You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Azure DevOps流水线实现多层级Azure标签策略自动化的技术咨询

Azure资源标签强制管控的DevOps自动化方案

一、可集成到Azure DevOps的ARM模板示例

1. 订阅级标签管控Policy ARM模板

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "policyName": {
      "type": "string",
      "defaultValue": "Enforce-Subscription-Tags"
    },
    "policyDescription": {
      "type": "string",
      "defaultValue": "强制订阅级必须包含指定标签st1、st2"
    }
  },
  "resources": [
    {
      "type": "Microsoft.Authorization/policyDefinitions",
      "apiVersion": "2021-06-01",
      "name": "[parameters('policyName')]",
      "properties": {
        "description": "[parameters('policyDescription')]",
        "mode": "All",
        "policyRule": {
          "if": {
            "allOf": [
              {
                "field": "type",
                "equals": "Microsoft.Resources/subscriptions"
              },
              {
                "anyOf": [
                  {
                    "field": "[concat('tags[', 'st1', ']')]",
                    "exists": false
                  },
                  {
                    "field": "[concat('tags[', 'st1', ']')]",
                    "notEquals": "st1"
                  },
                  {
                    "field": "[concat('tags[', 'st2', ']')]",
                    "exists": false
                  },
                  {
                    "field": "[concat('tags[', 'st2', ']')]",
                    "notEquals": "st2"
                  }
                ]
              }
            ]
          },
          "then": {
            "effect": "deny"
          }
        }
      }
    },
    {
      "type": "Microsoft.Authorization/policyAssignments",
      "apiVersion": "2021-06-01",
      "name": "[concat(parameters('policyName'), '-Assignment')]",
      "dependsOn": [
        "[resourceId('Microsoft.Authorization/policyDefinitions', parameters('policyName'))]"
      ],
      "properties": {
        "policyDefinitionId": "[resourceId('Microsoft.Authorization/policyDefinitions', parameters('policyName'))]",
        "scope": "[subscription().id]"
      }
    }
  ]
}

2. 资源组级标签管控Policy ARM模板

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "policyName": {
      "type": "string",
      "defaultValue": "Enforce-ResourceGroup-Tags"
    },
    "policyDescription": {
      "type": "string",
      "defaultValue": "强制资源组必须包含指定标签rt1、rt2"
    }
  },
  "resources": [
    {
      "type": "Microsoft.Authorization/policyDefinitions",
      "apiVersion": "2021-06-01",
      "name": "[parameters('policyName')]",
      "properties": {
        "description": "[parameters('policyDescription')]",
        "mode": "All",
        "policyRule": {
          "if": {
            "allOf": [
              {
                "field": "type",
                "equals": "Microsoft.Resources/resourceGroups"
              },
              {
                "anyOf": [
                  {
                    "field": "[concat('tags[', 'rt1', ']')]",
                    "exists": false
                  },
                  {
                    "field": "[concat('tags[', 'rt1', ']')]",
                    "notEquals": "rt1"
                  },
                  {
                    "field": "[concat('tags[', 'rt2', ']')]",
                    "exists": false
                  },
                  {
                    "field": "[concat('tags[', 'rt2', ']')]",
                    "notEquals": "rt2"
                  }
                ]
              }
            ]
          },
          "then": {
            "effect": "deny"
          }
        }
      }
    },
    {
      "type": "Microsoft.Authorization/policyAssignments",
      "apiVersion": "2021-06-01",
      "name": "[concat(parameters('policyName'), '-Assignment')]",
      "dependsOn": [
        "[resourceId('Microsoft.Authorization/policyDefinitions', parameters('policyName'))]"
      ],
      "properties": {
        "policyDefinitionId": "[resourceId('Microsoft.Authorization/policyDefinitions', parameters('policyName'))]",
        "scope": "[subscription().id]"
      }
    }
  ]
}

