如何通过ARM模板为Azure Logic App配置系统托管标识的SQL API连接?
解决方法
你遇到的错误是因为SQL的Managed API不支持parameterValueType: Alternative配置,这个参数仅适用于事件网格这类特定服务。要通过ARM模板为Logic App使用系统托管标识创建SQL API连接,需按以下方式修改模板:
1. 修改API连接(Microsoft.Web/connections)配置
移除parameterValueType: Alternative,添加authenticationType: "ManagedServiceIdentity",并在nonSecretParameterValues中指定SQL服务器和数据库名称:
{ "type": "Microsoft.Web/connections", "apiVersion": "2016-06-01", "name": "[parameters('connections_sql_name')]", "location": "westeurope", "kind": "V1", "properties": { "displayName": "SQL", "statuses": [ { "status": "Ready" } ], "customParameterValues": {}, "nonSecretParameterValues": { "sqlServer": "[parameters('sqlServerName')]", "databaseName": "[parameters('sqlDatabaseName')]" }, "api": { "id": "[concat('/subscriptions/',subscription().subscriptionId,'/providers/Microsoft.Web/locations/',parameters('logicAppLocation'),'/managedApis/sql')]" }, "authenticationType": "ManagedServiceIdentity" }, "dependsOn": [ "[resourceId('Microsoft.Logic/workflows', parameters('logicAppName'))]" ] }
2. 确保Logic App启用系统托管标识
在Logic App的资源定义中添加identity配置,启用系统分配的托管标识:
{ "type": "Microsoft.Logic/workflows", "apiVersion": "2017-07-01", "name": "[parameters('logicAppName')]", "location": "[parameters('logicAppLocation')]", "identity": { "type": "SystemAssigned" }, "properties": { "state": "Enabled", // 你的逻辑应用定义及其他属性 ... } }
额外注意事项
- API连接必须通过
dependsOn依赖于Logic App,确保Logic App的托管标识先创建完成 - 需要给Logic App的系统托管标识分配SQL数据库的权限(如
db_datareader、db_datawriter或自定义角色),可通过ARM模板添加角色分配资源,或手动在Azure门户配置
内容的提问来源于stack exchange,提问作者linmic
相关产品推荐
相关产品推荐

