You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure OpenAI密钥自动轮换实现方案及Terraform资源咨询

Azure OpenAI密钥自动轮换实现方案及Terraform支持

一、自动轮换的实现方法

  • Azure Key Vault + 自动化流程
    1. 将OpenAI密钥存入Azure Key Vault,避免明文存储在代码或配置中。
    2. 借助Azure Automation或Logic Apps搭建定时轮换流程:
      • 调用Azure Cognitive Services的密钥再生API(POST /subscriptions/{subId}/resourceGroups/{rgName}/providers/Microsoft.CognitiveServices/accounts/{accountName}/regenerateKey?api-version=2023-05-01),指定要轮换的密钥(Key1或Key2)。
      • 将新生成的密钥同步更新到Key Vault中。
      • 设置触发周期(如每月一次),在低峰时段执行轮换。
  • Azure Policy触发轮换
    创建自定义Policy检测密钥的使用时长,当密钥接近预设的过期阈值时,自动触发自动化流程完成轮换。

二、Terraform资源支持

AzureRM Terraform provider没有直接提供密钥自动轮换的专用资源,但可以通过组合以下资源实现完整的轮换能力:

  1. 创建OpenAI账户
    你提供的资源定义可用于部署Azure OpenAI账户:
    resource "azurerm_cognitive_account" "example" {
      name                = "xxxxx"
      location            = azurerm_resource_group.example.location
      resource_group_name = azurerm_resource_group.example.name
      kind                = "OpenAI"
      sku_name            = "S0"
    }
    
  2. 将密钥存储到Key Vault
    使用azurerm_key_vault_secret将生成的OpenAI密钥存入Key Vault:
    resource "azurerm_key_vault_secret" "openai_api_key" {
      name         = "openai-api-key"
      value        = azurerm_cognitive_account.example.primary_access_key
      key_vault_id = azurerm_key_vault.example.id
    }
    
  3. 配置自动化轮换流程
    用Terraform创建Automation Account、Runbook和定时触发器,示例PowerShell Runbook核心逻辑:
    # 调用API生成新密钥
    $regenerateUri = "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{rgName}/providers/Microsoft.CognitiveServices/accounts/{accountName}/regenerateKey?api-version=2023-05-01"
    $body = @{ keyName = "Key1" } | ConvertTo-Json
    $newKey = (Invoke-AzRestMethod -Method Post -Uri $regenerateUri -Body $body).Content | ConvertFrom-Json
    
    # 更新Key Vault中的密钥
    Set-AzKeyVaultSecret -VaultName "{vaultName}" -Name "openai-api-key" -SecretValue (ConvertTo-SecureString $newKey.key1 -AsPlainText -Force)
    
    对应的Terraform配置示例:
    # 创建自动化账户
    resource "azurerm_automation_account" "example" {
      name                = "openai-key-rotation-aa"
      location            = azurerm_resource_group.example.location
      resource_group_name = azurerm_resource_group.example.name
      sku_name            = "Basic"
    }
    
    # 创建密钥轮换Runbook
    resource "azurerm_automation_runbook" "key_rotation" {
      name                    = "OpenAIKeyRotation"
      location                = azurerm_resource_group.example.location
      resource_group_name     = azurerm_resource_group.example.name
      automation_account_name = azurerm_automation_account.example.name
      runbook_type            = "PowerShell"
      log_verbose             = true
      log_progress            = true
    
      content = <<-EOT
                # 替换为上述PowerShell脚本内容,填充实际的订阅ID、资源组名等参数
                EOT
    }
    
    # 创建每月轮换的定时任务
    resource "azurerm_automation_schedule" "monthly_rotation" {
      name                    = "MonthlyKeyRotationSchedule"
      location                = azurerm_resource_group.example.location
      resource_group_name     = azurerm_resource_group.example.name
      automation_account_name = azurerm_automation_account.example.name
      frequency               = "Month"
      interval                = 1
      start_time              = "2024-01-01T02:00:00Z"
    }
    
    # 关联Runbook与定时任务
    resource "azurerm_automation_job_schedule" "rotation_trigger" {
      automation_account_name = azurerm_automation_account.example.name
      resource_group_name     = azurerm_resource_group.example.name
      runbook_name            = azurerm_automation_runbook.key_rotation.name
      schedule_name           = azurerm_automation_schedule.monthly_rotation.name
    }
    

三、关键注意事项

  • 权限配置:自动化账户需拥有Cognitive Services Account Contributor权限以再生密钥,以及Key Vault Secrets Officer权限以更新密钥。
  • 服务连续性:确保应用程序从Key Vault动态获取密钥,而非静态硬编码,避免轮换过程中出现服务中断。

内容的提问来源于stack exchange,提问作者Rajnish Kumar Soni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 12:56:22