如何创建带有AutoPool和托管标识的Azure Batch作业?(.NET Framework 4.7)
如何通过AutoPool创建带托管标识的Azure Batch作业?
你的应用基于.NET Framework 4.7,当前用Microsoft.Azure.Batch库通过AutoPool创建作业,想知道能不能给这类AutoPool配置托管标识,答案是可以实现,具体说明和操作如下:
核心说明
Microsoft.Azure.Batch的较新版本库已支持在PoolSpecification中配置托管标识,若你使用的旧版本库无此属性,可结合Microsoft.Azure.Management.Batch库的能力完成配置。
具体实现步骤
确认或升级Batch库版本
确保使用的Microsoft.Azure.BatchNuGet包版本在v10.0及以上,该版本已包含ManagedIdentity相关属性支持。修改池配置方法,添加托管标识
在你的GetPoolSpec()方法中补充托管标识配置,示例代码如下:private PoolSpecification GetPoolSpec() { var poolSpec = new PoolSpecification { // 保留原有池配置,比如虚拟机规格、系统镜像等 VirtualMachineSize = "Standard_D2s_v3", VirtualMachineConfiguration = new VirtualMachineConfiguration( new ImageReference( publisher: "MicrosoftWindowsServer", offer: "WindowsServer", sku: "2019-Datacenter", version: "latest"), "batch.node.windows amd64"), // 添加托管标识配置 ManagedIdentity = new ManagedIdentity { // 可选SystemAssigned(系统分配)或UserAssigned(用户分配) Type = ManagedIdentityType.UserAssigned, UserAssignedIdentities = new Dictionary<string, UserAssignedIdentity> { // 替换为你的用户分配标识资源ID { "/subscriptions/xxx/resourceGroups/xxx/providers/Microsoft.ManagedIdentity/userAssignedIdentities/xxx", new UserAssignedIdentity() } } } }; return poolSpec; }保持原有作业创建逻辑
现有作业创建代码无需大幅调整,只要PoolSpecification包含了托管标识配置,AutoPool创建时会自动应用该设置:var poolInformation = new PoolInformation { AutoPoolSpecification = new AutoPoolSpecification { AutoPoolIdPrefix = this.autoPoolIdPrefix, PoolLifetimeOption = PoolLifetimeOption.Job, PoolSpecification = GetPoolSpec(), KeepAlive = false } }; job = batchClient.JobOperations.CreateJob(autoPoolJobId, poolInformation);
额外注意事项
- 若使用的
Microsoft.Azure.Batch库版本过旧,无法直接设置ManagedIdentity,则需改用Microsoft.Azure.Management.Batch库的API创建作业和AutoPool,通过该库完成托管标识配置。 - 托管标识需提前创建,同时要确保Batch服务拥有使用该标识的权限,且标识本身具备访问目标资源的权限。
内容的提问来源于stack exchange,提问作者Chris Hayes
相关产品推荐
相关产品推荐

