You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Fluent SDK中设置虚拟机Trusted Launch属性遇阻

问题:使用Azure Fluent SDK创建VM时无法配置Trusted Launch属性

我正在开发一个C#应用,使用Azure Fluent SDK从捕获的镜像创建虚拟机。常规场景下代码运行正常,但在尝试设置虚拟机的Trusted Launch属性时遇到困难,Microsoft Azure Management Fluent SDK中没有对应的直接配置方法。

现有代码如下:

public void DOCreateVMFromImage()
{
    string captureimage = "Image1";
    string vmName = "Test-4";
    string resourceGrp = "TESTVMGROUP";
    string resource = "TESTVMGROUP";
    string adminUsername = "Student1";
    string adminPassword = "student1Excel";
    var location = Region.USEast;
    var vNetName = "VNET-Fluent";
    var vNetAddress = "172.16.0.0/16";
    var subnetName = "Subnet-Fluent";
    var subnetAddress = "172.16.0.0/24";
    var nicName = "NICVM";
    var publicIPName = "Test4publicIp";
    var nsgName = "NSGi-Fluent";
    var sharedImageGalleryName = "NewImages";  // Replace with your actual gallery name
    var sharedImageDefinitionName = "Image1";  // Replace with your actual image definition name
    var sharedImageVersion = "0.0.1";

    var credentials = SdkContext.AzureCredentialsFactory
            .FromFile("../../../azure-configuration.json");

    var azure = Azure.Authenticate(credentials).WithDefaultSubscription();

    // Get the captured image
    var capturedImage = azure.GalleryImages.GetByGallery(resource, sharedImageGalleryName, sharedImageDefinitionName);
    
    if (capturedImage != null)
    {
        Console.WriteLine($"Creating virtual network {vNetName} ...");
        var network = azure.Networks.Define(vNetName)
            .WithRegion(capturedImage.Location)
            .WithExistingResourceGroup(resource)
            .WithAddressSpace(vNetAddress)
            .WithSubnet(subnetName, subnetAddress)
            .Create();

        Console.WriteLine($"Creating public IP {publicIPName} ...");
        var publicIP = azure.PublicIPAddresses.Define(publicIPName)
            .WithRegion(capturedImage.Location)
            .WithExistingResourceGroup(resource)
            .Create();
        Console.WriteLine($"Creating Network Security Group {nsgName} ...");
        var nsg = azure.NetworkSecurityGroups.Define(nsgName)
            .WithRegion(capturedImage.Location)
            .WithExistingResourceGroup(resource)
            .DefineRule("Allow-RDP")
                .AllowInbound()
                .FromAnyAddress()
                .FromAnyPort()
                .ToAnyAddress()
                .ToPort(3389)
                .WithProtocol(SecurityRuleProtocol.Tcp)
                .WithPriority(100)
                .Attach()
            .Create();

        Console.WriteLine($"Creating network interface {nicName} ...");
        var nic = azure.NetworkInterfaces.Define(nicName)
                 .WithRegion(capturedImage.Location)
                 .WithExistingResourceGroup(resource)
                 .WithExistingPrimaryNetwork(network)
                 .WithSubnet(subnetName)
                 .WithPrimaryPrivateIPAddressDynamic()
                 .WithExistingPrimaryPublicIPAddress(publicIP)
                 .WithExistingNetworkSecurityGroup(nsg)
                 .Create();
        Console.WriteLine($"Creating a new VM using {captureimage}...");

        SecurityProfile objsec = new SecurityProfile();

        var newVM = azure.VirtualMachines.Define(vmName)
                                         .WithRegion(capturedImage.Location)
                                         .WithExistingResourceGroup(resource)
                                         .WithExistingPrimaryNetworkInterface(nic)
                                         .WithWindowsCustomImage(capturedImage.Id)
                                         .WithAdminUsername(adminUsername)
                                         .WithAdminPassword(adminPassword)
                                         .WithComputerName(vmName)
                                         .WithSize(VirtualMachineSizeTypes.StandardD2sV3)
                                         .Create();
        newVM.Restart();
        Console.WriteLine("Successfully created a new VM: {0}!", vmName);
        Console.WriteLine("Press any key to exit...");
        Console.ReadLine();
    }
}

解决方案

Azure Fluent SDK虽然没有专门的链式调用方法直接配置Trusted Launch,但可以通过实例化SecurityProfile并设置对应属性,再将其附加到VM定义中来实现。Trusted Launch需要同时启用Secure Boot和vTPM,并将安全类型设置为TrustedLaunch。

