You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何自动化为Azure APIM的API/操作追加政策且避免重复

需求:自动化为Azure APIM的API/操作追加政策(去重)

我想实现一套自动化方案,给Azure APIM的API或操作范围修改、追加额外政策。目前脚本已能读取用户输入的$inbound、$outbound、$backend、$onerror变量,现在需要将新政策添加到已有全局/现有政策的对应会话中,要求不重复添加已存在的政策。


尝试的脚本片段

for f in $policy_ ; do
  if [[ $(eval echo \$${f}_name) == "ipfilter" ]]; then
    echo " given policy name is ipfilter "

    if [[ $(eval echo \$${f}_scope) == "api" ]]; then
      echo "decided the scope of Ipfilter policy as api "
    fi

    if [[ "$(eval echo \$${f}_apiname)" ]]; then
       echo "export the policy for the api $(eval echo \$${f}_apiname)"
       curl -H "Content-Type: application/json" -H "Authorization: Bearer $accessToken" "https://management.azure.com/subscriptions/xxxxx/resourceGroups/xx-rg/providers/Microsoft.ApiManagement/service/xxx-apim/apis/myapi/policies/policy?effective=true&format=xml&api-version=2022-08-01" > effectivepolicy.xml
    fi

    if [ -z "$(eval echo \$${f}_inboundsession)" ]; then
        echo 'the inbound session is not present'
    fi
    if [[ "$(eval echo \$${f}_inboundsession)" ]]; then
      echo 'the inbound session is present and append the policy settings to inbound'
      inbound=$(printf "$(eval echo \$${f}_inboundsession)")
       echo "$inbound"
       Add the $inbound to the inbound session of policy.xml if its not existing and apply back 
    fi
done

示例:$inbound变量内容

<ip-filter action="allow">
 <address-range from="xxxxx" to="yyy" />
</ip-filter> 

API范围的现有有效政策示例

<policies>
    <inbound>
            <!--base: Begin Global scope-->
            <cors xxxxxxxxxx="true">
            ****************************
            ****************************
            ****************************
            </cors>
            <!--base: End Global scope-->
    </inbound>
    <backend>
            <!--base: Begin Global scope-->
             ****************************
             ****************************
             ****************************
            <!--base: End Global scope-->
    </backend>
    <outbound>
            <!--base: Begin Global scope-->
            ****************************
            ****************************
            ****************************
            ****************************
            <!--base: End Global scope-->
    </outbound>
    <on-error>
            <!--base: Begin Global scope-->
            ****************************
            ****************************
            ****************************
            <!--base: End Global scope-->
    </on-error>
</policies>

尝试解决方案后的执行情况

YAML格式的政策输入文件

- name: ipfilter
  scope: api
  apiname: xxxxx
  inboundsession: |
                <ip-filter action="allow">
                    <address-range from="xxxxx" to="yyyy" />
                </ip-filter>
  outboundsession: |
                <ip-filter action="allow">
                    <address-range from="xxxxx" to="vvvv" />
                </ip-filter>

调整后的政策脚本

source parse_yaml.sh
eval $(parse_yaml input.yaml policy)
echo ".............Eval Result..............................."
for f in $policy_ ; do eval echo \$f \$${f}_ ; done
echo "............Eval Result................................"

for f in $policy_ ; do
  if [[ $(eval echo \$${f}_name) == "ipfilter" ]]; then
    echo " given policy name is ipfilter "

    if [[ $(eval echo \$${f}_scope) == "api" ]]; then
      echo "decided the scope of Ipfilter policy as api "
    fi

    if [[ "$(eval echo \$${f}_apiname)" ]]; then
       echo "export the policy for the api $(eval echo \$${f}_apiname)"
       curl -H "Content-Type: application/json" -H "Authorization: Bearer $accessToken" "https://management.azure.com/xxxx/providers/Microsoft.ApiManagement/service/ssssssss/apis/xxxxxxxxx/policies/policy?effective=true&format=xml&api-version=2022-08-01" > policy.xml
    fi

    if [ -z "$(eval echo \$${f}_inboundsession)" ]; then
        echo 'the inbound session is not present'
    fi
    if [[ "$(eval echo \$${f}_inboundsession)" ]]; then
      echo 'the inbound session is present and append the policy settings to inbound'
      inboundPolicy=$(printf "$(eval echo \$${f}_inboundsession)")
      echo "$inboundPolicy"
      if grep -qF "$inboundPolicy" policy.xml; then
        echo "Policy already exists in the inbound session."
      else
        # Insert the new policy into the existing policy XML
        echo "updating existing policy with new policy content"
        awk -v policy="$inboundPolicy" '/<\/inbound>/ && !p {print policy; p=1} 1' policy.xml > temp.xml
        mv temp.xml policy.xml
      fi
    fi
done

变量inboundPolicy的解析输出

<ip-filter action="allow">
 <address-range from="xxxxx" to="yyy" />
</ip-filter> 

脚本执行输出

.............Eval Result...............................
policy1 policy1_name policy1_scope policy1_apiname policy1_inboundsession policy1_outboundsession
............Eval Result................................
 given policy name is ipfilter
decided the scope of Ipfilter policy as api
export the policy for the api xxxxxxx
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
the inbound session is present and append the below policy settings to inbound
<ip-filter action="allow">
 <address-range from="xxxxx" to="yyyyyyy" />
 </ip-filter>
updating existing policy with new policy content
the outbound session is present
the backend session is not present

最终生成的政策文件内容

<policies>^M
        <inbound>^M
                <!--base: Begin Global scope-->^M
                <cors axxxxxxx="true">^M
                        <xxxxxxx>^M
                                <origin>aaaaaaaaaaa</origin>^M
                                <origin>bbbbbbbbbbb</origin>^M
                                <origin>cccccccccccc</origin>^M
                        </xxxxxxx>^M
                </cors>^M
                <!--base: End Global scope-->^M
<ip-filter action="allow">
 <address-range from="xxxx" to="yyyy" />
 </ip-filter>
        </inbound>^M
        <backend>^M
                <!--base: Begin Global scope-->^M
                <forward-request />^M
                <!--base: End Global scope-->^M
</policies>

内容的提问来源于stack exchange,提问作者Vowneee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 08:34:54