You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Bicep为Azure函数应用添加Service Tag访问限制

如何通过Bicep为Azure Function App添加服务标签(Service Tag)访问限制

可以通过Bicep为Azure Function App添加基于服务标签的访问限制,实际上**ipSecurityRestrictions**配置项支持服务标签类型的规则,只是需要指定对应的参数。

你可以在siteConfig.ipSecurityRestrictions数组中添加包含serviceTag属性的规则,不需要填写ipAddress或subnetMask。以下是针对AzureDevOps服务标签的示例Bicep代码:

resource functionApp 'Microsoft.Web/sites@2023-01-01' = {
  name: 'your-function-app-name'
  location: resourceGroup().location
  properties: {
    serverFarmId: appServicePlan.id
    siteConfig: {
      ipSecurityRestrictions: [
        {
          name: 'AllowAzureDevOps'
          priority: 100
          action: 'Allow'
          serviceTag: 'AzureDevOps'
          description: 'Allow traffic from AzureDevOps service tag'
        }
      ]
    }
  }
}

关键参数说明:

  • serviceTag: 指定要允许/拒绝的服务标签名称(比如AzureDevOps),可参考Azure官方的服务标签列表获取有效值
  • priority: 规则优先级,数值越小优先级越高,避免被其他规则覆盖
  • action: 设置为Allow或Deny,定义规则的行为
  • name和description: 用于标识和说明规则,方便后续管理

部署这个Bicep模板后,就能实现和门户中设置完全一致的服务标签访问限制效果。

内容的提问来源于stack exchange,提问作者Steve

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 18:57:38