Azure OpenAI密钥自动轮换实现方案及Terraform资源咨询
Azure OpenAI密钥自动轮换实现方案及Terraform支持
一、自动轮换的实现方法
- Azure Key Vault + 自动化流程
- 将OpenAI密钥存入Azure Key Vault,避免明文存储在代码或配置中。
- 借助Azure Automation或Logic Apps搭建定时轮换流程:
- 调用Azure Cognitive Services的密钥再生API(
POST /subscriptions/{subId}/resourceGroups/{rgName}/providers/Microsoft.CognitiveServices/accounts/{accountName}/regenerateKey?api-version=2023-05-01),指定要轮换的密钥(Key1或Key2)。 - 将新生成的密钥同步更新到Key Vault中。
- 设置触发周期(如每月一次),在低峰时段执行轮换。
- 调用Azure Cognitive Services的密钥再生API(
- Azure Policy触发轮换
创建自定义Policy检测密钥的使用时长,当密钥接近预设的过期阈值时,自动触发自动化流程完成轮换。
二、Terraform资源支持
AzureRM Terraform provider没有直接提供密钥自动轮换的专用资源,但可以通过组合以下资源实现完整的轮换能力:
- 创建OpenAI账户
你提供的资源定义可用于部署Azure OpenAI账户:resource "azurerm_cognitive_account" "example" { name = "xxxxx" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name kind = "OpenAI" sku_name = "S0" } - 将密钥存储到Key Vault
使用azurerm_key_vault_secret将生成的OpenAI密钥存入Key Vault:resource "azurerm_key_vault_secret" "openai_api_key" { name = "openai-api-key" value = azurerm_cognitive_account.example.primary_access_key key_vault_id = azurerm_key_vault.example.id } - 配置自动化轮换流程
用Terraform创建Automation Account、Runbook和定时触发器,示例PowerShell Runbook核心逻辑:
对应的Terraform配置示例:# 调用API生成新密钥 $regenerateUri = "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{rgName}/providers/Microsoft.CognitiveServices/accounts/{accountName}/regenerateKey?api-version=2023-05-01" $body = @{ keyName = "Key1" } | ConvertTo-Json $newKey = (Invoke-AzRestMethod -Method Post -Uri $regenerateUri -Body $body).Content | ConvertFrom-Json # 更新Key Vault中的密钥 Set-AzKeyVaultSecret -VaultName "{vaultName}" -Name "openai-api-key" -SecretValue (ConvertTo-SecureString $newKey.key1 -AsPlainText -Force)# 创建自动化账户 resource "azurerm_automation_account" "example" { name = "openai-key-rotation-aa" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name sku_name = "Basic" } # 创建密钥轮换Runbook resource "azurerm_automation_runbook" "key_rotation" { name = "OpenAIKeyRotation" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name automation_account_name = azurerm_automation_account.example.name runbook_type = "PowerShell" log_verbose = true log_progress = true content = <<-EOT # 替换为上述PowerShell脚本内容,填充实际的订阅ID、资源组名等参数 EOT } # 创建每月轮换的定时任务 resource "azurerm_automation_schedule" "monthly_rotation" { name = "MonthlyKeyRotationSchedule" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name automation_account_name = azurerm_automation_account.example.name frequency = "Month" interval = 1 start_time = "2024-01-01T02:00:00Z" } # 关联Runbook与定时任务 resource "azurerm_automation_job_schedule" "rotation_trigger" { automation_account_name = azurerm_automation_account.example.name resource_group_name = azurerm_resource_group.example.name runbook_name = azurerm_automation_runbook.key_rotation.name schedule_name = azurerm_automation_schedule.monthly_rotation.name }
三、关键注意事项
- 权限配置:自动化账户需拥有
Cognitive Services Account Contributor权限以再生密钥,以及Key Vault Secrets Officer权限以更新密钥。 - 服务连续性:确保应用程序从Key Vault动态获取密钥,而非静态硬编码,避免轮换过程中出现服务中断。
内容的提问来源于stack exchange,提问作者Rajnish Kumar Soni
相关产品推荐
相关产品推荐

