如何使用Bicep部署Azure Logic Apps的Connections配置?
问题:如何用Bicep部署有状态标准型Logic App的托管API连接配置?
我对有状态标准型Azure Logic Apps中使用的Connections感到困惑,我的Logic App已分配用户托管标识。通过设计器创建流后生成了如下JSON示例(执行Azure Monitor的KQL查询):
"actions": { "AppEvents_run_query_and_list_results": { "inputs": { "body": "let customStartDate = [...]", "host": { "connection": { "referenceName": "azuremonitorlogs-2" } }, "method": "post", "path": "/queryData", "queries": { "resourcegroups": "rg-main", "resourcename": "logmain", "resourcetype": "Log Analytics Workspace", "subscriptions": "04...", "timerange": "Set in query" } }, "type": "ApiConnection" } [...]
使用设计器创建并配置为使用用户托管标识的连接时,生成了两个资源:
- 资源组中类型为
Microsoft.Web/connections@2016-06-01的连接资源,我已能用Bicep实现; - Logic App的Connections菜单中有指向该连接资源的配置JSON,包含API、身份验证等信息(如下):
"managedApiConnections": { "azuremonitorlogs-2": { "api": { "id": "/subscriptions/7e.../providers/Microsoft.Web/locations/eastus2/managedApis/azuremonitorlogs" }, "authentication": { "identity": "/subscriptions/7e.../resourcegroups/rg-main/providers/Microsoft.ManagedIdentity/userAssignedIdentities/id-userid", "type": "ManagedServiceIdentity" }, "connection": { "id": "/subscriptions/7.../resourceGroups/rg-main/providers/Microsoft.Web/connections/azuremonitorlogs-2" }, "connectionProperties": { "authentication": { "additionalAudiences": [ "https://api.loganalytics.io" ], "audience": "https://management.core.windows.net/", "identity": "/subscriptions/7e.../resourcegroups/rg-main/providers/Microsoft.ManagedIdentity/userAssignedIdentities/id-userid", "type": "ManagedServiceIdentity" } } } [...]
我了解"referenceName": "azuremonitorlogs-2"指向该配置JSON,它关联实际连接资源并指定使用用户托管标识。请问如何使用Bicep创建Logic App时部署此Connections配置JSON?
解决方案
要在Bicep中部署Logic App的managedApiConnections配置,需在Logic App资源定义的properties.connections节点下直接配置对应连接的关联信息,同时确保工作流定义中的referenceName与配置键名一致。
完整Bicep示例
以下是包含用户托管标识、Azure Monitor连接资源,以及Logic App关联该连接的完整代码:
// 1. 定义用户托管标识 param userAssignedIdentityName string = 'id-userid' param location string = resourceGroup().location resource userAssignedIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = { name: userAssignedIdentityName location: location } // 2. 定义Azure Monitor连接资源(你已实现的部分) param azureMonitorConnectionName string = 'azuremonitorlogs-2' resource azureMonitorConnection 'Microsoft.Web/connections@2016-06-01' = { name: azureMonitorConnectionName location: location properties: { api: { id: '/subscriptions/${subscription().subscriptionId}/providers/Microsoft.Web/locations/${location}/managedApis/azuremonitorlogs' } displayName: azureMonitorConnectionName parameterValues: {} // 配置用户托管标识认证 authentication: { type: 'ManagedServiceIdentity' identity: userAssignedIdentity.id } } } // 3. 定义有状态标准型Logic App,包含managedApiConnections配置 param logicAppName string = 'my-stateful-logic-app' resource logicApp 'Microsoft.Logic/workflows@2019-05-01' = { name: logicAppName location: location identity: { type: 'UserAssigned' userAssignedIdentities: { '${userAssignedIdentity.id}': {} } } properties: { state: 'Enabled' definition: { '$schema': 'https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#' 'contentVersion': '1.0.0.0' 'parameters': { '$connections': { 'defaultValue': {}, 'type': 'Object' } } 'triggers': { // 替换为你的实际触发器定义 } 'actions': { 'AppEvents_run_query_and_list_results': { 'inputs': { 'body': 'let customStartDate = [...]', 'host': { 'connection': { 'referenceName': azureMonitorConnectionName } }, 'method': 'post', 'path': '/queryData', 'queries': { 'resourcegroups': 'rg-main', 'resourcename': 'logmain', 'resourcetype': 'Log Analytics Workspace', 'subscriptions': subscription().subscriptionId, 'timerange': 'Set in query' } }, 'type': 'ApiConnection' } } } // 关键:配置managedApiConnections connections: { '${azureMonitorConnectionName}': { api: { id: '/subscriptions/${subscription().subscriptionId}/providers/Microsoft.Web/locations/${location}/managedApis/azuremonitorlogs' } authentication: { identity: userAssignedIdentity.id type: 'ManagedServiceIdentity' } connection: { id: azureMonitorConnection.id } connectionProperties: { authentication: { additionalAudiences: [ 'https://api.loganalytics.io' ] audience: 'https://management.core.windows.net/' identity: userAssignedIdentity.id type: 'ManagedServiceIdentity' } } } } } }
关键说明
- Logic App的
properties.connections节点下的键名必须与工作流中referenceName完全一致(示例中为azuremonitorlogs-2)。 - 所有资源ID引用使用Bicep变量(如
userAssignedIdentity.id、azureMonitorConnection.id),避免硬编码,提升代码可移植性。 - 确保用户托管标识对Azure Monitor连接资源拥有
Microsoft.Web/connections/invoke/action权限,否则Logic App无法正常调用该连接。
内容的提问来源于stack exchange,提问作者Krumelur
相关产品推荐
相关产品推荐

