循环多Azure订阅时Get-AzWebApp无法返回TLS信息问题
问题原因
当你用Get-AzWebApp不带参数批量获取订阅下所有Web应用时,Azure PowerShell返回的是精简版对象,SiteConfig下的MinTlsVersion属于延迟加载属性,不会默认返回;而指定资源组和应用名称单独获取时,会拉取完整的资源详情,所以能拿到TLS版本信息。
解决方法
下面提供两种可行的修改方案:
方案1:重新获取单个Web应用的完整信息
在遍历每个Web应用时,单独调用Get-AzWebApp获取完整对象,确保拿到MinTlsVersion:
$arrSubs | ForEach-Object { $null = Set-AzContext -SubscriptionId $_.Id -WarningAction "SilentlyContinue" $subscriptionName = $_.Name $subscriptionId = $_.SubscriptionId # 遍历每个WebApp,单独获取完整信息 $objresources = Get-AzWebApp | ForEach-Object { $fullWebApp = Get-AzWebApp -ResourceGroupName $_.ResourceGroupName -Name $_.Name [PSCustomObject]@{ SubscriptionName = $subscriptionName SubscriptionId = $subscriptionId ResourceGroupName = $fullWebApp.ResourceGroupName ResourceName = $fullWebApp.Name Kind = $fullWebApp.Kind Location = $fullWebApp.Location tls = $fullWebApp.SiteConfig.MinTlsVersion HtpsOnly = $fullWebApp.HttpsOnly } } if ($null -eq $objresources){ Write-Output "No Web/Function Apps found in subscription $subscriptionName" } elseif (($objresources | Measure-Object).Count -eq 1) { [void]$resources.Add($objresources) Write-Output "1 Web/Function App found in subscription $subscriptionName" } elseif (($objresources | Measure-Object).Count -gt 1) { [void]$resources.AddRange($objresources) Write-Output "Multiple Web/Function Apps found in subscription $subscriptionName" } Write-Verbose "`t+++ Success `n" }
方案2:使用Get-AzResource直接读取完整属性
通过Get-AzResource获取Web应用的完整属性集合,直接提取siteConfig中的TLS版本:
$arrSubs | ForEach-Object { $null = Set-AzContext -SubscriptionId $_.Id -WarningAction "SilentlyContinue" $subscriptionName = $_.Name $subscriptionId = $_.SubscriptionId # 使用Get-AzResource获取完整属性 $objresources = Get-AzResource -ResourceType Microsoft.Web/sites | ForEach-Object { [PSCustomObject]@{ SubscriptionName = $subscriptionName SubscriptionId = $subscriptionId ResourceGroupName = $_.ResourceGroupName ResourceName = $_.Name Kind = $_.Kind Location = $_.Location tls = $_.Properties.siteConfig.minTlsVersion HtpsOnly = $_.Properties.httpsOnly } } if ($null -eq $objresources){ Write-Output "No Web/Function Apps found in subscription $subscriptionName" } elseif (($objresources | Measure-Object).Count -eq 1) { [void]$resources.Add($objresources) Write-Output "1 Web/Function App found in subscription $subscriptionName" } elseif (($objresources | Measure-Object).Count -gt 1) { [void]$resources.AddRange($objresources) Write-Output "Multiple Web/Function Apps found in subscription $subscriptionName" } Write-Verbose "`t+++ Success `n" }
说明
方案1的优点是完全沿用Get-AzWebApp的对象结构,无需调整属性路径;方案2的效率更高,因为只需要一次API调用就能获取所有Web应用的完整属性,避免多次单独请求。
内容的提问来源于stack exchange,提问作者user22067338
相关产品推荐
相关产品推荐

