如何通过Python SDK的begin_create_or_update为Azure VM添加AADLoginForLinux扩展?
在Azure Python SDK创建VM时直接添加AADLoginForLinux扩展
完全可以通过compute_client.virtual_machines.begin_create_or_update方法直接添加AADLoginForLinux扩展,无需单独调用REST接口。以下是完整的示例代码:
from azure.identity import DefaultAzureCredential from azure.mgmt.compute import ComputeManagementClient from azure.mgmt.compute.models import ( VirtualMachine, VirtualMachineExtension, HardwareProfile, StorageProfile, OSDisk, ImageReference, NetworkProfile, NetworkInterfaceReference ) # 初始化Compute客户端 subscription_id = "你的订阅ID" resource_group_name = "你的资源组名称" vm_name = "目标VM名称" compute_client = ComputeManagementClient( credential=DefaultAzureCredential(), subscription_id=subscription_id ) # 构建VM基础配置(根据实际环境调整参数) vm_parameters = VirtualMachine( location="eastus", hardware_profile=HardwareProfile(vm_size="Standard_D2s_v3"), storage_profile=StorageProfile( os_disk=OSDisk( caching="ReadWrite", create_option="FromImage", managed_disk={"storage_account_type": "Premium_LRS"} ), image_reference=ImageReference( publisher="Canonical", offer="0001-com-ubuntu-server-jammy", sku="22_04-lts", version="latest" ) ), network_profile=NetworkProfile( network_interfaces=[ NetworkInterfaceReference(id="/subscriptions/{}/resourceGroups/{}/providers/Microsoft.Network/networkInterfaces/{}".format(subscription_id, resource_group_name, "你的网卡名称")) ] ), os_profile={ "computer_name": vm_name, "admin_username": "你的管理员用户名", "admin_password": "你的管理员密码" # 也可替换为ssh_public_keys配置 }, # 核心部分:添加AADLoginForLinux扩展 extensions=[ VirtualMachineExtension( name="AADLoginForLinux", location="eastus", publisher="Microsoft.Azure.ActiveDirectory", virtual_machine_extension_type="AADLoginForLinux", type_handler_version="1.0", auto_upgrade_minor_version=True ) ] ) # 执行VM创建/更新操作 poller = compute_client.virtual_machines.begin_create_or_update( resource_group_name=resource_group_name, vm_name=vm_name, parameters=vm_parameters ) result = poller.result() print(f"VM创建完成,扩展已添加:{result.name}")
关键说明:
- 扩展核心参数必须准确:
publisher固定为Microsoft.Azure.ActiveDirectory,virtual_machine_extension_type固定为AADLoginForLinux,type_handler_version可指定为1.0(或根据官方最新版本调整) auto_upgrade_minor_version设为True可自动升级扩展的次要版本- 若需限制可登录的AAD用户/组,可添加
settings字段:settings={"aadGroups": ["目标AAD组ID"], "aadUsers": ["目标AAD用户ID"]}
内容的提问来源于stack exchange,提问作者archcutbank
相关产品推荐
相关产品推荐

