You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Bicep自动审批Front Door的专用终结点请求?

问题描述

我正在用基础设施即代码(IaC)通过Bicep模板创建App Service,以及一个带专用终结点的Front Door终结点。创建完成后,必须在UI里手动审批专用终结点链接。

请问怎么自动审批这个专用终结点请求?能不能通过Bicep部署实现?

我用下面的Bicep代码创建源和终结点:

resource appService 'Microsoft.Web/sites@2022-09-01' existing = {
  name: applicationName
  scope: resourceGroup(resourceGroup)
}

resource fdOrigin 'Microsoft.Cdn/profiles/originGroups/origins@2021-06-01' = {
  name: 'fd-origin'
  parent: fdOriginGroup
  properties: {
    hostName: '${applicationName}.azurewebsites.net'
    httpPort: 80
    httpsPort: 443
    originHostHeader: '${applicationName}.azurewebsites.net'
    priority: 1
    weight: 1000
    sharedPrivateLinkResource: {
      groupId: 'sites'
      privateLinkLocation: 'EastUS2'
      requestMessage: 'Created by Deployment Pipeline'
      status: 'Approved'
      privateLink: {
        id: appService.id
      }
    }
  }
}

我尝试在sharedPrivateLinkResource里把status设为Approved,但审批没完成,没报错但链接还是处于Pending状态。

我可以用下面的Bicep代码完成审批,但需要硬编码专用链接名称,没法从上面的Bicep代码里获取这个名称:

resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = {
  name: 'MyAppService/ecc50509-75b1-xxxx-92c9-62bebcececf3-13f6a331-6472-4497-bf94-67adda467e22'
  properties: {
      privateLinkServiceConnectionState: {
          status: 'Approved' 
          description: 'Approved by pipeline'
      }
  }
}
解决方案

要自动审批Front Door与App Service之间的专用终结点连接,你需要分两步处理:先创建带共享专用链接资源的Front Door源,再通过引用该连接的标识完成审批,无需硬编码名称。

1. 问题根源

你在sharedPrivateLinkResource中设置status: 'Approved'无效,因为这个字段是只读的,仅用于显示当前状态,无法通过设置它完成审批。真正的审批操作需要在App Service的privateEndpointConnections资源上执行。

2. 自动审批的Bicep实现

可以通过Bicep的现有资源引用和输出值动态获取专用终结点连接的名称,避免硬编码。具体步骤如下:

步骤一:部署Front Door源(生成专用终结点请求)

保留创建Front Door源的代码,无需设置sharedPrivateLinkResource里的status字段(只读),并输出共享专用链接的名称供后续使用:

resource appService 'Microsoft.Web/sites@2022-09-01' existing = {
  name: applicationName
  scope: resourceGroup(resourceGroup)
}

resource fdOrigin 'Microsoft.Cdn/profiles/originGroups/origins@2021-06-01' = {
  name: 'fd-origin'
  parent: fdOriginGroup
  properties: {
    hostName: '${applicationName}.azurewebsites.net'
    httpPort: 80
    httpsPort: 443
    originHostHeader: '${applicationName}.azurewebsites.net'
    priority: 1
    weight: 1000
    sharedPrivateLinkResource: {
      groupId: 'sites'
      privateLinkLocation: 'EastUS2'
      requestMessage: 'Created by Deployment Pipeline'
      privateLink: {
        id: appService.id
      }
    }
  }
}

// 输出共享专用链接名称,用于后续审批
output sharedPrivateLinkName string = fdOrigin.properties.sharedPrivateLinkResource.name

步骤二:动态审批专用终结点连接

部署完第一步后,通过App Service的privateEndpointConnections资源引用动态获取连接名称,有两种实现方式:

方式A:同一部署内完成审批

确保审批资源在Front Door源之后部署,通过dependsOn控制顺序,并动态拼接连接名称:

// 引用目标App Service
resource appService 'Microsoft.Web/sites@2022-09-01' existing = {
  name: applicationName
  scope: resourceGroup(resourceGroup)
}

// 引用已创建的Front Door源
resource fdOrigin 'Microsoft.Cdn/profiles/originGroups/origins@2021-06-01' existing = {
  name: 'fd-origin'
  parent: fdOriginGroup
}

// 动态拼接专用终结点连接名称:{AppService名称}/{共享专用链接名称}
resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = {
  name: '${appService.name}/${fdOrigin.properties.sharedPrivateLinkResource.name}'
  properties: {
    privateLinkServiceConnectionState: {
      status: 'Approved'
      description: 'Approved by deployment pipeline'
    }
  }
  // 确保在Front Door源创建完成后再执行审批
  dependsOn: [fdOrigin]
}

方式B:分阶段部署(管道传递变量)

如果部署分多个阶段(如先部署Front Door,再执行审批),将第一步输出的sharedPrivateLinkName作为管道变量传入后续阶段的Bicep代码:

param applicationName string
param sharedPrivateLinkName string

// 引用目标App Service
resource appService 'Microsoft.Web/sites@2022-09-01' existing = {
  name: applicationName
  scope: resourceGroup(resourceGroup)
}

// 审批专用终结点连接
resource privateEndpointConnection 'Microsoft.Web/sites/privateEndpointConnections@2022-09-01' = {
  name: '${applicationName}/${sharedPrivateLinkName}'
  properties: {
    privateLinkServiceConnectionState: {
      status: 'Approved'
      description: 'Approved by deployment pipeline'
    }
  }
}

3. 注意事项

  • 部署账号需拥有Microsoft.Web/sites/privateEndpointConnections/write权限(即App Service私有终结点连接的管理权限)。
  • 专用终结点连接名称由Azure自动生成,格式为{AppServiceName}/{SharedPrivateLinkResourceName},其中SharedPrivateLinkResourceName可从Front Door源的sharedPrivateLinkResource.name属性获取。

内容的提问来源于stack exchange,提问作者Don Chambers

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 16:30:12