如何通过Bicep自动审批Front Door的专用终结点请求?
我正在用基础设施即代码(IaC)通过Bicep模板创建App Service,以及一个带专用终结点的Front Door终结点。创建完成后,必须在UI里手动审批专用终结点链接。
请问怎么自动审批这个专用终结点请求?能不能通过Bicep部署实现?
我用下面的Bicep代码创建源和终结点:
resource appService 'Microsoft.Web/sites@2022-09-01' existing = { name: applicationName scope: resourceGroup(resourceGroup) } resource fdOrigin 'Microsoft.Cdn/profiles/originGroups/origins@2021-06-01' = { name: 'fd-origin' parent: fdOriginGroup properties: { hostName: '${applicationName}.azurewebsites.net' httpPort: 80 httpsPort: 443 originHostHeader: '${applicationName}.azurewebsites.net' priority: 1 weight: 1000 sharedPrivateLinkResource: { groupId: 'sites' privateLinkLocation: 'EastUS2' requestMessage: 'Created by Deployment Pipeline' status: 'Approved' privateLink: { id: appService.id } } } }
我尝试在sharedPrivateLinkResource里把status设为Approved,但审批没完成,没报错但链接还是处于Pending状态。
我可以用下面的Bicep代码完成审批,但需要硬编码专用链接名称,没法从上面的Bicep代码里获取这个名称:
resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = { name: 'MyAppService/ecc50509-75b1-xxxx-92c9-62bebcececf3-13f6a331-6472-4497-bf94-67adda467e22' properties: { privateLinkServiceConnectionState: { status: 'Approved' description: 'Approved by pipeline' } } }
要自动审批Front Door与App Service之间的专用终结点连接,你需要分两步处理:先创建带共享专用链接资源的Front Door源,再通过引用该连接的标识完成审批,无需硬编码名称。
1. 问题根源
你在sharedPrivateLinkResource中设置status: 'Approved'无效,因为这个字段是只读的,仅用于显示当前状态,无法通过设置它完成审批。真正的审批操作需要在App Service的privateEndpointConnections资源上执行。
2. 自动审批的Bicep实现
可以通过Bicep的现有资源引用和输出值动态获取专用终结点连接的名称,避免硬编码。具体步骤如下:
步骤一:部署Front Door源(生成专用终结点请求)
保留创建Front Door源的代码,无需设置sharedPrivateLinkResource里的status字段(只读),并输出共享专用链接的名称供后续使用:
resource appService 'Microsoft.Web/sites@2022-09-01' existing = { name: applicationName scope: resourceGroup(resourceGroup) } resource fdOrigin 'Microsoft.Cdn/profiles/originGroups/origins@2021-06-01' = { name: 'fd-origin' parent: fdOriginGroup properties: { hostName: '${applicationName}.azurewebsites.net' httpPort: 80 httpsPort: 443 originHostHeader: '${applicationName}.azurewebsites.net' priority: 1 weight: 1000 sharedPrivateLinkResource: { groupId: 'sites' privateLinkLocation: 'EastUS2' requestMessage: 'Created by Deployment Pipeline' privateLink: { id: appService.id } } } } // 输出共享专用链接名称,用于后续审批 output sharedPrivateLinkName string = fdOrigin.properties.sharedPrivateLinkResource.name
步骤二:动态审批专用终结点连接
部署完第一步后,通过App Service的privateEndpointConnections资源引用动态获取连接名称,有两种实现方式:
方式A:同一部署内完成审批
确保审批资源在Front Door源之后部署,通过dependsOn控制顺序,并动态拼接连接名称:
// 引用目标App Service resource appService 'Microsoft.Web/sites@2022-09-01' existing = { name: applicationName scope: resourceGroup(resourceGroup) } // 引用已创建的Front Door源 resource fdOrigin 'Microsoft.Cdn/profiles/originGroups/origins@2021-06-01' existing = { name: 'fd-origin' parent: fdOriginGroup } // 动态拼接专用终结点连接名称:{AppService名称}/{共享专用链接名称} resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = { name: '${appService.name}/${fdOrigin.properties.sharedPrivateLinkResource.name}' properties: { privateLinkServiceConnectionState: { status: 'Approved' description: 'Approved by deployment pipeline' } } // 确保在Front Door源创建完成后再执行审批 dependsOn: [fdOrigin] }
方式B:分阶段部署(管道传递变量)
如果部署分多个阶段(如先部署Front Door,再执行审批),将第一步输出的sharedPrivateLinkName作为管道变量传入后续阶段的Bicep代码:
param applicationName string param sharedPrivateLinkName string // 引用目标App Service resource appService 'Microsoft.Web/sites@2022-09-01' existing = { name: applicationName scope: resourceGroup(resourceGroup) } // 审批专用终结点连接 resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = { name: '${applicationName}/${sharedPrivateLinkName}' properties: { privateLinkServiceConnectionState: { status: 'Approved' description: 'Approved by deployment pipeline' } } }
3. 注意事项
- 部署账号需拥有Microsoft.Web/sites/privateEndpointConnections/write权限(即App Service私有终结点连接的管理权限)。
- 专用终结点连接名称由Azure自动生成,格式为
{AppServiceName}/{SharedPrivateLinkResourceName},其中SharedPrivateLinkResourceName可从Front Door源的sharedPrivateLinkResource.name属性获取。
内容的提问来源于stack exchange,提问作者Don Chambers

