You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AzureCLI@2任务中WAF策略规则添加多IP地址的正确格式咨询

问题

在AzureCLI@2任务中执行以下脚本时,单个IP地址可正常运行,但配置多个IP地址时失败:

az network front-door waf-policy rule match-condition add \
  --match-variable "SocketAddr" \
  --operator "IPMatch" \
  --values "${{ parameters.stageConfig.ipAddresses }}" \
  --negate "true" \
  --name "DigitalTimecardsAllowedIPs" \
  --resource-group "${{ parameters.stageConfig.resourceGroup }}" \
  --policy-name "${{ parameters.stageConfig.policyName }}"

单个IP的参数配置(可正常工作):

- name: ipAddresses
  displayName: IP Addresses
  type: string
  default: "167.60.67.178" 

尝试过的多种多IP格式均无效:

"192.168.1.1,10.10.1.1"
"192.168.1.1/24,10.10.1.1/24"
"192.168.1.1" "10.10.1.1"
"192.168.1.1","10.10.1.1"
"[192.168.1.1,10.10.1.1]"

收到的错误信息:

Message: WebApplicationFirewallPolicy validation failed. More information "Value 167.60.67.178,20.7.207.27 is not a valid IP Address in rule AllowedIPs".

Azure CLI官方文档示例:

az network front-door waf-policy rule match-condition add \
    --match-variable SocketAddr \
    --operator IPMatch \
    --values "ip-address-range-1" "ip-address-range-2" \
    --negate true \
    --name IPAllowListRule \
      --resource-group <resource-group-name> \
      --policy-name IPAllowPolicyExampleCLI

请问配置多个IP地址时需要使用什么格式?

解决方案

问题核心在于Azure CLI的--values参数需要接收多个独立的字符串值,当前把所有IP打包成单个字符串传递,导致CLI将整个逗号分隔的内容识别为无效IP。

方案1:使用字符串数组类型参数

  1. 修改参数定义为字符串数组,直接传入多个IP:
- name: ipAddresses
  displayName: IP Addresses
  type: string[]
  default: ["167.60.67.178", "20.7.207.27"]
  1. 在CLI脚本中用join函数将数组展开为空格分隔的独立参数:
az network front-door waf-policy rule match-condition add \
  --match-variable "SocketAddr" \
  --operator "IPMatch" \
  --values ${{ join(parameters.stageConfig.ipAddresses, ' ') }} \
  --negate "true" \
  --name "DigitalTimecardsAllowedIPs" \
  --resource-group "${{ parameters.stageConfig.resourceGroup }}" \
  --policy-name "${{ parameters.stageConfig.policyName }}"

方案2:保持字符串类型,用空格分隔IP

如果无法修改参数类型,可将IP用空格作为分隔符传入:

  1. 参数配置:
- name: ipAddresses
  displayName: IP Addresses
  type: string
  default: "167.60.67.178 20.7.207.27"
  1. 脚本中直接传递该参数:
--values ${{ parameters.stageConfig.ipAddresses }}

这种方式会让CLI自动识别出多个独立的IP值,符合命令要求。


内容的提问来源于stack exchange,提问作者fizgig

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 11:23:24