Azure DevOps环境下利用Private Endpoint/Private Link保障快照与VHD传输安全性的可行性咨询
Great question! The good news is you absolutely can keep all these operations within Azure's private network—no public internet transit is required for the VHD transfer from snapshots to your storage account. Here's a breakdown of how to implement this securely:
Configure Private Endpoints for Storage Accounts
Set up private endpoints for both the source storage account (where your snapshot's underlying VHD resides) and the target storage account where you'll store the copied VHD. This ensures all traffic between your resources and these storage accounts travels exclusively over Azure's private backbone, not the public internet.Restrict SAS Tokens to Private Networks
When generating SAS tokens for the source snapshot/VHD, don't just create a standard token. Instead, restrict its usage to private networks only:- In the SAS token settings, specify your virtual network's private IP range under
Allowed IP addresses. - Alternatively, enable the "Allow trusted Microsoft services to access this storage account" option alongside private endpoint access. This ensures the token can only be used from within your private network or trusted Azure services.
- In the SAS token settings, specify your virtual network's private IP range under
Initiate Copy Operations from a Privately Connected Client
Use an Azure VM (connected to the same VNet or peered VNet as your storage private endpoints) to run copy commands likeaz snapshot copy start(Azure CLI) orNew-AzDiskCopy(PowerShell). If you need to run commands from your local machine, connect to your Azure VNet via VPN or ExpressRoute to ensure you're accessing the storage accounts through their private endpoints.Validate Private Network Traffic
To confirm no public internet is being used, check your storage account's metrics:- Filter
IngressandEgressmetrics by "Private Endpoint" to see traffic flowing through private channels. - Use Azure Network Watcher's Route Trace tool to verify the traffic path stays within Azure's private network.
- Filter
Pro Tip: Azure's native snapshot copy mechanism will automatically use private network paths when private endpoints are properly configured—you don't need any special flags or workarounds. The key is ensuring all related resources are connected via private links and SAS tokens are locked down to private access only.
内容的提问来源于stack exchange,提问作者Norrin Rad

