如何通过PowerShell/Bicep为Azure Container App添加第二个身份提供商
给Azure Container App添加第二个身份验证提供商(Bicep/PowerShell实现)
一、使用Bicep脚本更新
直接在现有Container App的Bicep模板中扩展身份验证配置,添加第二个应用注册对应的身份提供商。如果是Microsoft Entra ID应用,可通过openIdConnectProviders节点配置:
resource containerApp 'Microsoft.App/containerApps@2023-05-01' = { name: 'your-container-app-name' location: resourceGroup().location properties: { configuration: { auth: { enabled: true identityProviders: { // 保留已有的身份提供商配置 azureActiveDirectory: { registration: { clientId: 'existing-app-client-id' clientSecretSecretRef: 'existing-secret-name' tenantId: subscription().tenantId } login: { loginParameters: [] } } // 添加第二个应用注册作为OIDC提供商 openIdConnectProviders: { secondEntraProvider: { registration: { clientId: 'second-app-client-id' clientSecretSecretRef: 'second-secret-name' openIdConnectConfiguration: { wellKnownOpenIdConfiguration: 'https://login.microsoftonline.com/${subscription().tenantId}/v2.0/.well-known/openid-configuration' } } login: { loginParameters: [] } } } } login: { allowedExternalRedirectUrls: [] } globalValidation: { requireAuthentication: true unauthenticatedClientAction: 'RedirectToLoginPage' } } } // 保留其他Container App原有配置(如模板、环境变量等) } }
- 提前确保第二个应用注册的客户端密钥已存入Container App的秘密存储(可通过Bicep的
secrets节点添加)。 - 若第二个提供商是非Entra的OIDC服务,只需替换
wellKnownOpenIdConfiguration为对应服务商的配置地址。
二、使用PowerShell命令更新
通过Azure PowerShell模块直接修改现有Container App的身份验证配置:
- 获取目标Container App的当前配置:
$containerApp = Get-AzContainerApp -Name "your-container-app-name" -ResourceGroupName "your-resource-group"
- 构建第二个身份提供商的配置对象:
$newOidcProvider = @{ secondProvider = @{ Registration = @{ ClientId = "second-app-client-id" ClientSecretSecretRef = "second-secret-name" OpenIdConnectConfiguration = @{ WellKnownOpenIdConfiguration = "https://login.microsoftonline.com/your-tenant-id/v2.0/.well-known/openid-configuration" } } Login = @{ LoginParameters = @() } } }
- 合并配置并更新Container App:
# 合并现有OIDC提供商与新配置 $updatedIdentityProviders = $containerApp.Configuration.Auth.IdentityProviders $updatedIdentityProviders.OpenIdConnectProviders += $newOidcProvider # 提交更新 Set-AzContainerApp -Name "your-container-app-name" -ResourceGroupName "your-resource-group" ` -AuthConfiguration @{ Enabled = $true IdentityProviders = $updatedIdentityProviders Login = $containerApp.Configuration.Auth.Login GlobalValidation = $containerApp.Configuration.Auth.GlobalValidation }
- 若要添加的是第二个Entra ID身份提供商,也可调整配置到
AzureActiveDirectory节点,但多应用场景下推荐用OIDC提供商方式管理。 - 若密钥未提前添加,可先用
New-AzContainerAppSecret命令将客户端密钥存入Container App。
内容的提问来源于stack exchange,提问作者Bart
相关产品推荐
相关产品推荐

