You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用JSON参数文件循环创建Azure NSG安全规则(Bicep实现)

使用JSON参数文件循环创建NSG安全规则的Bicep方案

该方案完全可行,以下是具体实现步骤:

步骤1:定义JSON参数文件

创建包含NSG基础信息及所有安全规则的参数文件,示例如下:

{
  "contentVersion": "1.0.0.0",
  "parameters": {
    "nsgName": {
      "value": "nsg-uat-001"
    },
    "location": {
      "value": "WestEurope"
    },
    "securityRules": {
      "value": [
        {
          "name": "AllowOnPremToAzure",
          "protocol": "*",
          "sourcePortRange": "*",
          "destinationPortRange": "*",
          "sourceAddressPrefix": "12.0.0.0/24",
          "destinationAddressPrefix": "VirtualNetwork",
          "access": "Allow",
          "priority": 1000,
          "direction": "Inbound"
        },
        {
          "name": "AllowAzureToOnPrem",
          "protocol": "*",
          "sourcePortRange": "*",
          "destinationPortRange": "*",
          "sourceAddressPrefix": "VirtualNetwork",
          "destinationAddressPrefix": "12.0.0.0/24",
          "access": "Allow",
          "priority": 1000,
          "direction": "Outbound"
        }
      ]
    }
  }
}

步骤2:创建NSG安全规则模块

创建独立的Bicep模块文件(如nsg-rule.bicep),封装单个安全规则的创建逻辑:

param nsgName string
param ruleName string
param protocol string
param sourcePortRange string = '*'
param destinationPortRange string = '*'
param sourceAddressPrefix string
param destinationAddressPrefix string
param access string
param priority int
param direction string

resource nsgRule 'Microsoft.Network/networkSecurityGroups/securityRules@2023-06-01' = {
  name: '${nsgName}/${ruleName}'
  properties: {
    protocol: protocol
    sourcePortRange: sourcePortRange
    destinationPortRange: destinationPortRange
    sourceAddressPrefix: sourceAddressPrefix
    destinationAddressPrefix: destinationAddressPrefix
    access: access
    priority: priority
    direction: direction
    sourcePortRanges: []
    destinationPortRanges: []
    sourceAddressPrefixes: []
    destinationAddressPrefixes: []
  }
}

步骤3:主Bicep文件创建NSG并循环生成规则

主文件(main.bicep)负责创建NSG资源,并遍历参数文件中的规则数组,调用模块生成每个安全规则:

param nsgName string
param location string
param securityRules array = []

// 创建基础NSG资源(不含内嵌规则)
resource nsg 'Microsoft.Network/networkSecurityGroups@2023-06-01' = {
  name: nsgName
  location: location
  properties: {
    securityRules: []
  }
}

// 遍历规则数组,通过模块创建每个安全规则
module nsgRules 'nsg-rule.bicep' = [for rule in securityRules: {
  name: 'nsg-rule-${rule.name}'
  params: {
    nsgName: nsgName
    ruleName: rule.name
    protocol: rule.protocol
    sourcePortRange: rule.sourcePortRange
    destinationPortRange: rule.destinationPortRange
    sourceAddressPrefix: rule.sourceAddressPrefix
    destinationAddressPrefix: rule.destinationAddressPrefix
    access: rule.access
    priority: rule.priority
    direction: rule.direction
  }
  dependsOn: [nsg]
}]

关键注意事项

  • 优先级唯一性: 同一方向(入站/出站)的安全规则优先级必须唯一,否则部署会失败,需在参数文件中确保这一点。
  • 简化实现方式: 若无需单独管理规则,也可直接在NSG资源的securityRules属性中循环生成规则(无需模块),代码更简洁:
param nsgName string
param location string
param securityRules array = []

resource nsg 'Microsoft.Network/networkSecurityGroups@2023-06-01' = {
  name: nsgName
  location: location
  properties: {
    securityRules: [for rule in securityRules: {
      name: rule.name
      properties: {
        protocol: rule.protocol
        sourcePortRange: rule.sourcePortRange
        destinationPortRange: rule.destinationPortRange
        sourceAddressPrefix: rule.sourceAddressPrefix
        destinationAddressPrefix: rule.destinationAddressPrefix
        access: rule.access
        priority: rule.priority
        direction: rule.direction
        sourcePortRanges: []
        destinationPortRanges: []
        sourceAddressPrefixes: []
        destinationAddressPrefixes: []
      }
    }]
  }
}

内容的提问来源于stack exchange,提问作者learner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 10:33:14