如何让Bicep调用的脚本使用Azure专用端点连接Azure SQL
强制Deployment Script使用Azure SQL专用端点连接的解决方案
要解决Deployment Script尝试通过公共端点连接Azure SQL失败的问题,核心是让脚本运行在能访问专用端点的网络环境中,并确保DNS正确解析,具体步骤如下:
1. 配置Deployment Script的虚拟网络集成
将Microsoft.Resources/deploymentScripts资源部署到与Azure SQL专用端点同一虚拟网络的子网内,这样脚本就能直接访问专用端点的私有IP。
在Bicep中添加virtualNetwork属性配置:
resource sqlDeploymentScript 'Microsoft.Resources/deploymentScripts@2020-10-01' = { name: 'connect-sql-private-endpoint' location: resourceGroup().location kind: 'AzurePowerShell' properties: { azPowerShellVersion: '7.2' // 你的SQL操作脚本 scriptContent: ''' $sqlServerName = "<你的SQL服务器名>" $dbName = "<你的数据库名>" $miClientId = "<用户托管标识的Client ID>" $connectionString = "Server=tcp:$sqlServerName.database.windows.net,1433;Initial Catalog=$dbName;Authentication=Active Directory Managed Identity;Encrypt=True" $sqlConnection = New-Object System.Data.SqlClient.SqlConnection($connectionString) try { $sqlConnection.Open() Write-Host "成功通过专用端点连接到Azure SQL" // 执行你的SQL操作 } catch { Write-Error "连接失败: $_" } finally { $sqlConnection.Close() } ''' cleanupPreference: 'OnSuccess' // 关联到专用端点所在的VNet和子网 virtualNetwork: { id: yourVnet.id subnetId: yourSubnet.id } // 使用用户托管标识进行SQL身份验证(避免密钥管理) identity: { type: 'UserAssigned' userAssignedIdentities: { '<用户托管标识资源ID>': {} } } } }
2. 确保DNS正确解析专用端点
- 确认你的虚拟网络已关联
privatelink.database.windows.net私有DNS区域,这样SQL服务器名(如xxx.database.windows.net)会被解析为专用端点的私有IP,无需修改连接字符串。 - 如果未配置私有DNS区域,也可以直接在连接字符串中使用专用端点的私有IP,但不推荐(IP可能变动)。
3. 验证网络权限
- 检查Deployment Script所在子网的网络安全组(NSG),确保允许出站TCP 1433端口的流量。
- 确认Azure SQL服务器的防火墙设置为
拒绝公共网络访问,且专用端点的网络策略已正确配置(允许来自目标子网的访问)。
内容的提问来源于stack exchange,提问作者Don Chambers
相关产品推荐
相关产品推荐

