如何通过Azure CLI获取应用网关用户分配标识的principalId值
正确的Azure CLI查询语法提取用户分配标识的principalId
因为顶层principalId对应系统分配标识(当前为null说明未启用系统分配标识),你需要针对userAssignedIdentities节点查询用户分配标识的principalId,具体分两种场景:
单个用户分配标识的场景
如果userAssignedIdentities下仅存在一个标识,直接用通配符匹配提取:
az network application-gateway identity show --gateway-name "xxx-inf-abc-wag" --resource-group "network-xxx" --query "userAssignedIdentities.*.principalId" -o tsv
若已知用户分配标识的完整资源ID,也可以精准定位:
az network application-gateway identity show --gateway-name "xxx-inf-abc-wag" --resource-group "network-xxx" --query "userAssignedIdentities['/subscriptions/{订阅ID}/resourceGroups/{资源组名}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{标识名称}'].principalId" -o tsv
多个用户分配标识的场景
如果存在多个用户分配标识,要提取所有标识的principalId,可以用:
az network application-gateway identity show --gateway-name "xxx-inf-abc-wag" --resource-group "network-xxx" --query "userAssignedIdentities | values(@)[*].principalId" -o tsv
语法说明
--query使用JMESPath语法,userAssignedIdentities.*匹配该节点下所有子项,.principalId提取目标字段-o tsv用于输出纯文本格式结果,方便后续脚本调用,不需要可直接移除
内容的提问来源于stack exchange,提问作者Ian Carrick
相关产品推荐
相关产品推荐

