如何通过Azure Cloud Shell查询指定用户创建的SHIR列表
查询指定用户创建的自托管集成运行时(SHIR)列表
SHIR是挂靠在Azure数据工厂(ADF)、Synapse工作区下的子资源,本身没有全局独立列表,需要遍历对应范围的资源结合活动日志的创建人记录筛选,以下是可直接在Azure Cloud Shell运行的方法:
查询本人创建的所有SHIR
PowerShell 版本(推荐)
Cloud Shell默认预装Az模块,打开Cloud Shell切换到PowerShell终端直接运行以下脚本即可,结果会直接输出你有权限访问范围内、自己创建的所有SHIR:
# 获取当前登录账号标识 $currentUser = (Get-AzContext).Account.Id # 拉取当前租户下你有权限访问的所有ADF和Synapse工作区 $adfList = Get-AzResource -ResourceType "Microsoft.DataFactory/factories" $synapseWsList = Get-AzResource -ResourceType "Microsoft.Synapse/workspaces" $result = @() # 遍历ADF查自托管IR foreach ($adf in $adfList) { $shirs = Get-AzDataFactoryV2IntegrationRuntime -ResourceGroupName $adf.ResourceGroupName -DataFactoryName $adf.Name | Where-Object PropertiesType -eq "SelfHosted" foreach ($shir in $shirs) { # 取该IR最早的成功创建操作日志匹配创建人 $createRecord = Get-AzActivityLog -ResourceId $shir.Id -StartTime (Get-Date).AddDays(-90) | Where-Object { $_.OperationName.Value -eq "Microsoft.DataFactory/factories/integrationruntimes/write" -and $_.Status.Value -eq "Succeeded" -and $_.Caller -eq $currentUser } | Select-Object -First 1 if ($createRecord) { $result += [PSCustomObject]@{ IR名称 = $shir.Name 所属资源名 = $adf.Name 所属资源类型 = "数据工厂(ADF)" 资源组 = $adf.ResourceGroupName 区域 = $adf.Location 创建时间 = $createRecord.EventTimestamp } } } } # 遍历Synapse工作区查自托管IR foreach ($ws in $synapseWsList) { $shirs = Get-AzSynapseIntegrationRuntime -ResourceGroupName $ws.ResourceGroupName -WorkspaceName $ws.Name | Where-Object PropertiesType -eq "SelfHosted" foreach ($shir in $shirs) { $createRecord = Get-AzActivityLog -ResourceId $shir.Id -StartTime (Get-Date).AddDays(-90) | Where-Object { $_.OperationName.Value -eq "Microsoft.Synapse/workspaces/integrationruntimes/write" -and $_.Status.Value -eq "Succeeded" -and $_.Caller -eq $currentUser } | Select-Object -First 1 if ($createRecord) { $result += [PSCustomObject]@{ IR名称 = $shir.Name 所属资源名 = $ws.Name 所属资源类型 = "Synapse工作区" 资源组 = $ws.ResourceGroupName 区域 = $ws.Location 创建时间 = $createRecord.EventTimestamp } } } } # 控制台输出结果,需要导出CSV的话把下一行替换成 $result | Export-Csv ./本人创建的SHIR列表.csv -NoTypeInformation -Encoding UTF8 $result | Format-Table -AutoSize
Azure CLI 版本
切换到Bash终端运行,依赖jq工具(Cloud Shell默认预装):
#!/bin/bash currentUserId=$(az ad signed-in-user show --query userPrincipalName -o tsv) echo "=== 数据工厂(ADF)下的SHIR ===" az resource list --resource-type Microsoft.DataFactory/factories --query [].id -o tsv | while read adfId; do rg=$(echo $adfId | awk -F/ '{print $5}') adfName=$(echo $adfId | awk -F/ '{print $NF}') az datafactory integration-runtime list -g $rg --factory-name $adfName --query "[?properties.type=='SelfHosted'].{name:name}" -o tsv | while read irName; do irId="${adfId}/integrationruntimes/${irName}" creator=$(az monitor activity-log list --resource-id $irId --start-time $(date -d "-90 days" +%Y-%m-%d) --query "[?operationName.value=='Microsoft.DataFactory/factories/integrationruntimes/write' && status.value=='Succeeded'].caller | [0]" -o tsv) if [ "$creator" == "$currentUserId" ]; then echo "IR名称: $irName | 所属ADF: $adfName | 资源组: $rg" fi done done echo -e "\n=== Synapse工作区下的SHIR ===" az resource list --resource-type Microsoft.Synapse/workspaces --query [].id -o tsv | while read wsId; do rg=$(echo $wsId | awk -F/ '{print $5}') wsName=$(echo $wsId | awk -F/ '{print $NF}') az synapse integration-runtime list -g $rg --workspace-name $wsName --query "[?properties.type=='SelfHosted'].{name:name}" -o tsv | while read irName; do irId="${wsId}/integrationruntimes/${irName}" creator=$(az monitor activity-log list --resource-id $irId --start-time $(date -d "-90 days" +%Y-%m-%d) --query "[?operationName.value=='Microsoft.Synapse/workspaces/integrationruntimes/write' && status.value=='Succeeded'].caller | [0]" -o tsv) if [ "$creator" == "$currentUserId" ]; then echo "IR名称: $irName | 所属Synapse工作区: $wsName | 资源组: $rg" fi done done
查询指定用户X创建的所有SHIR
只需要把上述脚本中获取当前用户的变量替换成用户X的账号UPN(即登录邮箱)或者Azure AD对象ID即可,注意你需要拥有对应范围资源的读取权限、活动日志读取权限才能拿到完整结果:
- PowerShell版本替换:把
$currentUser = (Get-AzContext).Account.Id改成$currentUser = "用户X的邮箱/对象ID" - CLI版本替换:把
currentUserId=$(az ad signed-in-user show --query userPrincipalName -o tsv)改成currentUserId="用户X的邮箱/对象ID"
注意事项
- Azure活动日志默认保留90天,如果需要查询创建超过90天的SHIR,需要提前把活动日志归档到Log Analytics工作区,将脚本中读取活动日志的部分替换为对应的Kusto查询即可。
- 脚本会自动跳过你没有读取权限的ADF/Synapse工作区,不会抛出权限错误中断运行。
- 如果需要查特定订阅、特定资源组下的SHIR,可以在拉取ADF/Synapse资源的命令中加
-SubscriptionId、-ResourceGroupName参数缩小查询范围,提升运行速度。
内容的提问来源于stack exchange,提问作者user19393362
相关产品推荐
相关产品推荐

