切换回连接字符串认证时,如何移除Redis缓存的用户分配托管标识?
移除Azure Redis缓存关联的用户分配托管标识解决方案
错误原因
报错核心在于:当需要移除所有用户分配托管标识时,必须将托管身份的类型从UserAssigned改为None,而非仅清空用户标识列表或保持原类型不变。你之前的代码仍将ManagedServiceIdentityType设为UserAssigned,导致Azure拒绝该操作。
正确实现代码
将托管身份类型明确设置为None即可完成移除操作,修正后的代码如下:
ArmClient ARMClientRM = new ArmClient(IdentityClientCredential, SubscriptionId.ToString()) ResourceIdentifier resourceGroupResourceId = ResourceGroupResource.CreateResourceIdentifier(SubscriptionId.ToString(), ResourceGroup.Name); ResourceGroupResource ResourceGroupResource = ArmClientRM.GetResourceGroupResource(resourceGroupResourceId); // 创建类型为None的托管身份实例,清空所有关联的用户标识 ManagedServiceIdentity managedIdentity = new ManagedServiceIdentity(ManagedServiceIdentityType.None); RedisPatch patch = new RedisPatch() { RedisConfiguration = new RedisCommonConfiguration() { PreferredDataPersistenceAuthMethod = "sas", AofStorageConnectionString0 = connectionstring1, AofStorageConnectionString1 = connectionstring2, }, Identity = managedIdentity }; RedisCollection redisCollection = ResourceGroupResource.GetAllRedis(); RedisResource resource = redisCollection.GetAsync(clusterName).GetResult(); resource.UpdateAsync(WaitUntil.Completed, patch).GetResult();
关键说明
- 不要直接将
Identity设为null,Azure资源API要求明确指定身份类型为None来移除所有托管身份关联 - 执行更新前,确认Redis实例的持久化配置已完全切换到连接字符串(sas)认证,避免因身份移除导致持久化功能异常
内容的提问来源于stack exchange,提问作者ranger
相关产品推荐
相关产品推荐

