You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置策略确保Azure ASE v3仅允许部署Azure Functions

仅允许在ASE v3中部署Azure Functions的解决方案

要实现仅在ASE v3环境中部署Azure Functions、禁止Web Apps和Standard Logic Apps的需求,核心是通过资源属性区分不同类型的Microsoft.Web/sites资源,再配合Azure Policy强制执行限制。

如何区分Azure Functions与其他Microsoft.Web/sites资源

1. 通过kind属性识别

Microsoft.Web/sites资源的kind属性会明确标识其类型:

  • Azure Functions(含Linux/Windows变体):kind包含functionapp(如functionapp、functionapp,linux)
  • Web Apps:kind为app或带环境后缀(如app,linux)
  • Standard Logic Apps(ASE中部署的类型):kind为workflow

2. 通过运行时配置双重验证

为了避免属性被篡改导致规则失效,可结合运行时配置进一步验证:

  • Linux环境:检查properties.siteConfig.linuxFxVersion,值以FUNCTIONS|开头(如FUNCTIONS|4)
  • Windows环境:检查properties.siteConfig.windowsFxVersion,值以AzureFunctionsRuntime:开头(如AzureFunctionsRuntime:~4)

用Azure Policy强制执行限制

创建以下Azure Policy规则,拒绝所有非Azure Functions类型的Microsoft.Web/sites资源部署到ASE v3环境:

基础版(基于kind属性)

{
  "mode": "All",
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Web/sites"
        },
        {
          "not": {
            "field": "kind",
            "contains": "functionapp"
          }
        },
        // 可选:仅针对目标ASE v3环境生效
        {
          "field": "Microsoft.Web/serverfarms/id",
          "contains": "/serverfarms/你的ASE名称"
        }
      ]
    },
    "then": {
      "effect": "deny"
    }
  },
  "parameters": {}
}

严谨版(结合运行时配置)

{
  "mode": "All",
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Web/sites"
        },
        {
          "not": {
            "anyOf": [
              {
                "field": "kind",
                "contains": "functionapp"
              },
              {
                "field": "properties.siteConfig.linuxFxVersion",
                "like": "FUNCTIONS|*"
              },
              {
                "field": "properties.siteConfig.windowsFxVersion",
                "like": "AzureFunctionsRuntime:*"
              }
            ]
          }
        },
        // 可选:仅针对目标ASE v3环境生效
        {
          "field": "Microsoft.Web/serverfarms/id",
          "contains": "/serverfarms/你的ASE名称"
        }
      ]
    },
    "then": {
      "effect": "deny"
    }
  },
  "parameters": {}
}

注意事项

  • 如果需要仅对特定ASE v3环境生效,取消上述代码中Microsoft.Web/serverfarms/id条件的注释,并替换为你的ASE资源名称。
  • 部署Policy后,需将其分配到ASE所在的资源组或订阅,确保规则生效。

内容的提问来源于stack exchange,提问作者GilliVilla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 19:36:20