You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

托管VNet的Azure Synapse中,Terraform部署Linked Service无法使用专用端点

问题:Terraform部署的Synapse托管VNet中Linked Service无法使用专用端点

我用Terraform部署Azure基础设施,其他部分正常,但部署指向Key Vault和通用v2型Blob Storage的Synapse Linked Service时遇到问题:Synapse已部署在托管VNet中,Terraform创建的Linked Service无法像Synapse手动创建的那样自动使用专用端点。

现有Terraform代码(Blob Storage示例)

resource "azurerm_synapse_linked_service" "blob_ls" {
  name                 = "BLOBLinkedService${var.env_prefix}"
  synapse_workspace_id = azurerm_synapse_workspace.compass-syn-ws.id
  type                 = "AzureBlobStorage"
  type_properties_json = <<JSON
{
  "serviceEndpoint": "${azurerm_storage_account.compass_storage_account_blob.primary_blob_endpoint}",
  "accountKind": "StorageV2"
}
JSON
  depends_on = [azurerm_storage_account.compass_storage_account_blob, azurerm_synapse_workspace.compass-syn-ws, azapi_update_resource.approval_storage_blob]
}

排查过程

  • 最初怀疑是未指定Synapse托管标识(MSI),但测试后发现与身份验证方式无关——即使专用端点已创建并批准,Terraform创建的Linked Service仍不使用它,调整部署顺序也无效。
  • 尝试修改type_properties_json的JSON结构,但未解决问题。

解决方案

方案1:在type_properties_json中添加托管集成运行时配置

Synapse托管VNet中,Linked Service需要明确指定使用托管集成运行时才能自动关联专用端点。修改type_properties_json,添加enableIntegrationRuntime字段:

resource "azurerm_synapse_linked_service" "blob_ls" {
  name                 = "BLOBLinkedService${var.env_prefix}"
  synapse_workspace_id = azurerm_synapse_workspace.compass-syn-ws.id
  type                 = "AzureBlobStorage"
  type_properties_json = <<JSON
{
  "serviceEndpoint": "${azurerm_storage_account.compass_storage_account_blob.primary_blob_endpoint}",
  "accountKind": "StorageV2",
  "enableIntegrationRuntime": {
    "type": "Managed"
  }
}
JSON
  depends_on = [azurerm_storage_account.compass_storage_account_blob, azurerm_synapse_workspace.compass-syn-ws, azapi_update_resource.approval_storage_blob]
}

对于Key Vault的Linked Service,同样添加该配置:

resource "azurerm_synapse_linked_service" "kv_ls" {
  name                 = "KVLinkedService${var.env_prefix}"
  synapse_workspace_id = azurerm_synapse_workspace.compass-syn-ws.id
  type                 = "AzureKeyVault"
  type_properties_json = <<JSON
{
  "baseUrl": "${azurerm_key_vault.compass_kv.vault_uri}",
  "enableIntegrationRuntime": {
    "type": "Managed"
  }
}
JSON
}

方案2:使用AzAPI Provider补全配置(方案1不生效时)

如果官方azurerm_synapse_linked_service资源无法完整支持该字段,可通过AzAPI Provider直接更新Linked Service的完整配置:

resource "azapi_update_resource" "synapse_blob_ls_private_endpoint" {
  type      = "Microsoft.Synapse/workspaces/linkedservices@2021-06-01"
  name      = azurerm_synapse_linked_service.blob_ls.name
  parent_id = azurerm_synapse_workspace.compass-syn-ws.id
  body = jsonencode({
    properties = {
      typeProperties = {
        serviceEndpoint = azurerm_storage_account.compass_storage_account_blob.primary_blob_endpoint,
        accountKind = "StorageV2",
        enableIntegrationRuntime = {
          type = "Managed"
        }
      }
    }
  })
  depends_on = [azurerm_synapse_linked_service.blob_ls]
}

验证步骤

  1. 部署修改后的Terraform代码
  2. 进入Synapse Studio查看Linked Service的连接配置,确认已自动关联专用端点
  3. 测试Linked Service的连接,验证是否能通过专用端点正常访问存储/Key Vault

内容的提问来源于stack exchange,提问作者ExploitedRoutine

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 20:00:21