You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform和PowerShell自动挂载Azure文件共享到AVD会话主机失败求助

解决AVD会话主机全局持久挂载Azure File Share的方案

核心问题分析

CustomScriptExtension以系统账户执行,默认挂载仅对系统账户可见,普通用户登录后无法自动加载;需将凭据存储到系统级,并配置全局自动挂载逻辑,让所有用户无需输入凭据即可访问。

修改后的PowerShell脚本

# 配置Azure存储账户参数
$storageAccountName = "你的存储账户名"
$storageAccountKey = "你的存储账户密钥"
$fileShareName = "你的文件共享名"
$driveLetter = "Z:"
$uncPath = "\\$storageAccountName.file.core.windows.net\$fileShareName"

# 将存储账户凭据添加到系统级凭据管理器(所有用户共享)
cmdkey /add:$storageAccountName.file.core.windows.net /user:AZURE\$storageAccountName /pass:$storageAccountKey

# 验证凭据添加状态
cmdkey /list:$storageAccountName.file.core.windows.net

# 创建注册表项,实现所有用户登录时自动挂载驱动器
$regPath = "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
$regValueName = "MountAzureFileShare"
$regValueData = "powershell.exe -ExecutionPolicy Bypass -Command 'New-PSDrive -Name $($driveLetter.TrimEnd(':')) -PSProvider FileSystem -Root `"$uncPath`" -Persist'"

# 检查注册表项,不存在则创建
if (-not (Get-ItemProperty -Path $regPath -Name $regValueName -ErrorAction SilentlyContinue)) {
    New-ItemProperty -Path $regPath -Name $regValueName -Value $regValueData -PropertyType String -Force
}

# 系统账户上下文立即挂载(普通用户登录后会通过注册表自动加载)
New-PSDrive -Name $($driveLetter.TrimEnd(':')) -PSProvider FileSystem -Root $uncPath -Persist

Terraform中CustomScriptExtension配置要点

  • 避免硬编码敏感信息,通过Terraform变量传入存储账户参数
  • 确保Extension以系统账户执行(默认配置即可)
  • 示例Terraform片段:
resource "azurerm_virtual_machine_extension" "avd_mount_fileshare" {
  name                 = "AVD-Mount-FileShare"
  virtual_machine_id   = azurerm_virtual_machine.avd_session_host.id
  publisher            = "Microsoft.Compute"
  type                 = "CustomScriptExtension"
  type_handler_version = "1.10"

  settings = jsonencode({
    "commandToExecute" = "powershell -ExecutionPolicy Bypass -File mount-fileshare.ps1"
  })

  protected_settings = jsonencode({
    "storageAccountName" = var.storage_account_name
    "storageAccountKey"  = var.storage_account_key
    "fileUris"           = ["https://你的存储账户.blob.core.windows.net/scripts/mount-fileshare.ps1"]
  })
}

额外注意事项

  • 确保AVD会话主机与Azure File Share在同一VNet,或已配置服务端点/私钥端点打通网络
  • 存储账户密钥建议通过Azure Key Vault引用,避免明文暴露
  • 若使用AD身份验证,需将会话主机加入域并配置文件共享的AD权限,无需存储账户密钥,用户可通过AD身份直接访问

内容的提问来源于stack exchange,提问作者Khoi Vo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 12:12:17