如何配置策略确保Azure ASE v3仅允许部署Azure Functions
仅允许在ASE v3中部署Azure Functions的解决方案
要实现仅在ASE v3环境中部署Azure Functions、禁止Web Apps和Standard Logic Apps的需求,核心是通过资源属性区分不同类型的Microsoft.Web/sites资源,再配合Azure Policy强制执行限制。
如何区分Azure Functions与其他Microsoft.Web/sites资源
1. 通过kind属性识别
Microsoft.Web/sites资源的kind属性会明确标识其类型:
- Azure Functions(含Linux/Windows变体):
kind包含functionapp(如functionapp、functionapp,linux) - Web Apps:
kind为app或带环境后缀(如app,linux) - Standard Logic Apps(ASE中部署的类型):
kind为workflow
2. 通过运行时配置双重验证
为了避免属性被篡改导致规则失效,可结合运行时配置进一步验证:
- Linux环境:检查
properties.siteConfig.linuxFxVersion,值以FUNCTIONS|开头(如FUNCTIONS|4) - Windows环境:检查
properties.siteConfig.windowsFxVersion,值以AzureFunctionsRuntime:开头(如AzureFunctionsRuntime:~4)
用Azure Policy强制执行限制
创建以下Azure Policy规则,拒绝所有非Azure Functions类型的Microsoft.Web/sites资源部署到ASE v3环境:
基础版(基于kind属性)
{ "mode": "All", "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Web/sites" }, { "not": { "field": "kind", "contains": "functionapp" } }, // 可选:仅针对目标ASE v3环境生效 { "field": "Microsoft.Web/serverfarms/id", "contains": "/serverfarms/你的ASE名称" } ] }, "then": { "effect": "deny" } }, "parameters": {} }
严谨版(结合运行时配置)
{ "mode": "All", "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Web/sites" }, { "not": { "anyOf": [ { "field": "kind", "contains": "functionapp" }, { "field": "properties.siteConfig.linuxFxVersion", "like": "FUNCTIONS|*" }, { "field": "properties.siteConfig.windowsFxVersion", "like": "AzureFunctionsRuntime:*" } ] } }, // 可选:仅针对目标ASE v3环境生效 { "field": "Microsoft.Web/serverfarms/id", "contains": "/serverfarms/你的ASE名称" } ] }, "then": { "effect": "deny" } }, "parameters": {} }
注意事项
- 如果需要仅对特定ASE v3环境生效,取消上述代码中
Microsoft.Web/serverfarms/id条件的注释,并替换为你的ASE资源名称。 - 部署Policy后,需将其分配到ASE所在的资源组或订阅,确保规则生效。
内容的提问来源于stack exchange,提问作者GilliVilla
相关产品推荐
相关产品推荐

