如何自动化为Azure APIM的API/操作追加政策且避免重复
需求:自动化为Azure APIM的API/操作追加政策(去重)
我想实现一套自动化方案,给Azure APIM的API或操作范围修改、追加额外政策。目前脚本已能读取用户输入的$inbound、$outbound、$backend、$onerror变量,现在需要将新政策添加到已有全局/现有政策的对应会话中,要求不重复添加已存在的政策。
尝试的脚本片段
for f in $policy_ ; do if [[ $(eval echo \$${f}_name) == "ipfilter" ]]; then echo " given policy name is ipfilter " if [[ $(eval echo \$${f}_scope) == "api" ]]; then echo "decided the scope of Ipfilter policy as api " fi if [[ "$(eval echo \$${f}_apiname)" ]]; then echo "export the policy for the api $(eval echo \$${f}_apiname)" curl -H "Content-Type: application/json" -H "Authorization: Bearer $accessToken" "https://management.azure.com/subscriptions/xxxxx/resourceGroups/xx-rg/providers/Microsoft.ApiManagement/service/xxx-apim/apis/myapi/policies/policy?effective=true&format=xml&api-version=2022-08-01" > effectivepolicy.xml fi if [ -z "$(eval echo \$${f}_inboundsession)" ]; then echo 'the inbound session is not present' fi if [[ "$(eval echo \$${f}_inboundsession)" ]]; then echo 'the inbound session is present and append the policy settings to inbound' inbound=$(printf "$(eval echo \$${f}_inboundsession)") echo "$inbound" Add the $inbound to the inbound session of policy.xml if its not existing and apply back fi done
示例:$inbound变量内容
<ip-filter action="allow"> <address-range from="xxxxx" to="yyy" /> </ip-filter>
API范围的现有有效政策示例
<policies> <inbound> <!--base: Begin Global scope--> <cors xxxxxxxxxx="true"> **************************** **************************** **************************** </cors> <!--base: End Global scope--> </inbound> <backend> <!--base: Begin Global scope--> **************************** **************************** **************************** <!--base: End Global scope--> </backend> <outbound> <!--base: Begin Global scope--> **************************** **************************** **************************** **************************** <!--base: End Global scope--> </outbound> <on-error> <!--base: Begin Global scope--> **************************** **************************** **************************** <!--base: End Global scope--> </on-error> </policies>
尝试解决方案后的执行情况
YAML格式的政策输入文件
- name: ipfilter scope: api apiname: xxxxx inboundsession: | <ip-filter action="allow"> <address-range from="xxxxx" to="yyyy" /> </ip-filter> outboundsession: | <ip-filter action="allow"> <address-range from="xxxxx" to="vvvv" /> </ip-filter>
调整后的政策脚本
source parse_yaml.sh eval $(parse_yaml input.yaml policy) echo ".............Eval Result..............................." for f in $policy_ ; do eval echo \$f \$${f}_ ; done echo "............Eval Result................................" for f in $policy_ ; do if [[ $(eval echo \$${f}_name) == "ipfilter" ]]; then echo " given policy name is ipfilter " if [[ $(eval echo \$${f}_scope) == "api" ]]; then echo "decided the scope of Ipfilter policy as api " fi if [[ "$(eval echo \$${f}_apiname)" ]]; then echo "export the policy for the api $(eval echo \$${f}_apiname)" curl -H "Content-Type: application/json" -H "Authorization: Bearer $accessToken" "https://management.azure.com/xxxx/providers/Microsoft.ApiManagement/service/ssssssss/apis/xxxxxxxxx/policies/policy?effective=true&format=xml&api-version=2022-08-01" > policy.xml fi if [ -z "$(eval echo \$${f}_inboundsession)" ]; then echo 'the inbound session is not present' fi if [[ "$(eval echo \$${f}_inboundsession)" ]]; then echo 'the inbound session is present and append the policy settings to inbound' inboundPolicy=$(printf "$(eval echo \$${f}_inboundsession)") echo "$inboundPolicy" if grep -qF "$inboundPolicy" policy.xml; then echo "Policy already exists in the inbound session." else # Insert the new policy into the existing policy XML echo "updating existing policy with new policy content" awk -v policy="$inboundPolicy" '/<\/inbound>/ && !p {print policy; p=1} 1' policy.xml > temp.xml mv temp.xml policy.xml fi fi done
变量inboundPolicy的解析输出
<ip-filter action="allow"> <address-range from="xxxxx" to="yyy" /> </ip-filter>
脚本执行输出
.............Eval Result............................... policy1 policy1_name policy1_scope policy1_apiname policy1_inboundsession policy1_outboundsession ............Eval Result................................ given policy name is ipfilter decided the scope of Ipfilter policy as api export the policy for the api xxxxxxx % Total % Received % Xferd Average Speed Time Time Time Current the inbound session is present and append the below policy settings to inbound <ip-filter action="allow"> <address-range from="xxxxx" to="yyyyyyy" /> </ip-filter> updating existing policy with new policy content the outbound session is present the backend session is not present
最终生成的政策文件内容
<policies>^M <inbound>^M <!--base: Begin Global scope-->^M <cors axxxxxxx="true">^M <xxxxxxx>^M <origin>aaaaaaaaaaa</origin>^M <origin>bbbbbbbbbbb</origin>^M <origin>cccccccccccc</origin>^M </xxxxxxx>^M </cors>^M <!--base: End Global scope-->^M <ip-filter action="allow"> <address-range from="xxxx" to="yyyy" /> </ip-filter> </inbound>^M <backend>^M <!--base: Begin Global scope-->^M <forward-request />^M <!--base: End Global scope-->^M </policies>
内容的提问来源于stack exchange,提问作者Vowneee
相关产品推荐
相关产品推荐

