如何通过PowerShell或Azure CLI创建Azure API Management授权/凭据提供商
Azure API Management 授权/凭据提供商的PowerShell与Azure CLI创建方案
PowerShell 实现方式
创建授权服务器(OAuth2/OpenID Connect)
使用Az.ApiManagement模块的New-AzApiManagementAuthorizationServer命令,示例如下:
# 连接Azure账户 Connect-AzAccount # 定义参数 $resourceGroupName = "你的资源组名称" $apiServiceName = "你的APIM实例名称" $authServerName = "自定义授权服务器名称" $clientId = "客户端ID" $clientSecret = "客户端密钥" $authorizationEndpoint = "https://你的授权端点" $tokenEndpoint = "https://你的令牌端点" $clientRegistrationEndpoint = "https://你的客户端注册端点(可选)" # 创建授权服务器 New-AzApiManagementAuthorizationServer -ResourceGroupName $resourceGroupName ` -ServiceName $apiServiceName ` -Name $authServerName ` -ClientId $clientId ` -ClientSecret $clientSecret ` -AuthorizationEndpoint $authorizationEndpoint ` -TokenEndpoint $tokenEndpoint ` -ClientRegistrationEndpoint $clientRegistrationEndpoint ` -GrantType "authorization_code" # 支持authorization_code/client_credentials等类型
自定义凭据提供商(无直接命令时用REST API调用)
如果需要创建自定义凭据提供商,可通过PowerShell调用Azure REST API实现:
# 获取APIM实例的访问令牌 $accessToken = (Get-AzAccessToken -ResourceUrl "https://management.azure.com").Token # 定义API请求参数 $subscriptionId = "你的订阅ID" $resourceGroupName = "你的资源组名称" $apiServiceName = "你的APIM实例名称" $credentialProviderName = "自定义凭据提供商名称" $apiUrl = "https://management.azure.com/subscriptions/$subscriptionId/resourceGroups/$resourceGroupName/providers/Microsoft.ApiManagement/service/$apiServiceName/credentials/$credentialProviderName?api-version=2023-03-01-preview" # 构建请求体(以OAuth2凭据为例) $requestBody = @{ properties = @{ type = "OAuth2" credentials = @{ clientId = "客户端ID" clientSecret = "客户端密钥" } oauth2 = @{ authorizationEndpoint = "https://你的授权端点" tokenEndpoint = "https://你的令牌端点" scope = "所需权限范围" } } } | ConvertTo-Json -Depth 10 # 发送POST请求创建凭据提供商 Invoke-RestMethod -Uri $apiUrl -Method Put -Headers @{ "Authorization" = "Bearer $accessToken" "Content-Type" = "application/json" } -Body $requestBody
Azure CLI 实现方式
创建授权服务器
使用az apim authorization-server create命令,示例如下:
# 登录Azure账户 az login # 创建授权服务器 az apim authorization-server create \ --resource-group "你的资源组名称" \ --service-name "你的APIM实例名称" \ --name "自定义授权服务器名称" \ --client-id "客户端ID" \ --client-secret "客户端密钥" \ --authorization-endpoint "https://你的授权端点" \ --token-endpoint "https://你的令牌端点" \ --grant-types "authorization_code" \ --client-registration-endpoint "https://你的客户端注册端点(可选)"
自定义凭据提供商(无直接命令时用REST API调用)
通过Azure CLI调用REST API,先获取访问令牌再发送请求:
# 获取访问令牌 access_token=$(az account get-access-token --resource "https://management.azure.com" --query accessToken -o tsv) # 定义参数 subscription_id=$(az account show --query id -o tsv) resource_group="你的资源组名称" apim_name="你的APIM实例名称" credential_name="自定义凭据提供商名称" api_url="https://management.azure.com/subscriptions/$subscription_id/resourceGroups/$resource_group/providers/Microsoft.ApiManagement/service/$apim_name/credentials/$credential_name?api-version=2023-03-01-preview" # 构建请求体 request_body='{ "properties": { "type": "OAuth2", "credentials": { "clientId": "客户端ID", "clientSecret": "客户端密钥" }, "oauth2": { "authorizationEndpoint": "https://你的授权端点", "tokenEndpoint": "https://你的令牌端点", "scope": "所需权限范围" } } }' # 发送请求 curl -X PUT "$api_url" \ -H "Authorization: Bearer $access_token" \ -H "Content-Type: application/json" \ -d "$request_body"
注意事项
- 确保使用的PowerShell
Az.ApiManagement模块版本为最新(可通过Update-Module -Name Az.ApiManagement更新) - Azure CLI需升级至最新版本(
az upgrade),部分命令仅在新版本中支持 - 预览版API可能存在变动,使用时请确认对应API版本的兼容性
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

