Bicep循环配置Key Vault密钥与对应存储账户加密配对问题
Bicep 存储加密配对与Key Vault报错解决方案
1. 存储账户与对应Key Vault密钥配对实现
你只需要在循环中引入索引参数,即可实现同标识的存储与密钥一一对应,同时修正原有配置中的两个错误项:
- 存储加密的keySource参数需要改为
Microsoft.KeyVault才会生效,原有配置写的Microsoft.Storage是使用平台托管密钥 - 存储连接串循环中硬编码的
[0]索引会导致所有连接串都指向第一个存储账户,需要替换为当前循环索引对应的存储账户
修改后的核心代码片段
// 存储账户循环新增索引参数i,对应同索引的tenantKey resource storage_Accounts 'Microsoft.Storage/storageAccounts@2021-06-01' = [ for (name, i) in storageName :{ name: name.name location: 'westeurope' sku: { name: 'Standard_RAGRS' } kind: 'StorageV2' dependsOn: [ tenantKey ] // 确保密钥先创建完成 properties: { allowCrossTenantReplication: true minimumTlsVersion: 'TLS1_2' allowBlobPublicAccess: false allowSharedKeyAccess: true networkAcls: { bypass: 'AzureServices' virtualNetworkRules: [] ipRules: [] defaultAction: 'Allow' } supportsHttpsTrafficOnly: true encryption: { services: { file: { keyType: 'Account' enabled: true } blob: { keyType: 'Account' enabled: true } } keySource: 'Microsoft.KeyVault' // 修正密钥源为Key Vault keyvaultproperties: { keyname: tenantKey[i].name // 使用同索引的对应密钥 keyvaulturi: keyVault.properties.vaultUri } } accessTier: 'Cool' } }] // 存储连接串循环修正索引 resource storageAccountConnectionString 'Microsoft.KeyVault/vaults/secrets@2019-09-01' = [for (name, i) in storageName :{ name: '${keyVault.name}/${name.name}' properties: { value: 'DefaultEndpointsProtocol=https;AccountName=${storage_Accounts[i].name};AccountKey=${listKeys(storage_Accounts[i].id, storage_Accounts[i].apiVersion).keys[0].value};EndpointSuffix=${environment().suffixes.storage}' } }]
2. Keyvault policy recoverable is not set 报错解决
该报错是Azure的强制安全要求:用于存储服务端加密的Key Vault必须开启软删除与清除保护功能。
解决步骤
- 如果使用的是已有的Key Vault:
- 进入Key Vault控制台的「属性」页,开启软删除,保留天数设置为≥7天
- 开启清除保护功能,保存设置
- 如果是通过Bicep创建Key Vault,补充如下配置即可:
resource keyVault 'Microsoft.KeyVault/vaults@2019-09-01' = { name: 'XXX' location: 'westeurope' properties: { sku: { family: 'A' name: 'standard' } tenantId: subscription().tenantId enableSoftDelete: true // 开启软删除 softDeleteRetentionInDays: 7 // 最少保留7天 enablePurgeProtection: true // 开启清除保护 // 补充存储服务访问策略,允许存储服务访问密钥 accessPolicies: [ { tenantId: subscription().tenantId objectId: 'bf7b6499-ff71-4aa2-97a4-f372087be7f0' // Azure Storage服务固定的principal ID permissions: { keys: [ 'Get' 'WrapKey' 'UnwrapKey' ] } } ] } }
内容的提问来源于stack exchange,提问作者Nayden Van
相关产品推荐
相关产品推荐

