You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Bicep创建带专用端点和客户托管密钥的Azure存储账户

自动化实现带客户托管密钥的Azure存储账户部署方案

核心方案

将流程拆分为Bicep模块化资源定义+PowerShell自动化脚本,一次性完成密钥创建/轮换、存储账户关联及专用端点配置,全程无需手动操作。

1. Bicep模块化设计

拆分三个独立模块,实现职责分离与复用:

Key Vault密钥管理模块(kv-key.bicep)

负责在现有Key Vault中创建密钥,支持重复部署时保留已存在的密钥:

param keyVaultName string
param keyName string = 'storage-encryption-key'
param keyOps array = ['encrypt', 'decrypt']

resource keyVault 'Microsoft.KeyVault/vaults@2023-07-01' existing = {
  name: keyVaultName
}

resource encryptionKey 'Microsoft.KeyVault/vaults/keys@2023-07-01' = {
  parent: keyVault
  name: keyName
  properties: {
    keySize: 2048
    kty: 'RSA'
    keyOps: keyOps
    attributes: {
      enabled: true
    }
  }
}

output keyId string = encryptionKey.id

存储账户创建模块(storage-account.bicep)

创建带专用端点的存储账户,并直接关联Key Vault密钥:

param storageAccountName string
param location string
param keyVaultKeyId string
param privateEndpointSubnetId string

resource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {
  name: storageAccountName
  location: location
  sku: {
    name: 'Standard_RAGRS'
  }
  kind: 'StorageV2'
  properties: {
    encryption: {
      services: {
        blob: { enabled: true }
        file: { enabled: true }
      }
      keySource: 'Microsoft.KeyVault'
      keyVaultProperties: {
        keyName: last(split(keyVaultKeyId, '/'))
        keyVersion: last(split(keyVaultKeyId, '/'))
        keyVaultUri: 'https://${split(keyVaultKeyId, '/')[2]}'
      }
    }
  }
}

resource privateEndpoint 'Microsoft.Network/privateEndpoints@2023-04-01' = {
  name: '${storageAccountName}-pe'
  location: location
  properties: {
    subnet: { id: privateEndpointSubnetId }
    privateLinkServiceConnections: [
      {
        name: '${storageAccountName}-plsc'
        properties: {
          privateLinkServiceId: storageAccount.id
          groupIds: ['blob']
        }
      }
    ]
  }
}

主部署文件(main.bicep)

调用上述模块,传递参数并实现资源关联:

param keyVaultName string
param storageAccountName string
param location string = resourceGroup().location
param privateEndpointSubnetId string

module kvKey './kv-key.bicep' = {
  name: 'deploy-kv-key'
  params: {
    keyVaultName: keyVaultName
  }
}

module storageAccount './storage-account.bicep' = {
  name: 'deploy-storage-account'
  params: {
    storageAccountName: storageAccountName
    location: location
    keyVaultKeyId: kvKey.outputs.keyId
    privateEndpointSubnetId: privateEndpointSubnetId
  }
}

2. 密钥自动轮换PowerShell脚本

部署完成后,自动检查密钥是否存在,若存在则触发轮换并更新存储账户:

param(
  [string]$KeyVaultName,
  [string]$KeyName = 'storage-encryption-key',
  [string]$StorageAccountName,
  [string]$ResourceGroupName
)

# 检查目标密钥是否已存在
$existingKey = Get-AzKeyVaultKey -VaultName $KeyVaultName -Name $KeyName -ErrorAction SilentlyContinue

if ($existingKey) {
  # 创建密钥新版本
  $newKeyVersion = Add-AzKeyVaultKey -VaultName $KeyVaultName -Name $KeyName -Destination 'Software'
  
  # 更新存储账户使用新版本密钥
  Set-AzStorageAccount -ResourceGroupName $ResourceGroupName -Name $StorageAccountName `
    -KeyVaultUri $newKeyVersion.VaultUri -KeyName $newKeyVersion.Name -KeyVersion $newKeyVersion.Version
  
  Write-Host "密钥已完成轮换,存储账户已切换至新版本: $($newKeyVersion.Version)"
} else {
  Write-Host "密钥不存在,已通过Bicep完成创建"
}

3. 一键执行流程

  1. 部署Bicep模板:
az deployment group create --resource-group <你的资源组名> --template-file main.bicep `
  --parameters keyVaultName=<目标KeyVault名> storageAccountName=<存储账户名> privateEndpointSubnetId=<专用端点子网ID>
  1. 执行密钥轮换脚本:
.\Rotate-StorageKey.ps1 -KeyVaultName <目标KeyVault名> -StorageAccountName <存储账户名> -ResourceGroupName <你的资源组名>

关键优化点

  • Bicep模块通过输出参数自动传递密钥ID,彻底消除手动关联步骤
  • 轮换脚本自动判断密钥状态,无需人工干预即可完成密钥版本更新
  • 专用端点与存储账户在同一模块定义,避免额外配置操作

内容的提问来源于stack exchange,提问作者learner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 04:05:23