You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Marketplace模板能否提前验证Azure DNS区域内子域名未重复?

解决方案:Azure Marketplace部署前验证子域名可用性

要在Azure Marketplace模板部署前完成子域名占用验证,核心是通过Create UI Definition (CUID) 结合自定义Azure Function实现前置校验,具体步骤如下:

1. 编写子域名验证的Azure Function

你需要一个Azure Function来处理子域名的可用性检查,逻辑可二选一:

  • 检查Azure DNS Zone记录:若顶级域名product.com托管在Azure DNS Zone,查询对应子域名的A/CNAME记录是否存在。
  • 检查Web App自定义域名:遍历目标订阅下所有Web App,查看是否已绑定{subdomain}.product.com域名。

示例Python Function(检查Web App域名):

import azure.functions as func
from azure.mgmt.web import WebSiteManagementClient
from azure.identity import DefaultAzureCredential

def main(req: func.HttpRequest) -> func.HttpResponse:
    req_body = req.get_json()
    subdomain = req_body.get('subdomain')
    target_domain = f"{subdomain}.product.com"
    
    # 初始化Web App管理客户端
    credential = DefaultAzureCredential()
    web_client = WebSiteManagementClient(credential, "<你的订阅ID>")
    
    # 遍历所有资源组下的Web App
    for rg in web_client.resource_groups.list():
        for web_app in web_client.web_apps.list_by_resource_group(rg.name):
            # 检查已绑定的自定义域名
            for domain in web_app.host_names:
                if domain == target_domain:
                    return func.HttpResponse(
                        '{"isValid": false, "message": "该子域名已被占用"}',
                        mimetype="application/json"
                    )
    
    return func.HttpResponse(
        '{"isValid": true, "message": "子域名可用"}',
        mimetype="application/json"
    )

注意:给Function配置CORS,允许https://portal.azure.com和https://marketplace.azure.com访问;同时可添加API密钥参数防止恶意调用。

2. 在Create UI Definition中添加验证逻辑

在市场产品的createUiDefinition.json里,给子域名输入框添加自定义验证,调用上述Azure Function:

{
  "name": "subdomain",
  "type": "Microsoft.Common.TextBox",
  "label": "企业子域名",
  "placeholder": "例如:acme",
  "constraints": {
    "required": true,
    "regex": "^[a-z0-9-]{3,20}$",
    "validationMessage": "请输入3-20位小写字母、数字或连字符"
  },
  "validation": {
    "customValidation": {
      "condition": "[not(equals(customValidationReturn('subdomainCheck'), 'valid'))]",
      "message": "[customValidationReturn('subdomainCheck')]",
      "request": {
        "url": "<你的Azure Function URL>?code=<Function密钥>",
        "method": "POST",
        "body": "[parse(concat('{\"subdomain\": \"', steps('basics').subdomain, '\"}'))]"
      }
    }
  }
}

用户输入子域名后,CUID会自动调用Function验证,只有验证通过才允许进入下一步部署。

3. 部署ARM模板时直接使用验证后的子域名

在ARM模板中直接引用CUID里的subdomain参数,无需重复验证:

"parameters": {
  "subdomain": {
    "type": "string",
    "metadata": {
      "description": "企业自定义子域名"
    }
  }
},
"resources": [
  {
    "type": "Microsoft.Web/sites",
    "name": "[parameters('webAppName')]",
    ...
    "properties": {
      "hostNames": [
        "[concat(parameters('subdomain'), '.product.com')]",
        "[concat(parameters('webAppName'), '.azurewebsites.net')]"
      ]
    }
  }
]

额外注意事项

  • 为避免验证与部署间隙的竞态问题(比如验证后到部署前被他人占用),可在ARM模板部署时加一次兜底检查,用部署脚本或自定义资源提供者做最终校验,不过此类概率极低。
  • 若顶级域名托管在非Azure DNS服务,可修改Function逻辑,用DNS解析库(如dnspython)直接查询域名是否已被解析。

内容的提问来源于stack exchange,提问作者Aiden Dipple

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 00:21:21