修改后的完整代码

public void DOCreateVMFromImage()
{
    string captureimage = "Image1";
    string vmName = "Test-4";
    string resourceGrp = "TESTVMGROUP";
    string resource = "TESTVMGROUP";
    string adminUsername = "Student1";
    string adminPassword = "student1Excel";
    var location = Region.USEast;
    var vNetName = "VNET-Fluent";
    var vNetAddress = "172.16.0.0/16";
    var subnetName = "Subnet-Fluent";
    var subnetAddress = "172.16.0.0/24";
    var nicName = "NICVM";
    var publicIPName = "Test4publicIp";
    var nsgName = "NSGi-Fluent";
    var sharedImageGalleryName = "NewImages";  // Replace with your actual gallery name
    var sharedImageDefinitionName = "Image1";  // Replace with your actual image definition name
    var sharedImageVersion = "0.0.1";

    var credentials = SdkContext.AzureCredentialsFactory
            .FromFile("../../../azure-configuration.json");

    var azure = Azure.Authenticate(credentials).WithDefaultSubscription();

    // Get the captured image
    var capturedImage = azure.GalleryImages.GetByGallery(resource, sharedImageGalleryName, sharedImageDefinitionName);
    
    if (capturedImage != null)
    {
        Console.WriteLine($"Creating virtual network {vNetName} ...");
        var network = azure.Networks.Define(vNetName)
            .WithRegion(capturedImage.Location)
            .WithExistingResourceGroup(resource)
            .WithAddressSpace(vNetAddress)
            .WithSubnet(subnetName, subnetAddress)
            .Create();

        Console.WriteLine($"Creating public IP {publicIPName} ...");
        var publicIP = azure.PublicIPAddresses.Define(publicIPName)
            .WithRegion(capturedImage.Location)
            .WithExistingResourceGroup(resource)
            .Create();
        Console.WriteLine($"Creating Network Security Group {nsgName} ...");
        var nsg = azure.NetworkSecurityGroups.Define(nsgName)
            .WithRegion(capturedImage.Location)
            .WithExistingResourceGroup(resource)
            .DefineRule("Allow-RDP")
                .AllowInbound()
                .FromAnyAddress()
                .FromAnyPort()
                .ToAnyAddress()
                .ToPort(3389)
                .WithProtocol(SecurityRuleProtocol.Tcp)
                .WithPriority(100)
                .Attach()
            .Create();

        Console.WriteLine($"Creating network interface {nicName} ...");
        var nic = azure.NetworkInterfaces.Define(nicName)
                 .WithRegion(capturedImage.Location)
                 .WithExistingResourceGroup(resource)
                 .WithExistingPrimaryNetwork(network)
                 .WithSubnet(subnetName)
                 .WithPrimaryPrivateIPAddressDynamic()
                 .WithExistingPrimaryPublicIPAddress(publicIP)
                 .WithExistingNetworkSecurityGroup(nsg)
                 .Create();
        Console.WriteLine($"Creating a new VM using {captureimage}...");

        // 配置Trusted Launch所需的安全参数
        SecurityProfile objsec = new SecurityProfile
        {
            SecurityType = SecurityType.TrustedLaunch,
            SecureBootEnabled = true,
            VtpmEnabled = true
        };

        var newVM = azure.VirtualMachines.Define(vmName)
                                         .WithRegion(capturedImage.Location)
                                         .WithExistingResourceGroup(resource)
                                         .WithExistingPrimaryNetworkInterface(nic)
                                         .WithWindowsCustomImage(capturedImage.Id)
                                         .WithAdminUsername(adminUsername)
                                         .WithAdminPassword(adminPassword)
                                         .WithComputerName(vmName)
                                         .WithSize(VirtualMachineSizeTypes.StandardD2sV3)
                                         .WithSecurityProfile(objsec) // 附加安全配置
                                         .Create();
        newVM.Restart();
        Console.WriteLine("Successfully created a new VM: {0}!", vmName);
        Console.WriteLine("Press any key to exit...");
        Console.ReadLine();
    }
}

注意事项

  • 确保使用的Azure Fluent SDK版本支持SecurityType.TrustedLaunch,版本过旧需升级至最新稳定版。
  • 捕获的镜像本身必须支持Trusted Launch,否则配置后VM创建会失败。

内容的提问来源于stack exchange,提问作者DHARSHAN MUTHUKUMAR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 09:35:04