Azure函数应用Bicep配置KeyVaultReferenceIdentity切换至UAMI遇阻
问题:Azure函数应用切换到用户分配托管身份连接Key Vault的配置困惑
我正尝试将当前使用系统分配身份连接Key Vault的Azure函数应用,改为使用用户分配托管身份(UAMI)。该UAMI已拥有Key Vault的正确权限,但对Bicep中keyVaultReferenceIdentity属性的配置存在困惑,相关文档比较稀缺。
以下是我的模块代码:
param uamiId string='' resource functionApp 'Microsoft.Web/sites@2021-03-01' = { name: functionAppName location: 'uks' kind: 'functionapp' identity: empty(uamiId)? { type: 'SystemAssigned' }:{ type: 'UserAssigned' userAssignedIdentities: { '${uamiId}': {} } } properties: { serverFarmId: appPlansprimaryId siteConfig: { ftpsState: 'FtpsOnly' minTlsVersion: '1.2' use32BitWorkerProcess : false// 64 bit keyVaultReferenceIdentity: uamiId } httpsOnly: true keyVaultReferenceIdentity: uamiId } }
我不理解为何keyVaultReferenceIdentity会出现在两个位置:
- 注释掉其中一处时,应用的JSON视图中仅对应位置有值,另一处为null;
- 同时配置两处时,部署后身份又变回系统分配。
请问是否需要同时配置两处?是否还有其他配置要求?目前似乎无法通过门户操作完成设置,仅找到一篇建议使用PowerShell脚本的解决方案。
内容的提问来源于stack exchange,提问作者Echilon
相关产品推荐
相关产品推荐

