Azure Fluent SDK中设置虚拟机Trusted Launch属性遇阻
问题:使用Azure Fluent SDK创建VM时无法配置Trusted Launch属性
我正在开发一个C#应用,使用Azure Fluent SDK从捕获的镜像创建虚拟机。常规场景下代码运行正常,但在尝试设置虚拟机的Trusted Launch属性时遇到困难,Microsoft Azure Management Fluent SDK中没有对应的直接配置方法。
现有代码如下:
public void DOCreateVMFromImage() { string captureimage = "Image1"; string vmName = "Test-4"; string resourceGrp = "TESTVMGROUP"; string resource = "TESTVMGROUP"; string adminUsername = "Student1"; string adminPassword = "student1Excel"; var location = Region.USEast; var vNetName = "VNET-Fluent"; var vNetAddress = "172.16.0.0/16"; var subnetName = "Subnet-Fluent"; var subnetAddress = "172.16.0.0/24"; var nicName = "NICVM"; var publicIPName = "Test4publicIp"; var nsgName = "NSGi-Fluent"; var sharedImageGalleryName = "NewImages"; // Replace with your actual gallery name var sharedImageDefinitionName = "Image1"; // Replace with your actual image definition name var sharedImageVersion = "0.0.1"; var credentials = SdkContext.AzureCredentialsFactory .FromFile("../../../azure-configuration.json"); var azure = Azure.Authenticate(credentials).WithDefaultSubscription(); // Get the captured image var capturedImage = azure.GalleryImages.GetByGallery(resource, sharedImageGalleryName, sharedImageDefinitionName); if (capturedImage != null) { Console.WriteLine($"Creating virtual network {vNetName} ..."); var network = azure.Networks.Define(vNetName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .WithAddressSpace(vNetAddress) .WithSubnet(subnetName, subnetAddress) .Create(); Console.WriteLine($"Creating public IP {publicIPName} ..."); var publicIP = azure.PublicIPAddresses.Define(publicIPName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .Create(); Console.WriteLine($"Creating Network Security Group {nsgName} ..."); var nsg = azure.NetworkSecurityGroups.Define(nsgName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .DefineRule("Allow-RDP") .AllowInbound() .FromAnyAddress() .FromAnyPort() .ToAnyAddress() .ToPort(3389) .WithProtocol(SecurityRuleProtocol.Tcp) .WithPriority(100) .Attach() .Create(); Console.WriteLine($"Creating network interface {nicName} ..."); var nic = azure.NetworkInterfaces.Define(nicName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .WithExistingPrimaryNetwork(network) .WithSubnet(subnetName) .WithPrimaryPrivateIPAddressDynamic() .WithExistingPrimaryPublicIPAddress(publicIP) .WithExistingNetworkSecurityGroup(nsg) .Create(); Console.WriteLine($"Creating a new VM using {captureimage}..."); SecurityProfile objsec = new SecurityProfile(); var newVM = azure.VirtualMachines.Define(vmName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .WithExistingPrimaryNetworkInterface(nic) .WithWindowsCustomImage(capturedImage.Id) .WithAdminUsername(adminUsername) .WithAdminPassword(adminPassword) .WithComputerName(vmName) .WithSize(VirtualMachineSizeTypes.StandardD2sV3) .Create(); newVM.Restart(); Console.WriteLine("Successfully created a new VM: {0}!", vmName); Console.WriteLine("Press any key to exit..."); Console.ReadLine(); } }
解决方案
Azure Fluent SDK虽然没有专门的链式调用方法直接配置Trusted Launch,但可以通过实例化SecurityProfile并设置对应属性,再将其附加到VM定义中来实现。Trusted Launch需要同时启用Secure Boot和vTPM,并将安全类型设置为TrustedLaunch。
修改后的完整代码
public void DOCreateVMFromImage() { string captureimage = "Image1"; string vmName = "Test-4"; string resourceGrp = "TESTVMGROUP"; string resource = "TESTVMGROUP"; string adminUsername = "Student1"; string adminPassword = "student1Excel"; var location = Region.USEast; var vNetName = "VNET-Fluent"; var vNetAddress = "172.16.0.0/16"; var subnetName = "Subnet-Fluent"; var subnetAddress = "172.16.0.0/24"; var nicName = "NICVM"; var publicIPName = "Test4publicIp"; var nsgName = "NSGi-Fluent"; var sharedImageGalleryName = "NewImages"; // Replace with your actual gallery name var sharedImageDefinitionName = "Image1"; // Replace with your actual image definition name var sharedImageVersion = "0.0.1"; var credentials = SdkContext.AzureCredentialsFactory .FromFile("../../../azure-configuration.json"); var azure = Azure.Authenticate(credentials).WithDefaultSubscription(); // Get the captured image var capturedImage = azure.GalleryImages.GetByGallery(resource, sharedImageGalleryName, sharedImageDefinitionName); if (capturedImage != null) { Console.WriteLine($"Creating virtual network {vNetName} ..."); var network = azure.Networks.Define(vNetName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .WithAddressSpace(vNetAddress) .WithSubnet(subnetName, subnetAddress) .Create(); Console.WriteLine($"Creating public IP {publicIPName} ..."); var publicIP = azure.PublicIPAddresses.Define(publicIPName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .Create(); Console.WriteLine($"Creating Network Security Group {nsgName} ..."); var nsg = azure.NetworkSecurityGroups.Define(nsgName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .DefineRule("Allow-RDP") .AllowInbound() .FromAnyAddress() .FromAnyPort() .ToAnyAddress() .ToPort(3389) .WithProtocol(SecurityRuleProtocol.Tcp) .WithPriority(100) .Attach() .Create(); Console.WriteLine($"Creating network interface {nicName} ..."); var nic = azure.NetworkInterfaces.Define(nicName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .WithExistingPrimaryNetwork(network) .WithSubnet(subnetName) .WithPrimaryPrivateIPAddressDynamic() .WithExistingPrimaryPublicIPAddress(publicIP) .WithExistingNetworkSecurityGroup(nsg) .Create(); Console.WriteLine($"Creating a new VM using {captureimage}..."); // 配置Trusted Launch所需的安全参数 SecurityProfile objsec = new SecurityProfile { SecurityType = SecurityType.TrustedLaunch, SecureBootEnabled = true, VtpmEnabled = true }; var newVM = azure.VirtualMachines.Define(vmName) .WithRegion(capturedImage.Location) .WithExistingResourceGroup(resource) .WithExistingPrimaryNetworkInterface(nic) .WithWindowsCustomImage(capturedImage.Id) .WithAdminUsername(adminUsername) .WithAdminPassword(adminPassword) .WithComputerName(vmName) .WithSize(VirtualMachineSizeTypes.StandardD2sV3) .WithSecurityProfile(objsec) // 附加安全配置 .Create(); newVM.Restart(); Console.WriteLine("Successfully created a new VM: {0}!", vmName); Console.WriteLine("Press any key to exit..."); Console.ReadLine(); } }
注意事项
- 确保使用的Azure Fluent SDK版本支持
SecurityType.TrustedLaunch,版本过旧需升级至最新稳定版。 - 捕获的镜像本身必须支持Trusted Launch,否则配置后VM创建会失败。
内容的提问来源于stack exchange,提问作者DHARSHAN MUTHUKUMAR
相关产品推荐
相关产品推荐

