You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Bicep部署Azure Logic Apps的Connections配置?

问题:如何用Bicep部署有状态标准型Logic App的托管API连接配置?

我对有状态标准型Azure Logic Apps中使用的Connections感到困惑,我的Logic App已分配用户托管标识。通过设计器创建流后生成了如下JSON示例(执行Azure Monitor的KQL查询):

"actions": {
    "AppEvents_run_query_and_list_results": {
        "inputs": {
            "body": "let customStartDate = [...]",
            "host": {
                "connection": {
                    "referenceName": "azuremonitorlogs-2"
                }
            },
            "method": "post",
            "path": "/queryData",
            "queries": {
                "resourcegroups": "rg-main",
                "resourcename": "logmain",
                "resourcetype": "Log Analytics Workspace",
                "subscriptions": "04...",
                "timerange": "Set in query"
            }
        },
        "type": "ApiConnection"
    }
    [...]

使用设计器创建并配置为使用用户托管标识的连接时,生成了两个资源:

  • 资源组中类型为Microsoft.Web/connections@2016-06-01的连接资源,我已能用Bicep实现;
  • Logic App的Connections菜单中有指向该连接资源的配置JSON,包含API、身份验证等信息(如下):
"managedApiConnections": {
    "azuremonitorlogs-2": {
        "api": {
            "id": "/subscriptions/7e.../providers/Microsoft.Web/locations/eastus2/managedApis/azuremonitorlogs"
        },
        "authentication": {
            "identity": "/subscriptions/7e.../resourcegroups/rg-main/providers/Microsoft.ManagedIdentity/userAssignedIdentities/id-userid",
            "type": "ManagedServiceIdentity"
        },
        "connection": {
            "id": "/subscriptions/7.../resourceGroups/rg-main/providers/Microsoft.Web/connections/azuremonitorlogs-2"
        },
        "connectionProperties": {
            "authentication": {
                "additionalAudiences": [
                    "https://api.loganalytics.io"
                ],
                "audience": "https://management.core.windows.net/",
                "identity": "/subscriptions/7e.../resourcegroups/rg-main/providers/Microsoft.ManagedIdentity/userAssignedIdentities/id-userid",
                "type": "ManagedServiceIdentity"
            }
        }
    }
    [...]

我了解"referenceName": "azuremonitorlogs-2"指向该配置JSON,它关联实际连接资源并指定使用用户托管标识。请问如何使用Bicep创建Logic App时部署此Connections配置JSON?


解决方案

要在Bicep中部署Logic App的managedApiConnections配置,需在Logic App资源定义的properties.connections节点下直接配置对应连接的关联信息,同时确保工作流定义中的referenceName与配置键名一致。

完整Bicep示例

以下是包含用户托管标识、Azure Monitor连接资源,以及Logic App关联该连接的完整代码:

// 1. 定义用户托管标识
param userAssignedIdentityName string = 'id-userid'
param location string = resourceGroup().location

resource userAssignedIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = {
  name: userAssignedIdentityName
  location: location
}

// 2. 定义Azure Monitor连接资源(你已实现的部分)
param azureMonitorConnectionName string = 'azuremonitorlogs-2'

resource azureMonitorConnection 'Microsoft.Web/connections@2016-06-01' = {
  name: azureMonitorConnectionName
  location: location
  properties: {
    api: {
      id: '/subscriptions/${subscription().subscriptionId}/providers/Microsoft.Web/locations/${location}/managedApis/azuremonitorlogs'
    }
    displayName: azureMonitorConnectionName
    parameterValues: {}
    // 配置用户托管标识认证
    authentication: {
      type: 'ManagedServiceIdentity'
      identity: userAssignedIdentity.id
    }
  }
}

// 3. 定义有状态标准型Logic App,包含managedApiConnections配置
param logicAppName string = 'my-stateful-logic-app'

resource logicApp 'Microsoft.Logic/workflows@2019-05-01' = {
  name: logicAppName
  location: location
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${userAssignedIdentity.id}': {}
    }
  }
  properties: {
    state: 'Enabled'
    definition: {
      '$schema': 'https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#'
      'contentVersion': '1.0.0.0'
      'parameters': {
        '$connections': {
          'defaultValue': {},
          'type': 'Object'
        }
      }
      'triggers': {
        // 替换为你的实际触发器定义
      }
      'actions': {
        'AppEvents_run_query_and_list_results': {
          'inputs': {
            'body': 'let customStartDate = [...]',
            'host': {
              'connection': {
                'referenceName': azureMonitorConnectionName
              }
            },
            'method': 'post',
            'path': '/queryData',
            'queries': {
              'resourcegroups': 'rg-main',
              'resourcename': 'logmain',
              'resourcetype': 'Log Analytics Workspace',
              'subscriptions': subscription().subscriptionId,
              'timerange': 'Set in query'
            }
          },
          'type': 'ApiConnection'
        }
      }
    }
    // 关键:配置managedApiConnections
    connections: {
      '${azureMonitorConnectionName}': {
        api: {
          id: '/subscriptions/${subscription().subscriptionId}/providers/Microsoft.Web/locations/${location}/managedApis/azuremonitorlogs'
        }
        authentication: {
          identity: userAssignedIdentity.id
          type: 'ManagedServiceIdentity'
        }
        connection: {
          id: azureMonitorConnection.id
        }
        connectionProperties: {
          authentication: {
            additionalAudiences: [
              'https://api.loganalytics.io'
            ]
            audience: 'https://management.core.windows.net/'
            identity: userAssignedIdentity.id
            type: 'ManagedServiceIdentity'
          }
        }
      }
    }
  }
}

关键说明

  • Logic App的properties.connections节点下的键名必须与工作流中referenceName完全一致(示例中为azuremonitorlogs-2)。
  • 所有资源ID引用使用Bicep变量(如userAssignedIdentity.id、azureMonitorConnection.id),避免硬编码,提升代码可移植性。
  • 确保用户托管标识对Azure Monitor连接资源拥有Microsoft.Web/connections/invoke/action权限,否则Logic App无法正常调用该连接。

内容的提问来源于stack exchange,提问作者Krumelur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 20:02:24