You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨租户Azure Web App与Azure Function的安全连接方案咨询

Azure Web App 与 Azure Function 安全连接方案

前提:强制HTTPS

首先确保Azure Web App和Azure Function都开启强制HTTPS:

  • Web App:在门户的「TLS/SSL设置」中开启「HTTPS only」
  • Function App:默认已开启强制HTTPS,可在「平台设置」->「TLS/SSL设置」确认

方案1:Azure AD OAuth2 客户端凭证流(推荐,同租户最优解)

利用Azure AD实现身份验证,无需管理静态密钥,权限可控,适合同租户内服务间调用。

配置步骤

  1. 为Function配置Azure AD身份验证

    • 在Function App门户的「身份验证」中,添加「Microsoft Identity Platform」提供商
    • 设置「允许的令牌受众」为Function的应用ID URI(格式:https://<function-app-name>.azurewebsites.net/.default)
    • 开启「要求身份验证」,拒绝未认证的请求
  2. 为Web App配置访问权限

    • 若Web App使用系统分配托管身份:在Azure AD中找到Web App的托管身份,为其添加「Function App」的应用权限(选择user_impersonation或自定义权限)
    • 若使用应用注册:创建一个代表Web App的Azure AD应用,为其添加Function的应用权限,然后在Web App的「身份验证」中关联该应用
  3. Web App调用Function的代码示例(.NET为例)
    使用Azure.Identity库自动获取令牌,无需硬编码密钥:

    using Azure.Identity;
    using System.Net.Http.Headers;
    
    var credential = new DefaultAzureCredential();
    // 请求Function的令牌受众
    var tokenRequestContext = new TokenRequestContext(new[] { "https://<your-function-app>.azurewebsites.net/.default" });
    var accessToken = await credential.GetTokenAsync(tokenRequestContext);
    
    using var httpClient = new HttpClient();
    httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken.Token);
    
    // 构造表单数据
    var formContent = new FormUrlEncodedContent(new Dictionary<string, string>
    {
        { "field1", "value1" },
        { "field2", "value2" }
    });
    
    var response = await httpClient.PostAsync("https://<your-function-app>.azurewebsites.net/api/<http-trigger-name>", formContent);
    response.EnsureSuccessStatusCode();
    

方案2:Function API密钥认证(快速实现,适合轻量场景)

如果不需要复杂的身份管理,可使用Function自带的API密钥,配合HTTPS保障传输安全。

配置步骤

  1. 获取Function密钥

    • 在Function App门户的「功能管理」->「密钥」中,复制「主机密钥」或创建函数级密钥
    • 将密钥存储在Web App的应用设置中(避免硬编码),比如设置名为FUNCTION_API_KEY的变量
  2. Web App调用示例

    var functionKey = Environment.GetEnvironmentVariable("FUNCTION_API_KEY");
    using var httpClient = new HttpClient();
    // 添加密钥到请求头
    httpClient.DefaultRequestHeaders.Add("x-functions-key", functionKey);
    
    var formContent = new FormUrlEncodedContent(new Dictionary<string, string>
    {
        { "field1", "value1" },
        { "field2", "value2" }
    });
    
    var response = await httpClient.PostAsync("https://<your-function-app>.azurewebsites.net/api/<http-trigger-name>", formContent);
    response.EnsureSuccessStatusCode();
    

注意:密钥为静态凭证,需定期轮换;若密钥泄露,需立即重置。


方案3:Azure API Management(APIM)中间层(增强可用性与管控)

如果需要额外的流量管控、监控、缓存等能力,可引入APIM作为Web App与Function的中间层。

核心配置

  1. 将Function导入APIM,创建API服务
  2. 在APIM中配置JWT验证策略,仅允许来自Web App的Azure AD令牌访问
  3. Web App调用APIM的端点,APIM自动转发请求到Function

优势

  • 提供限流、缓存、日志记录等功能,提升系统可用性
  • 统一管控API访问权限,Function无需直接暴露给外部
  • 支持跨区域流量路由,优化访问延迟

高可用补充建议

  • 将Web App与Function部署在同一Azure区域,减少网络延迟
  • 为Function配置自动缩放,根据请求量调整实例数
  • 在Web App中添加重试逻辑(如使用Polly库),处理Function的临时错误(5xx状态码)

内容的提问来源于stack exchange,提问作者GEBRU

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 07:50:20