如何在Azure ARM模板中获取网站公网IP并配置到存储账户允许列表
实现方法
1. 核心逻辑说明
Azure App Service(网站)的公网访问IP分为两种:
- 出站IP:网站对外访问(比如调用存储账户API)时使用的IP,由其关联的应用服务计划分配,是存储账户防火墙需要放行的目标IP。
- 静态入站IP:仅用于外部访问网站,若网站通过此IP访问存储账户,仍需使用出站IP。
在ARM模板中,我们通过reference函数动态获取网站的出站IP列表,再将这些IP添加到存储账户的防火墙允许规则中。
2. 完整ARM模板示例
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ // 应用服务计划 { "type": "Microsoft.Web/serverfarms", "apiVersion": "2022-03-01", "name": "[variables('appServicePlanName')]", "location": "[resourceGroup().location]", "sku": { "name": "S1", "tier": "Standard" } }, // 网站资源 { "type": "Microsoft.Web/sites", "apiVersion": "2022-03-01", "name": "[variables('webSiteName')]", "location": "[resourceGroup().location]", "dependsOn": [ "[resourceId('Microsoft.Web/serverfarms', variables('appServicePlanName'))]" ], "properties": { "serverFarmId": "[resourceId('Microsoft.Web/serverfarms', variables('appServicePlanName'))]" } }, // 存储账户(动态添加网站出站IP到防火墙) { "type": "Microsoft.Storage/storageAccounts", "apiVersion": "2022-09-01", "name": "[variables('storageAccountName')]", "location": "[resourceGroup().location]", "sku": { "name": "Standard_LRS" }, "kind": "StorageV2", "properties": { "networkAcls": { "defaultAction": "Deny", "ipRules": [ // 拆分出站IP列表,逐个添加允许规则 { "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[0]]", "action": "Allow" }, { "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[1]]", "action": "Allow" }, { "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[2]]", "action": "Allow" }, { "value": "[split(reference(resourceId('Microsoft.Web/sites', variables('webSiteName')), '2022-03-01').outboundIpAddresses, ',')[3]]", "action": "Allow" } ] } }, "dependsOn": [ "[resourceId('Microsoft.Web/sites', variables('webSiteName'))]" ] } ], "variables": { "appServicePlanName": "myAppPlan", "webSiteName": "myUniqueWebSite", "storageAccountName": "mystorage123xyz" } }
3. 关键细节
- 依赖关系:存储账户必须依赖网站资源,确保网站创建完成后再获取其IP地址,避免部署时出现资源未就绪的错误。
- 出站IP数量:不同SKU的App Service出站IP数量不同:Free/Basic SKU有2个,Standard及以上SKU至少有4个,需根据实际SKU添加所有IP,避免遗漏导致网站无法访问存储账户。
- 静态出站IP场景:若网站使用Premium SKU并配置了静态出站IP,可直接将该静态IP填入
ipRules的value字段,无需拆分字符串。
内容的提问来源于stack exchange,提问作者frank
相关产品推荐
相关产品推荐

