如何在Pulumi置备的Azure虚拟机中运行自定义Powershell脚本
问题描述
我通过如下C#代码片段使用Pulumi置备了一台Azure Windows虚拟机:
var ssrsVm = new WindowsVirtualMachine("vmssrs001", new WindowsVirtualMachineArgs { Name = "vmssrs001", ResourceGroupName = resourceGroup.Name, NetworkInterfaceIds = { nic.Id }, Size = "Standard_B1ms", AdminUsername = ssrsLogin, AdminPassword = ssrsPassword, SourceImageReference = new WindowsVirtualMachineSourceImageReferenceArgs { Publisher = "microsoftpowerbi", Offer = "ssrs-2016", Sku = "dev-rs-only", Version = "latest" }, OsDisk = new WindowsVirtualMachineOsDiskArgs { Name = "vmssrs001disk", Caching = "ReadWrite", DiskSizeGb = 200, StorageAccountType = "Standard_LRS", } });
虚拟机置备完成后,需要在虚拟机内运行自定义Powershell脚本添加防火墙规则,要求该操作作为Pulumi应用的一部分执行。尝试使用VirtualMachineRunCommandByVirtualMachine资源实现需求,代码如下:
var virtualMachineRunCommandByVirtualMachine = new VirtualMachineRunCommandByVirtualMachine("vmssrs001-script", new VirtualMachineRunCommandByVirtualMachineArgs { ResourceGroupName = resourceGroup.Name, VmName = ssrsVm.Name, RunAsUser = ssrsLogin, RunAsPassword = ssrsPassword, RunCommandName = "enable firewall rule for ssrs", Source = new VirtualMachineRunCommandScriptSourceArgs { Script = @"Firewall AllowHttpForSSRS { Name = 'AllowHTTPForSSRS' DisplayName = 'AllowHTTPForSSRS' Group = 'PT Rule Group' Ensure = 'Present' Enabled = 'True' Profile = 'Public' Direction = 'Inbound' LocalPort = ('80') Protocol = 'TCP' Description = 'Firewall Rule for SSRS HTTP' }" } });
运行时返回报错:The property 'runCommands' is not valid because the 'Microsoft.Compute/RunCommandPreview' feature is not enabled for this subscription.
可行解决方案
以下方案按推荐优先级排序:
- 方案1:使用Azure网络安全组(NSG)规则(最推荐)
这是云原生的端口管控方案,无需进入虚拟机内部执行脚本,直接在云网络层配置端口放行规则,管理效率和可靠性更高。你可以直接在Pulumi中创建NSG规则,关联到虚拟机对应的网卡或所属子网即可开放80端口入站访问。 - 方案2:使用自定义脚本扩展(Custom Script Extension,稳定GA功能)
如果必须在虚拟机操作系统内部配置防火墙规则,可以使用Azure官方稳定的自定义脚本扩展,该功能无预览功能限制,Pulumi原生支持对应资源,示例代码如下:
var ssrsFirewallExtension = new VirtualMachineExtension("ssrs-firewall-rule", new VirtualMachineExtensionArgs { Name = "CustomScriptExtension", ResourceGroupName = resourceGroup.Name, VmName = ssrsVm.Name, Publisher = "Microsoft.Compute", Type = "CustomScriptExtension", TypeHandlerVersion = "1.10", AutoUpgradeMinorVersion = true, Settings = new Dictionary<string, object> { // 直接执行PowerShell命令添加防火墙规则,你也可以替换为自己的DSC执行逻辑 {"commandToExecute", "powershell -ExecutionPolicy Unrestricted -Command \"New-NetFirewallRule -Name 'AllowHTTPForSSRS' -DisplayName 'AllowHTTPForSSRS' -Group 'PT Rule Group' -Enabled True -Profile Public -Direction Inbound -LocalPort 80 -Protocol TCP -Description 'Firewall Rule for SSRS HTTP'\"" } } });
- 方案3:启用订阅的RunCommand预览功能
如果要继续使用VirtualMachineRunCommandByVirtualMachine资源,需要先为订阅注册RunCommandPreview功能,执行以下Azure CLI命令:
# 注册预览功能 az feature register --namespace Microsoft.Compute --name RunCommandPreview # 等待注册完成,状态变为Registered后执行下一步 az feature show --namespace Microsoft.Compute --name RunCommandPreview # 刷新Compute资源提供者注册状态 az provider register --namespace Microsoft.Compute
功能注册完成后重新执行Pulumi部署即可正常运行。
内容的提问来源于stack exchange,提问作者Rob
相关产品推荐
相关产品推荐

