You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在.NET Framework 4.8.2应用中用Azure Managed Identity替代Instrumentation Key配置Application Insights?

迁移.NET Framework 4.8.2应用至Application Insights RBAC+托管身份

完全可行,以下是具体操作步骤:

一、应用端配置修改

  1. 更新依赖包版本
    需使用支持Azure AD身份验证的SDK版本,通过NuGet安装/更新以下包:

    Install-Package Microsoft.ApplicationInsights.WindowsServer -Version 2.21.0
    Install-Package Microsoft.ApplicationInsights.Auth -Version 2.21.0
    Install-Package Azure.Identity -Version 1.10.4
    
  2. 移除Instrumentation Key
    直接删除ApplicationInsights.config中的<InstrumentationKey>MyKey</InstrumentationKey>节点。

  3. 配置Azure AD身份验证
    在ApplicationInsights.config中添加TelemetryInitializer,指定目标Application Insights资源ID:

    <TelemetryInitializers>
      <Add Type="Microsoft.ApplicationInsights.Auth.TokenCredentialTelemetryInitializer, Microsoft.ApplicationInsights.Auth">
        <ResourceId>/subscriptions/{订阅ID}/resourceGroups/{资源组名}/providers/microsoft.insights/components/{AI实例名}</ResourceId>
      </Add>
    </TelemetryInitializers>
    

    若需更灵活的代码配置,可在应用启动时初始化:

    using Azure.Identity;
    using Microsoft.ApplicationInsights;
    using Microsoft.ApplicationInsights.Auth;
    
    var telemetryClient = new TelemetryClient();
    var aiResourceId = "/subscriptions/{订阅ID}/resourceGroups/{资源组名}/providers/microsoft.insights/components/{AI实例名}";
    telemetryClient.TelemetryInitializers.Add(new TokenCredentialTelemetryInitializer(new DefaultAzureCredential(), aiResourceId));
    
  4. 启用托管身份

    • 部署在Azure App Service:在App Service的「身份」设置中启用系统分配托管身份,或绑定用户分配托管身份。
    • 本地运行:通过az login登录Azure账号,或设置AZURE_CLIENT_ID、AZURE_TENANT_ID、AZURE_CLIENT_SECRET环境变量(服务主体模式),DefaultAzureCredential会自动适配身份验证方式。

二、Terraform配置RBAC权限

为托管身份分配Application Insights组件数据写入者角色(遵循最小权限原则),示例代码如下:

针对系统分配托管身份(App Service)

# 引用目标Application Insights资源
data "azurerm_application_insights" "target_ai" {
  name                = "your-ai-instance-name"
  resource_group_name = "your-resource-group-name"
}

# 引用App Service的系统身份
data "azurerm_app_service" "target_app" {
  name                = "your-app-service-name"
  resource_group_name = "your-resource-group-name"
}

# 分配角色
resource "azurerm_role_assignment" "ai_data_writer" {
  scope                = data.azurerm_application_insights.target_ai.id
  role_definition_name = "Application Insights Component Data Writer"
  principal_id         = data.azurerm_app_service.target_app.identity[0].principal_id
}

针对用户分配托管身份

# 引用用户分配托管身份
data "azurerm_user_assigned_identity" "uaid" {
  name                = "your-user-assigned-identity-name"
  resource_group_name = "your-resource-group-name"
}

# 引用目标Application Insights资源
data "azurerm_application_insights" "target_ai" {
  name                = "your-ai-instance-name"
  resource_group_name = "your-resource-group-name"
}

# 分配角色
resource "azurerm_role_assignment" "ai_data_writer" {
  scope                = data.azurerm_application_insights.target_ai.id
  role_definition_name = "Application Insights Component Data Writer"
  principal_id         = data.azurerm_user_assigned_identity.uaid.principal_id
}

三、验证配置

  1. 重启应用后,查看Application Insights的「日志」面板,确认有新的请求数据生成。
  2. 检查应用日志(App Service日志流或本地日志),排除身份验证类错误。
  3. 在Azure门户的Application Insights资源「访问控制(IAM)」页面,确认托管身份已被分配对应角色。

内容的提问来源于stack exchange,提问作者James

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 07:44:53