如何通过交互式认证访问Azure Blob存储(无需密钥/令牌)
交互式认证访问Azure Blob存储(无需密钥/令牌硬编码)
Azure Blob存储支持通过Azure AD交互式认证访问,在R中可以借助AzureStor和AzureAuth包实现类似你提到的Azure SQL交互式认证流程,以下是具体步骤:
1. 安装依赖包
首先安装并加载所需的R包:
install.packages(c("AzureStor", "AzureAuth")) library(AzureStor) library(AzureAuth)
2. 获取交互式Azure AD令牌
使用get_azure_token函数触发交互式登录(会自动弹出浏览器让你完成Azure AD账号登录),需要指定Blob存储的资源ID、你的租户ID,以及一个通用的客户端ID(这里用Azure CLI的公共客户端ID,无需自行注册应用):
# 替换为你的Azure租户ID(可在Azure门户的Azure AD中找到) tenant_id <- "your-azure-tenant-id" # 获取交互式令牌 token <- get_azure_token( resource = "https://storage.azure.com/", tenant = tenant_id, app = "04b07795-8ddb-461a-bbee-02f9e1bf7b46", # Azure CLI公共客户端ID auth_type = "authorization_code" )
3. 连接Azure Blob存储账户
用获取到的令牌连接你的存储账户,之后就可以操作容器和Blob:
# 替换为你的存储账户名称 storage_account_name <- "your-storage-account-name" # 建立存储账户连接 storage_acct <- storage_account(storage_account_name, token = token) # 示例:列出存储账户下的所有容器 list_storage_containers(storage_acct) # 示例:访问指定容器并下载Blob target_container <- storage_container(storage_acct, "your-container-name") download_blob(target_container, "path/to/remote/blob.txt", "local/save/path.txt")
常见问题说明
- 若之前使用AzureR系列包失败,大概率是资源ID指定错误(Blob存储的资源ID是
https://storage.azure.com/,不要误用其他服务的资源ID),或者租户ID/客户端ID配置不正确。 - 如果在无图形界面的环境中运行,可将
auth_type改为device_code,此时会生成一个设备码,你需要在另一台设备的浏览器中输入该码完成登录。
内容的提问来源于stack exchange,提问作者nleiserowitz
相关产品推荐
相关产品推荐

