You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Bicep实现Azure ML自定义数据科学家角色分配

用Bicep创建自定义数据科学家角色并分配权限

一、编写自定义角色的Bicep定义

以下是对应你提供的JSON角色定义的Bicep实现,创建名为Data Scientist Custom的自定义角色:

param subscriptionId string
param resourceGroupName string
param workspaceName string

resource customRoleDefinition 'Microsoft.Authorization/roleDefinitions@2022-04-01' = {
  name: guid(subscriptionId, resourceGroupName, workspaceName, 'DataScientistCustom')
  scope: resourceGroup(resourceGroupName)
  properties: {
    roleName: 'Data Scientist Custom'
    description: '可以运行实验,但无法创建或删除计算资源'
    type: 'CustomRole'
    permissions: [
      {
        actions: ['*']
        notActions: [
          'Microsoft.MachineLearningServices/workspaces/*/delete'
          'Microsoft.MachineLearningServices/workspaces/write'
          'Microsoft.MachineLearningServices/workspaces/computes/*/write'
          'Microsoft.MachineLearningServices/workspaces/computes/*/delete'
          'Microsoft.Authorization/*/write'
        ]
      }
    ]
    assignableScopes: [
      '/subscriptions/${subscriptionId}/resourceGroups/${resourceGroupName}/providers/Microsoft.MachineLearningServices/workspaces/${workspaceName}'
    ]
  }
}

代码说明

  • 用guid()生成唯一角色定义ID,保证在目标范围内唯一
  • scope指定为目标资源组,确保角色定义在正确层级创建
  • permissions块对应原JSON的权限规则,通过actions开放所有操作,notActions排除指定的敏感操作
  • assignableScopes限定该角色仅能在指定的机器学习工作区内分配

二、添加角色分配

在同一Bicep文件中,添加角色分配资源,将自定义角色分配给指定的用户/组/服务主体:

param principalId string // 需分配权限的主体ID(用户/组/服务主体的Object ID)

resource roleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(subscriptionId, resourceGroupName, workspaceName, principalId, customRoleDefinition.name)
  scope: resourceId('Microsoft.MachineLearningServices/workspaces', workspaceName)
  properties: {
    roleDefinitionId: customRoleDefinition.id
    principalId: principalId
    principalType: 'User' // 可根据实际改为Group或ServicePrincipal
  }
}

注意事项

  • principalId需替换为实际主体的对象ID,可在Azure门户的Azure AD中获取
  • scope指定为目标机器学习工作区,确保权限仅作用于该工作区
  • principalType根据主体类型选择对应值:User(用户)、Group(组)、ServicePrincipal(服务主体)

三、部署Bicep文件

使用Azure CLI执行部署:

az deployment group create --resource-group <你的资源组名> --template-file <你的Bicep文件名> --parameters subscriptionId=<订阅ID> resourceGroupName=<资源组名> workspaceName=<工作区名> principalId=<主体ID>

内容的提问来源于stack exchange,提问作者MPathan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 14:11:16