "SystemAssigned" } }
2. 为ACR身份分配Kudu访问权限
给ACR的系统身份授予Website Contributor角色,使其有权调用Kudu的Webhook端点:
resource "azurerm_role_assignment" "acr_webhook_kudu_access" { scope = azurerm_linux_web_app.webapp_myapp.id role_definition_name = "Website Contributor" principal_id = azurerm_container_registry.cr_mycontainerregistry.identity[0].principal_id }
3. 配置Webhook使用系统身份
修改Webhook配置,添加身份块指定使用ACR的系统托管身份,无需在URI中携带用户名密码:
resource "azurerm_container_registry_webhook" "cr_webhook_myapp" { name = "myappnamewebhook" resource_group_name = azurerm_container_registry.cr_mycontainerregistry.resource_group_name registry_name = azurerm_container_registry.cr_mycontainerregistry.name location = azurerm_container_registry.cr_mycontainerregistry.location service_uri = "https://${azurerm_linux_web_app.webapp_myapp.name}.scm.azurewebsites.net/api/registry/webhook" status = "enabled" scope = "myapp:latest" actions = ["push"] identity { type = "SystemAssigned" identity_ids = [azurerm_container_registry.cr_mycontainerregistry.id] } tags = { source = "terraform" } }
二、使用Entra ID服务主体认证
1. 创建服务主体(应用注册)
创建用于Webhook认证的服务主体:
resource "azuread_application" "webhook_sp" { display_name = "acr-webhook-kudu-sp" } resource "azuread_service_principal" "webhook_sp" { client_id = azuread_application.webhook_sp.client_id } resource "azuread_service_principal_password" "webhook_sp" { service_principal_id = azuread_service_principal.webhook_sp.id end_date = timeadd(timestamp(), "8760h") # 有效期1年 }
2. 为服务主体分配Kudu访问权限
同样授予Website Contributor角色:
resource "azurerm_role_assignment" "sp_kudu_access" { scope = azurerm_linux_web_app.webapp_myapp.id role_definition_name = "Website Contributor" principal_id = azuread_service_principal.webhook_sp.id }
3. 配置Webhook使用服务主体令牌
通过自定义头部传递Bearer令牌,建议用Terraform的azuread_access_token数据源动态获取令牌:
data "azuread_access_token" "kudu_token" { client_id = azuread_application.webhook_sp.client_id client_secret = azuread_service_principal_password.webhook_sp.value scope = "https://management.azure.com/.default" tenant_id = data.azurerm_client_config.current.tenant_id } resource "azurerm_container_registry_webhook" "cr_webhook_myapp" { name = "myappnamewebhook" resource_group_name = azurerm_container_registry.cr_mycontainerregistry.resource_group_name registry_name = azurerm_container_registry.cr_mycontainerregistry.name location = azurerm_container_registry.cr_mycontainerregistry.location service_uri = "https://${azurerm_linux_web_app.webapp_myapp.name}.scm.azurewebsites.net/api/registry/webhook" status = "enabled" scope = "myapp:latest" actions = ["push"] custom_headers = { Authorization = "Bearer ${data.azuread_access_token.kudu_token.access_token}" } tags = { source = "terraform" } }
关键注意事项
- ACR系统托管身份仅支持Premium SKU,若当前是Basic/Standard需先升级。
- 权限验证:确保分配的角色包含
Microsoft.Web/sites/scm/action权限,Website Contributor已覆盖该权限。 - 测试验证:配置完成后可在Azure门户手动触发Webhook测试,确认返回200状态码。
内容的提问来源于stack exchange,提问作者Francois Denis
相关产品推荐
相关产品推荐

