You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Bicep为Azure SQL Server防火墙配置多个独立IP?

配置Azure SQL Server多IP防火墙规则的Bicep最佳实践

1. 定义参数结构

首先在Bicep模板里定义一个数组类型的参数,用来接收多个IP规则,每个规则包含规则名称、起始IP和结束IP:

param sqlServerName string
param firewallRules array = [
  {
    ruleName: 'AllowOfficeIP'
    startIpAddress: '192.168.1.1'
    endIpAddress: '192.168.1.1'
  }
  {
    ruleName: 'AllowHomeIP'
    startIpAddress: '10.0.0.1'
    endIpAddress: '10.0.0.10'
  }
]

2. 使用循环批量创建防火墙规则

利用Bicep的for循环遍历参数数组,批量关联到已配置的SQL Server资源:

// 引用已存在的SQL Server资源(如果是模板内创建的资源,直接用其符号名)
resource sqlServer 'Microsoft.Sql/servers@2022-05-01-preview' existing = {
  name: sqlServerName
}

// 遍历数组创建多个防火墙规则
resource sqlFirewallRules 'Microsoft.Sql/servers/firewallRules@2022-05-01-preview' = [for rule in firewallRules: {
  parent: sqlServer
  name: rule.ruleName
  properties: {
    startIpAddress: rule.startIpAddress
    endIpAddress: rule.endIpAddress
  }
}]

3. 配合外部JSON参数文件使用

如果需要通过外部JSON参数文件传递规则,创建如下格式的参数文件(示例命名为sql-firewall-params.json):

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "sqlServerName": {
      "value": "your-target-sql-server"
    },
    "firewallRules": {
      "value": [
        {
          "ruleName": "AllowDevTeamSubnet",
          "startIpAddress": "172.16.0.0",
          "endIpAddress": "172.16.0.255"
        },
        {
          "ruleName": "AllowBuildServer",
          "startIpAddress": "13.80.0.1",
          "endIpAddress": "13.80.0.1"
        },
        {
          "ruleName": "AllowRemoteWorker",
          "startIpAddress": "203.0.113.5",
          "endIpAddress": "203.0.113.5"
        }
      ]
    }
  }
}

部署时指定该参数文件即可:

az deployment group create --resource-group your-resource-group --template-file main.bicep --parameters sql-firewall-params.json

4. 常见问题与注意事项

  • 语法错误排查:确保JSON参数文件中的键名与Bicep模板的参数定义完全匹配,比如ruleName不能大小写错误或拼写错误;
  • 规则名称唯一性:每个防火墙规则的名称在目标SQL Server下必须唯一,参数数组中避免重复的ruleName;
  • IP格式校验:必须使用合法的IPv4地址,且startIpAddress不能大于endIpAddress;
  • 权限要求:部署账号需拥有SQL Server的Microsoft.Sql/servers/firewallRules/write权限。

内容的提问来源于stack exchange,提问作者gc23

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 20:20:23