如何用Terraform配置Azure Web应用的客户端应用要求为仅允许自身请求
解决方案:配置Azure Windows Web应用仅允许自身请求的身份验证限制
要将Azure Windows Web应用的“Client application requirement”设置为“allow requests only from this application itself”,你需要在Terraform的auth_settings_v2.active_directory_v2块中添加客户端应用ID白名单配置,仅包含当前Web应用自身的Client ID。
修改后的完整Terraform配置
resource "azurerm_windows_web_app" "terra_webapp" { resource_group_name = var.web_app_resource_group_name name = var.web_app_name location = var.web_app_location service_plan_id = var.service_plan_id tags = var.tags https_only = true app_settings = { WEBSITE_AUTH_AAD_ALLOWED_TENANTS = "<TenantID>" } site_config { minimum_tls_version = "1.2" } auth_settings_v2 { auth_enabled = true require_authentication = true require_https = true runtime_version = "~1" default_provider = "azureactivedirectory" unauthenticated_action = "RedirectToLoginPage" login { token_store_enabled = true token_refresh_extension_time = 6 allowed_external_redirect_urls = [] } active_directory_v2 { client_id = "<appClientID>" tenant_auth_endpoint = "https://sts.windows.net/<TenantID>/v2.0" # 添加这一行,仅允许当前应用自身的客户端ID allowed_client_app_ids = ["<appClientID>"] } } }
关键说明
allowed_client_app_ids是控制“Client application requirement”的核心参数:当数组中仅包含当前Web应用的Client ID时,Azure会自动将该选项设置为“allow requests only from this application itself”。- 确保替换配置中的
<TenantID>和<appClientID>为你实际的租户ID和Web应用客户端ID。
验证方法
部署修改后的Terraform配置后,登录Azure门户,进入目标Web应用的Authentication设置页面,查看“Client application requirement”选项,确认已切换为目标设置。
内容的提问来源于stack exchange,提问作者Paul
相关产品推荐
相关产品推荐

