创建Event Grid系统主题事件订阅时启用系统分配托管标识的Azure CLI命令
创建Event Grid系统主题事件订阅并启用系统分配托管标识的Azure CLI命令
直接使用az eventgrid system-topic event-subscription create命令,通过--enable-system-assigned-identity参数启用系统分配托管标识,具体命令示例如下:
az eventgrid system-topic event-subscription create \ --resource-group <你的资源组名称> \ --system-topic-name <你的系统主题名称> \ --name <事件订阅名称> \ --endpoint <目标端点,例如:/subscriptions/<订阅ID>/resourceGroups/<资源组>/providers/Microsoft.Storage/storageAccounts/<存储账户名>/queueServices/default/queues/<队列名>> \ --enable-system-assigned-identity
参数说明
--enable-system-assigned-identity:核心参数,用于启用事件订阅的系统分配托管标识- 其余参数为创建事件订阅的必填项,需根据实际环境替换占位符内容
可选:为托管标识分配权限
创建完成后,你需要为这个系统分配标识授予目标资源的访问权限(比如向存储队列发送事件需要Storage Queue Data Contributor角色),步骤如下:
- 先获取事件订阅的系统分配标识主体ID:
az eventgrid system-topic event-subscription show \ --resource-group <你的资源组名称> \ --system-topic-name <你的系统主题名称> \ --name <事件订阅名称> \ --query identity.principalId -o tsv
- 使用上述获取的主体ID分配角色:
az role assignment create \ --assignee <上一步获取的主体ID> \ --role "Storage Queue Data Contributor" \ --scope <目标资源的范围,例如:/subscriptions/<订阅ID>/resourceGroups/<资源组>/providers/Microsoft.Storage/storageAccounts/<存储账户名>>
内容的提问来源于stack exchange,提问作者sneha
相关产品推荐
相关产品推荐