3. 特定资源类型标签管控Policy ARM模板

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "policyName": {
      "type": "string",
      "defaultValue": "Enforce-SpecificResource-Tags"
    },
    "policyDescription": {
      "type": "string",
      "defaultValue": "强制AKS、App Service、存储账户必须包含指定标签"
    },
    "requiredTags": {
      "type": "object",
      "defaultValue": {
        "env": "prod",
        "costCenter": "IT001"
      }
    }
  },
  "variables": {
    "targetResourceTypes": [
      "Microsoft.ContainerService/managedClusters",
      "Microsoft.Web/sites",
      "Microsoft.Storage/storageAccounts"
    ]
  },
  "resources": [
    {
      "type": "Microsoft.Authorization/policyDefinitions",
      "apiVersion": "2021-06-01",
      "name": "[parameters('policyName')]",
      "properties": {
        "description": "[parameters('policyDescription')]",
        "mode": "Indexed",
        "policyRule": {
          "if": {
            "allOf": [
              {
                "field": "type",
                "in": "[variables('targetResourceTypes')]"
              },
              {
                "anyOf": "[concat('[', string(join(',', map(parameters('requiredTags'), (key, value) => { return { 'field': concat('tags[', key, ']'), 'notEquals': value } }))), ']')]"
              }
            ]
          },
          "then": {
            "effect": "deny"
          }
        }
      }
    },
    {
      "type": "Microsoft.Authorization/policyAssignments",
      "apiVersion": "2021-06-01",
      "name": "[concat(parameters('policyName'), '-Assignment')]",
      "dependsOn": [
        "[resourceId('Microsoft.Authorization/policyDefinitions', parameters('policyName'))]"
      ],
      "properties": {
        "policyDefinitionId": "[resourceId('Microsoft.Authorization/policyDefinitions', parameters('policyName'))]",
        "scope": "[subscription().id]"
      }
    }
  ]
}

二、Azure DevOps集成Shell脚本示例

1. ARM模板部署脚本(Linux环境)

#!/bin/bash

# DevOps流水线中可通过Azure资源服务连接自动完成身份验证,无需手动执行登录命令
# az login --service-principal -u $AZURE_CLIENT_ID -p $AZURE_CLIENT_SECRET --tenant $AZURE_TENANT_ID

# 部署订阅级标签Policy
az deployment sub create \
  --name Deploy-Subscription-Tag-Policy \
  --location "eastus" \
  --template-file ./policies/subscription-tag-policy.json

# 部署资源组级标签Policy
az deployment sub create \
  --name Deploy-ResourceGroup-Tag-Policy \
  --location "eastus" \
  --template-file ./policies/resourcegroup-tag-policy.json

# 部署特定资源类型标签Policy
az deployment sub create \
  --name Deploy-SpecificResource-Tag-Policy \
  --location "eastus" \
  --template-file ./policies/specificresource-tag-policy.json

2. 剩余标签批量添加脚本

#!/bin/bash

# 定义需要补充的标签
EXTRA_TAGS="owner=dev-team project=azure-tagging"

# 为订阅添加剩余标签
az tag update \
  --resource-id "/subscriptions/$AZURE_SUBSCRIPTION_ID" \
  --operation merge \
  --tags $EXTRA_TAGS

# 为所有资源组添加剩余标签
RESOURCE_GROUPS=$(az group list --query "[].id" -o tsv)
for rg in $RESOURCE_GROUPS; do
  az tag update \
    --resource-id $rg \
    --operation merge \
    --tags $EXTRA_TAGS
done

# 为目标资源类型添加剩余标签
TARGET_RESOURCES=$(az resource list --resource-type "Microsoft.ContainerService/managedClusters" --query "[].id" -o tsv)
TARGET_RESOURCES+=" $(az resource list --resource-type "Microsoft.Web/sites" --query "[].id" -o tsv)"
TARGET_RESOURCES+=" $(az resource list --resource-type "Microsoft.Storage/storageAccounts" --query "[].id" -o tsv)"

for res in $TARGET_RESOURCES; do
  az tag update \
    --resource-id $res \
    --operation merge \
    --tags $EXTRA_TAGS
done

三、实践建议

  • 权限配置:确保Azure DevOps使用的服务主体拥有Policy Contributor和Resource Policy Contributor权限,避免部署或标签操作失败。
  • 模板参数化:将标签键值对、目标资源类型等配置抽为ARM模板参数,方便不同环境(测试/生产)快速复用调整。
  • 增量部署:在流水线中添加条件判断,仅当Policy定义或分配内容有变更时才执行部署,减少冗余操作。
  • 合规验证:部署完成后,添加az policy state list命令检查资源合规状态,确认标签管控规则生效。
  • 脚本容错:在Shell脚本中加入set -e开启错误捕获,关键操作添加重试机制,避免因网络波动导致流水线中断。
  • 标签优先级:明确Policy强制标签和手动补充标签的优先级,Policy规则会阻止不符合要求的资源创建,手动标签仅做补充,避免冲突。

内容的提问来源于stack exchange,提问作者Vowneee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 10:20:35