如何获取Azure租户内所有资源类型(含存储账户子资源)?
解决Azure Resource Graph无法获取存储账户子资源的问题
问题原因
Azure Resource Graph仅索引控制平面级别的资源(如存储账户实例),而Blob容器、队列、表、文件共享属于存储账户的数据平面子资源,不在Resource Graph的默认检索范围内,因此无法直接通过Resource Graph查询到这些子资源。
方案1:使用Azure PowerShell直接查询存储子资源
通过遍历租户内所有存储账户,直接访问数据平面获取子资源,整理成你需要的格式:
# 获取租户内所有存储账户 $storageAccounts = Get-AzStorageAccount # 初始化结果数组 $resourceList = @() # 遍历存储账户,收集自身及子资源信息 foreach ($sa in $storageAccounts) { $context = $sa.Context # 添加存储账户本身 $resourceList += [PSCustomObject]@{ type = $sa.Type kind = $sa.Kind any_id = $sa.Id } # 查询Blob容器 $blobContainers = Get-AzStorageContainer -Context $context foreach ($container in $blobContainers) { $resourceList += [PSCustomObject]@{ type = "Microsoft.Storage/storageAccounts/blobServices/containers" kind = "BlobContainer" any_id = "$($sa.Id)/blobServices/default/containers/$($container.Name)" } } # 查询队列 $queues = Get-AzStorageQueue -Context $context foreach ($queue in $queues) { $resourceList += [PSCustomObject]@{ type = "Microsoft.Storage/storageAccounts/queueServices/queues" kind = "Queue" any_id = "$($sa.Id)/queueServices/default/queues/$($queue.Name)" } } # 查询表 $tables = Get-AzStorageTable -Context $context foreach ($table in $tables) { $resourceList += [PSCustomObject]@{ type = "Microsoft.Storage/storageAccounts/tableServices/tables" kind = "Table" any_id = "$($sa.Id)/tableServices/default/tables/$($table.Name)" } } # 查询文件共享 $fileShares = Get-AzStorageShare -Context $context foreach ($share in $fileShares) { $resourceList += [PSCustomObject]@{ type = "Microsoft.Storage/storageAccounts/fileServices/shares" kind = "FileShare" any_id = "$($sa.Id)/fileServices/default/shares/$($share.Name)" } } } # 去重并按类型排序(匹配原有处理逻辑) $uniqueResources = $resourceList | Group-Object type | ForEach-Object { $_.Group[0] } | Sort-Object -Property type $uniqueResources
方案2:混合使用Resource Graph与数据平面查询
先用Resource Graph高效获取所有存储账户列表,再批量查询子资源,适合租户内存储账户较多的场景:
# 用Resource Graph获取所有存储账户 $query = 'Resources | where type == "Microsoft.Storage/storageAccounts" | project id, type, kind' $restSplat = @{ Uri = 'https://management.azure.com/providers/Microsoft.ResourceGraph/resources?api-version=2020-04-01-preview' Method = 'Post' Body = @{ query = $query managementGroupId = $ManagementGroupId } | ConvertTo-Json ContentType = 'application/json' headers = @{"Authorization" = "Bearer $($AzToken.Token)"} } $storageAccountsFromGraph = Invoke-RestMethod @restSplat # 初始化结果数组,先添加存储账户信息 $resourceList = $storageAccountsFromGraph.data.rows | ForEach-Object { [PSCustomObject]@{ type = $_[1] kind = $_[2] any_id = $_[0] } } # 遍历存储账户ID,查询子资源 foreach ($saRow in $storageAccountsFromGraph.data.rows) { $saId = $saRow[0] # 从资源ID拆分出订阅、资源组、存储账户名 $saParts = $saId -split '/', 8 $subscriptionId = $saParts[2] $resourceGroupName = $saParts[4] $storageAccountName = $saParts[8] # 获取存储账户上下文 $context = New-AzStorageContext -StorageAccountName $storageAccountName -UseConnectedAccount # 以下查询逻辑同方案1,依次添加Blob容器、队列、表、文件共享 $blobContainers = Get-AzStorageContainer -Context $context foreach ($container in $blobContainers) { $resourceList += [PSCustomObject]@{ type = "Microsoft.Storage/storageAccounts/blobServices/containers" kind = "BlobContainer" any_id = "$saId/blobServices/default/containers/$($container.Name)" } } # 队列、表、文件共享的查询代码省略,参考方案1即可 } # 去重并排序 $uniqueResources = $resourceList | Group-Object type | ForEach-Object { $_.Group[0] } | Sort-Object -Property type $uniqueResources
注意事项
- 数据平面查询需要对应权限:如
Storage Blob Data Contributor、Storage Queue Data Contributor等,确保当前账号拥有足够权限访问目标存储子资源。 - 若租户内存储账户数量庞大,建议添加分页或批量处理逻辑,避免请求超时。
内容的提问来源于stack exchange,提问作者Nadia Hansen
相关产品推荐
相关产品推荐

