You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell/Bicep为Azure Container App添加第二个身份提供商

给Azure Container App添加第二个身份验证提供商(Bicep/PowerShell实现)

一、使用Bicep脚本更新

直接在现有Container App的Bicep模板中扩展身份验证配置,添加第二个应用注册对应的身份提供商。如果是Microsoft Entra ID应用,可通过openIdConnectProviders节点配置:

resource containerApp 'Microsoft.App/containerApps@2023-05-01' = {
  name: 'your-container-app-name'
  location: resourceGroup().location
  properties: {
    configuration: {
      auth: {
        enabled: true
        identityProviders: {
          // 保留已有的身份提供商配置
          azureActiveDirectory: {
            registration: {
              clientId: 'existing-app-client-id'
              clientSecretSecretRef: 'existing-secret-name'
              tenantId: subscription().tenantId
            }
            login: { loginParameters: [] }
          }
          // 添加第二个应用注册作为OIDC提供商
          openIdConnectProviders: {
            secondEntraProvider: {
              registration: {
                clientId: 'second-app-client-id'
                clientSecretSecretRef: 'second-secret-name'
                openIdConnectConfiguration: {
                  wellKnownOpenIdConfiguration: 'https://login.microsoftonline.com/${subscription().tenantId}/v2.0/.well-known/openid-configuration'
                }
              }
              login: { loginParameters: [] }
            }
          }
        }
        login: { allowedExternalRedirectUrls: [] }
        globalValidation: {
          requireAuthentication: true
          unauthenticatedClientAction: 'RedirectToLoginPage'
        }
      }
    }
    // 保留其他Container App原有配置(如模板、环境变量等)
  }
}
  • 提前确保第二个应用注册的客户端密钥已存入Container App的秘密存储(可通过Bicep的secrets节点添加)。
  • 若第二个提供商是非Entra的OIDC服务,只需替换wellKnownOpenIdConfiguration为对应服务商的配置地址。

二、使用PowerShell命令更新

通过Azure PowerShell模块直接修改现有Container App的身份验证配置:

  1. 获取目标Container App的当前配置:
$containerApp = Get-AzContainerApp -Name "your-container-app-name" -ResourceGroupName "your-resource-group"
  1. 构建第二个身份提供商的配置对象:
$newOidcProvider = @{
  secondProvider = @{
    Registration = @{
      ClientId = "second-app-client-id"
      ClientSecretSecretRef = "second-secret-name"
      OpenIdConnectConfiguration = @{
        WellKnownOpenIdConfiguration = "https://login.microsoftonline.com/your-tenant-id/v2.0/.well-known/openid-configuration"
      }
    }
    Login = @{ LoginParameters = @() }
  }
}
  1. 合并配置并更新Container App:
# 合并现有OIDC提供商与新配置
$updatedIdentityProviders = $containerApp.Configuration.Auth.IdentityProviders
$updatedIdentityProviders.OpenIdConnectProviders += $newOidcProvider

# 提交更新
Set-AzContainerApp -Name "your-container-app-name" -ResourceGroupName "your-resource-group" `
  -AuthConfiguration @{
    Enabled = $true
    IdentityProviders = $updatedIdentityProviders
    Login = $containerApp.Configuration.Auth.Login
    GlobalValidation = $containerApp.Configuration.Auth.GlobalValidation
  }
  • 若要添加的是第二个Entra ID身份提供商,也可调整配置到AzureActiveDirectory节点,但多应用场景下推荐用OIDC提供商方式管理。
  • 若密钥未提前添加,可先用New-AzContainerAppSecret命令将客户端密钥存入Container App。

内容的提问来源于stack exchange,提问作者Bart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 13:50:39