如何使用Bicep为Azure函数应用添加Service Tag访问限制
如何通过Bicep为Azure Function App添加服务标签(Service Tag)访问限制
可以通过Bicep为Azure Function App添加基于服务标签的访问限制,实际上**ipSecurityRestrictions**配置项支持服务标签类型的规则,只是需要指定对应的参数。
你可以在siteConfig.ipSecurityRestrictions数组中添加包含serviceTag属性的规则,不需要填写ipAddress或subnetMask。以下是针对AzureDevOps服务标签的示例Bicep代码:
resource functionApp 'Microsoft.Web/sites@2023-01-01' = { name: 'your-function-app-name' location: resourceGroup().location properties: { serverFarmId: appServicePlan.id siteConfig: { ipSecurityRestrictions: [ { name: 'AllowAzureDevOps' priority: 100 action: 'Allow' serviceTag: 'AzureDevOps' description: 'Allow traffic from AzureDevOps service tag' } ] } } }
关键参数说明:
serviceTag: 指定要允许/拒绝的服务标签名称(比如AzureDevOps),可参考Azure官方的服务标签列表获取有效值priority: 规则优先级,数值越小优先级越高,避免被其他规则覆盖action: 设置为Allow或Deny,定义规则的行为name和description: 用于标识和说明规则,方便后续管理
部署这个Bicep模板后,就能实现和门户中设置完全一致的服务标签访问限制效果。
内容的提问来源于stack exchange,提问作者Steve
相关产品推荐
相关产品推荐

