You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure APIM策略中使用访问密钥认证Azure App Configuration服务

操作前置准备
  • 进入已创建的Azure App Configuration资源页面,打开左侧「访问密钥」面板,复制只读访问密钥的完整连接字符串(优先使用只读密钥,最小化权限风险),同时记录你需要读取的配置项的键名。
  • 进入目标Azure APIM实例,将App Configuration连接字符串存储为APIM保密命名空间值,禁止硬编码在策略中:
    • 操作路径:APIM实例左侧菜单 → 「命名空间值」→ 点击「添加」
    • 自定义名称(例如AppConfigConnectionString),值粘贴刚才复制的连接字符串,勾选「保密」选项后保存。
核心策略配置步骤

你需要通过APIM的send-request策略调用App Configuration的REST接口,同时用HMAC-SHA256算法生成访问密钥签名完成身份认证,以下是入站策略的示例片段:

<policies>
    <inbound>
        <base />
        <!-- 解析存储的App Config连接字符串,提取Endpoint、ID、密钥参数 -->
        <set-variable name="connectionStringParts" value="@{
            var connStr = "{{AppConfigConnectionString}}";
            var parts = connStr.Split(';').ToDictionary(p => p.Split('=')[0], p => p.Split('=', 2)[1]);
            return new {
                Endpoint = parts["Endpoint"],
                Id = parts["Id"],
                Secret = parts["Secret"]
            };
        }" />
        <!-- 生成HMAC签名所需的UTC时间戳 -->
        <set-variable name="utcNow" value="@(DateTime.UtcNow.ToString("r"))" />
        <!-- 构造请求路径,替换为你实际的配置键名,这里示例键名为TestConfigKey -->
        <set-variable name="requestPath" value="/kv/TestConfigKey?api-version=2023-10-01" />
        <!-- 生成签名 -->
        <set-variable name="signature" value="@{
            var secret = (string)((dynamic)context.Variables["connectionStringParts"]).Secret;
            var utcNow = (string)context.Variables["utcNow"];
            var requestPath = (string)context.Variables["requestPath"];
            var stringToSign = $"GET\n\n\n{utcNow}\n{requestPath}";
            var secretBytes = Convert.FromBase64String(secret);
            var signBytes = System.Text.Encoding.UTF8.GetBytes(stringToSign);
            using(var hmac = new System.Security.Cryptography.HMACSHA256(secretBytes)) {
                return Convert.ToBase64String(hmac.ComputeHash(signBytes));
            }
        }" />
        <!-- 发送请求到App Configuration获取配置值 -->
        <send-request mode="new" response-variable-name="appConfigResponse" timeout="10" ignore-error="false">
            <set-url>@(((dynamic)context.Variables["connectionStringParts"]).Endpoint + (string)context.Variables["requestPath"])</set-url>
            <set-method>GET</set-method>
            <set-header name="Date" exists-action="override">
                <value>@((string)context.Variables["utcNow"])</value>
            </set-header>
            <set-header name="Authorization" exists-action="override">
                <value>@($"HMAC-SHA256 Credential={((dynamic)context.Variables["connectionStringParts"]).Id}, SignedHeaders=date, Signature={((string)context.Variables["signature"])}")</value>
            </set-header>
        </send-request>
        <!-- 解析返回的配置值,存入变量供后续流程使用 -->
        <set-variable name="configValue" value="@(((IResponse)context.Variables["appConfigResponse"]).Body.As<JObject>()["value"].ToString())" />
    </inbound>
    <!-- 后续出站、后端策略可按需引用context.Variables["configValue"] -->
    <backend>
        <base />
    </backend>
    <outbound>
        <base />
    </outbound>
    <on-error>
        <base />
    </on-error>
</policies>
常见问题排查
  • 若返回401认证失败:检查签名生成逻辑的时间戳是否为UTC格式,访问密钥ID和密钥是否匹配,连接字符串解析是否正确
  • 若返回403访问拒绝:检查App Configuration的访问权限是否对APIM的IP开放,只读密钥是否有对应配置项的读取权限
  • 若返回404找不到资源:检查配置键名是否正确,API版本是否为App Configuration支持的版本

内容的提问来源于stack exchange,提问作者Madhu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 19:36:03