You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让PowerShell遍历Azure存储账户时遇错停止循环?

解决Azure存储账户扫描脚本遇指定错误停止循环的问题

你的脚本当前在遇到权限不足、超时等错误时仅记录错误,仍会继续遍历后续存储账户和订阅。要实现遇指定错误即停止循环,需要在catch块中增加错误类型判断,并加入循环终止逻辑。

修改后的完整脚本

# Connect to Azure
Connect-AzAccount

# Get all Azure subscriptions
$subscriptions = Get-AzSubscription
# Variables to store access levels and errors
$publicAccessOn = @()
$errorsaccessing = @()
# 定义终止标志,控制整个扫描流程
$stopProcessing = $false

# 为外层订阅循环添加标签,支持跨层级终止
:subscriptionLoop foreach ($subscription in $subscriptions) {
    if ($stopProcessing) { break }
    Write-Output "Subscription: $($subscription.Name)"

    # Select the current subscription
    Select-AzSubscription -SubscriptionId $subscription.Id

    # Get a list of storage accounts 
    $storageAccounts = Get-AzStorageAccount

    # 为内层存储账户循环添加标签
    :storageLoop foreach ($storageAccount in $storageAccounts) {
        if ($stopProcessing) { break }
        $storageAccountName = $storageAccount.StorageAccountName
        $storageAccountRG = $storageAccount.ResourceGroupName

        try {
            # Get a list of containers in the storage account
            $containers = Get-AzStorageContainer -Context $storageAccount.Context -ServerTimeoutPerRequest 30 | Select Name, PublicAccess

            # Check if there are containers in the storage account
            if ($containers -eq $null) {
                Write-Host "No containers found in storage account $storageAccountName. Skipping."  -ForegroundColor Cyan
                continue
            }

            # Display the public access setting
            if ($containers.PublicAccess -eq "Off") {
                Write-Host "Container count is: $($containers.Count) in $storageAccountName"
                Write-Host "PublicAccess Settings is Off in all container in storage account: $storageAccountName" -ForegroundColor Green
                
            }
            else
            {
                Write-Host "Container count is: $($containers.Count) in $storageAccountName"
                Write-Host "PublicAccess Settings is ON in one or more container in storage account: $storageAccountName" -ForegroundColor Red
                $publicAccessOn += $storageAccountName
                
            }
        }
        catch {
            # 记录错误账户
            $errorsaccessing += $storageAccountName
            # 判断错误类型:匹配权限不足或超时关键字
            $errorMessage = $_.Exception.Message
            if ($errorMessage -match "AuthorizationFailed" -or $errorMessage -match "RequestTimeout" -or $errorMessage -match "ServerTimeout") {
                Write-Host "遇到致命错误:$_,停止所有扫描" -ForegroundColor Red
                $stopProcessing = $true
                # 终止内层存储账户循环
                break storageLoop
            } else {
                # 非目标错误,仅记录并继续后续扫描
                Write-Host "非致命错误:$_,继续扫描" -ForegroundColor Yellow
            }
        }
    }
}

# 输出最终扫描结果
Write-Host "`n存在公共访问开启的存储账户:" -ForegroundColor Red
$publicAccessOn | ForEach-Object { Write-Host $_ }

Write-Host "`n访问出错的存储账户:" -ForegroundColor Yellow
$errorsaccessing | ForEach-Object { Write-Host $_ }

关键修改说明

  • 循环标签:给外层订阅循环(subscriptionLoop)和内层存储账户循环(storageLoop)添加标签,实现跨层级终止循环的需求。
  • 终止标志:用$stopProcessing变量控制整个扫描流程,一旦触发致命错误就将其设为$true,外层循环检测到后会同步停止。
  • 错误过滤:在catch块中匹配AuthorizationFailed(权限不足)、RequestTimeout/ServerTimeout(超时)关键字,仅对这两类错误触发停止逻辑,其他非致命错误仍会继续执行。
  • 结果输出优化:添加了最终扫描结果的汇总输出,方便快速查看公共访问开启的账户和出错账户列表。

内容的提问来源于stack exchange,提问作者Bombbe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 04:32:51