You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Azure Web App部署槽设置未匹配规则默认拒绝动作?

Azure Web App部署槽IP限制默认动作设置报错解决方法

问题场景与错误信息

为Azure Web App部署槽批量添加IP访问限制时,执行PowerShell脚本设置默认拒绝动作时触发报错:

##[error]The property 'IpSecurityRestrictionsDefaultAction' cannot be found on this object. Verify that the property exists and can be set.
##[error]PowerShell exited with code '1'

错误原因

脚本中使用Get-AzResource获取的通用资源对象,其SiteConfig结构与Az.Websites模块返回的Get-AzWebAppSlot对象不一致,前者未直接暴露IpSecurityRestrictionsDefaultAction属性。而脚本中已经通过Get-AzWebAppSlot获取了部署槽的完整配置对象$webApp,完全可以直接基于该对象操作。

解决方案

  1. 删除脚本中通过Get-AzResource获取资源并设置默认动作的代码段
  2. 在添加完所有IP限制规则后,直接在$webApp对象上设置默认拒绝动作
  3. 启用注释的Set-AzWebAppSlot命令,将修改后的配置保存到部署槽

修改后的完整脚本

param ($FrontendAppName, $backendAppName,$appResourceGroup, $Slot)
Write-Host "Frontend: " $FrontendAppName
Write-Host "Backend: " $backendAppName
Write-Host "ResourceGroup: " $appResourceGroup
Write-Host "Slot: " $Slot

Write-Host "Importing Az Modules"
#Import Azure Modules
Import-Module -Name Az.Websites
New-Object Microsoft.Azure.Management.WebSites.Models.IpSecurityRestriction

# This needs to be from the front end to the backend
Write-Host "Getting Frontend  web IPs ..."

$ipList = (Get-AzWebAppSlot -Name $FrontendAppName -Slot $Slot -ResourceGroupName $appResourceGroup).PossibleOutboundIpAddresses -split ","   
$webApp = Get-AzWebAppSlot -ResourceGroupName $appResourceGroup -Name $backendAppName -Slot $Slot

Write-Host $ipList

Write-Host "Adding Frontend web IPs ..."
ForEach ($ip in $ipList) {
    $ipAddress = "$($ip)/32"
    $existingRule = $webApp.SiteConfig.IpSecurityRestrictions | Where-Object { $_.IpAddress -eq $ipAddress -and $_.Name -eq "FrontendAppName" }
    if ($null -eq $existingRule) {
        $rule = New-Object Microsoft.Azure.Management.WebSites.Models.IpSecurityRestriction
        $rule.ipAddress = $ipAddress
        $rule.action = "Allow"
        $rule.priority = "10"
        $rule.name = "FrontendAppName"
        $webApp.SiteConfig.IpSecurityRestrictions.Add($rule)
    }
}

Write-Host "Adding Firewall IPs to backendapp Slot ..."

# Custom IPs [remove block comment and enable relevant IP addresses as desired]
$customIPs = @(
       # Generic integrations
      [pscustomobject]@{ruleName='RuleName1'; ipAddress='2.3.4.5/32'},
      [pscustomobject]@{ruleName='RuleName2'; ipAddress='6.7.8.9/32'},
      [pscustomobject]@{ruleName='RuleName3'; ipAddress='10.11.12.13/32'}
       )

ForEach ($customIP in $customIPs) {
    $existingRule = $webApp.SiteConfig.IpSecurityRestrictions | Where-Object { $_.IpAddress -eq $customIP.ipAddress -and $_.Name -eq $customIP.ruleName }
    if ($null -eq $existingRule) {
        $rule = New-Object Microsoft.Azure.Management.WebSites.Models.IpSecurityRestriction
        $rule.ipAddress = $($customIP.ipAddress)
        $rule.action = "Allow"
        $rule.priority = "12"
        $rule.name = $($customIP.ruleName)
        $webApp.SiteConfig.IpSecurityRestrictions.Add($rule)
    }
}

# 设置未匹配规则的默认动作为拒绝
$webApp.SiteConfig.IpSecurityRestrictionsDefaultAction = "Deny"

Write-Host "Saving back to webapp slot ..."
$webApp | Set-AzWebAppSlot

关键修改说明

  • 移除了原脚本中Get-AzResource相关代码块,规避通用资源对象的结构差异问题
  • 直接在Get-AzWebAppSlot返回的$webApp对象上设置默认拒绝动作,该对象包含正确的属性结构
  • 启用Set-AzWebAppSlot命令,确保修改后的配置被持久化到部署槽

内容的提问来源于stack exchange,提问作者SafeCyclist SafeCyclist

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 16:11:12