如何为Azure Web App部署槽设置未匹配规则默认拒绝动作?
Azure Web App部署槽IP限制默认动作设置报错解决方法
问题场景与错误信息
为Azure Web App部署槽批量添加IP访问限制时,执行PowerShell脚本设置默认拒绝动作时触发报错:
##[error]The property 'IpSecurityRestrictionsDefaultAction' cannot be found on this object. Verify that the property exists and can be set.
##[error]PowerShell exited with code '1'
错误原因
脚本中使用Get-AzResource获取的通用资源对象,其SiteConfig结构与Az.Websites模块返回的Get-AzWebAppSlot对象不一致,前者未直接暴露IpSecurityRestrictionsDefaultAction属性。而脚本中已经通过Get-AzWebAppSlot获取了部署槽的完整配置对象$webApp,完全可以直接基于该对象操作。
解决方案
- 删除脚本中通过
Get-AzResource获取资源并设置默认动作的代码段 - 在添加完所有IP限制规则后,直接在
$webApp对象上设置默认拒绝动作 - 启用注释的
Set-AzWebAppSlot命令,将修改后的配置保存到部署槽
修改后的完整脚本
param ($FrontendAppName, $backendAppName,$appResourceGroup, $Slot) Write-Host "Frontend: " $FrontendAppName Write-Host "Backend: " $backendAppName Write-Host "ResourceGroup: " $appResourceGroup Write-Host "Slot: " $Slot Write-Host "Importing Az Modules" #Import Azure Modules Import-Module -Name Az.Websites New-Object Microsoft.Azure.Management.WebSites.Models.IpSecurityRestriction # This needs to be from the front end to the backend Write-Host "Getting Frontend web IPs ..." $ipList = (Get-AzWebAppSlot -Name $FrontendAppName -Slot $Slot -ResourceGroupName $appResourceGroup).PossibleOutboundIpAddresses -split "," $webApp = Get-AzWebAppSlot -ResourceGroupName $appResourceGroup -Name $backendAppName -Slot $Slot Write-Host $ipList Write-Host "Adding Frontend web IPs ..." ForEach ($ip in $ipList) { $ipAddress = "$($ip)/32" $existingRule = $webApp.SiteConfig.IpSecurityRestrictions | Where-Object { $_.IpAddress -eq $ipAddress -and $_.Name -eq "FrontendAppName" } if ($null -eq $existingRule) { $rule = New-Object Microsoft.Azure.Management.WebSites.Models.IpSecurityRestriction $rule.ipAddress = $ipAddress $rule.action = "Allow" $rule.priority = "10" $rule.name = "FrontendAppName" $webApp.SiteConfig.IpSecurityRestrictions.Add($rule) } } Write-Host "Adding Firewall IPs to backendapp Slot ..." # Custom IPs [remove block comment and enable relevant IP addresses as desired] $customIPs = @( # Generic integrations [pscustomobject]@{ruleName='RuleName1'; ipAddress='2.3.4.5/32'}, [pscustomobject]@{ruleName='RuleName2'; ipAddress='6.7.8.9/32'}, [pscustomobject]@{ruleName='RuleName3'; ipAddress='10.11.12.13/32'} ) ForEach ($customIP in $customIPs) { $existingRule = $webApp.SiteConfig.IpSecurityRestrictions | Where-Object { $_.IpAddress -eq $customIP.ipAddress -and $_.Name -eq $customIP.ruleName } if ($null -eq $existingRule) { $rule = New-Object Microsoft.Azure.Management.WebSites.Models.IpSecurityRestriction $rule.ipAddress = $($customIP.ipAddress) $rule.action = "Allow" $rule.priority = "12" $rule.name = $($customIP.ruleName) $webApp.SiteConfig.IpSecurityRestrictions.Add($rule) } } # 设置未匹配规则的默认动作为拒绝 $webApp.SiteConfig.IpSecurityRestrictionsDefaultAction = "Deny" Write-Host "Saving back to webapp slot ..." $webApp | Set-AzWebAppSlot
关键修改说明
- 移除了原脚本中
Get-AzResource相关代码块,规避通用资源对象的结构差异问题 - 直接在
Get-AzWebAppSlot返回的$webApp对象上设置默认拒绝动作,该对象包含正确的属性结构 - 启用
Set-AzWebAppSlot命令,确保修改后的配置被持久化到部署槽
内容的提问来源于stack exchange,提问作者SafeCyclist SafeCyclist
相关产品推荐
相关产品推荐

