You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure ARM模板中获取网站公网IP并配置到存储账户允许列表

实现方法

1. 核心逻辑说明

Azure App Service(网站)的公网访问IP分为两种:

  • 出站IP:网站对外访问(比如调用存储账户API)时使用的IP,由其关联的应用服务计划分配,是存储账户防火墙需要放行的目标IP。
  • 静态入站IP:仅用于外部访问网站,若网站通过此IP访问存储账户,仍需使用出站IP。

在ARM模板中,我们通过reference函数动态获取网站的出站IP列表,再将这些IP添加到存储账户的防火墙允许规则中。

2. 完整ARM模板示例

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    // 应用服务计划
    {
      "type": "Microsoft.Web/serverfarms",
      "apiVersion": "2022-03-01",
      "name": "[variables('appServicePlanName')]",
      "location": "[resourceGroup().location]",
      "sku": {
        "name": "S1",
        "tier": "Standard"
      }
    },
    // 网站资源
    {
      "type": "Microsoft.Web/sites",
      "apiVersion": "2022-03-01",
      "name": "[variables('webSiteName')]",
      "location": "[resourceGroup().location]",
      "dependsOn": [
        "[resourceId('Microsoft.Web/serverfarms', variables('appServicePlanName'))]"
      ],
      "properties": {
        "serverFarmId": "[resourceId('Microsoft.Web/serverfarms', variables('appServicePlanName'))]"
      }
    },
    // 存储账户(动态添加网站出站IP到防火墙)
    {
      "type": "Microsoft.Storage/storageAccounts",
      "apiVersion": "2022-09-01",
      "name": "[variables('storageAccountName')]",
      "location": "[resourceGroup().location]",
      "sku": {
        "name": "Standard_LRS"
      },
      "kind": "StorageV2",
      "properties": {
        "networkAcls": {
          "defaultAction": "Deny",
          "ipRules": [
            // 拆分出站IP列表,逐个添加允许规则
            {
              "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[0]]",
              "action": "Allow"
            },
            {
              "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[1]]",
              "action": "Allow"
            },
            {
              "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[2]]",
              "action": "Allow"
            },
            {
              "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[3]]",
              "action": "Allow"
            }
          ]
        }
      },
      "dependsOn": [
        "[resourceId('Microsoft.Web/sites', variables('webSiteName'))]"
      ]
    }
  ],
  "variables": {
    "appServicePlanName": "myAppPlan",
    "webSiteName": "myUniqueWebSite",
    "storageAccountName": "mystorage123xyz"
  }
}

3. 关键细节

  • 依赖关系:存储账户必须依赖网站资源,确保网站创建完成后再获取其IP地址,避免部署时出现资源未就绪的错误。
  • 出站IP数量:不同SKU的App Service出站IP数量不同:Free/Basic SKU有2个,Standard及以上SKU至少有4个,需根据实际SKU添加所有IP,避免遗漏导致网站无法访问存储账户。
  • 静态出站IP场景:若网站使用Premium SKU并配置了静态出站IP,可直接将该静态IP填入ipRules的value字段,无需拆分字符串。

内容的提问来源于stack exchange,提问作者frank

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 00:41:58