You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure函数应用Bicep配置KeyVaultReferenceIdentity切换至UAMI遇阻

问题:Azure函数应用切换到用户分配托管身份连接Key Vault的配置困惑

我正尝试将当前使用系统分配身份连接Key Vault的Azure函数应用,改为使用用户分配托管身份(UAMI)。该UAMI已拥有Key Vault的正确权限,但对Bicep中keyVaultReferenceIdentity属性的配置存在困惑,相关文档比较稀缺。

以下是我的模块代码:

param uamiId string=''

resource functionApp 'Microsoft.Web/sites@2021-03-01' = {
  name: functionAppName
  location: 'uks'
  kind: 'functionapp'
  identity: empty(uamiId)? {
    type: 'SystemAssigned'
  }:{
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${uamiId}': {}
    }
  }
  properties: {
    serverFarmId: appPlansprimaryId
    siteConfig: {
      ftpsState: 'FtpsOnly'
      minTlsVersion: '1.2'
      use32BitWorkerProcess : false// 64 bit
      keyVaultReferenceIdentity: uamiId
    }
    httpsOnly: true
    keyVaultReferenceIdentity: uamiId
  }
}

我不理解为何keyVaultReferenceIdentity会出现在两个位置:

  • 注释掉其中一处时,应用的JSON视图中仅对应位置有值,另一处为null;
  • 同时配置两处时,部署后身份又变回系统分配。

请问是否需要同时配置两处?是否还有其他配置要求?目前似乎无法通过门户操作完成设置,仅找到一篇建议使用PowerShell脚本的解决方案。


内容的提问来源于stack exchange,提问作者Echilon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 16:39:55