CICD流程中如何通过CLI审批Azure SQL Server的Synapse托管私有端点
解决方案
Azure CLI 未为SQL Server封装独立的私有端点审批子命令,可直接使用通用私有端点连接管理命令实现需求,调整后的Bash脚本如下:
function enable_sql_private_endpoint { endpoints=$(az sql server show --name $1 -g ${{ parameters.resourceGroupName }} --subscription $(serviceConnection) --query "privateEndpointConnections[?properties.privateLinkServiceConnectionState.status=='Pending'].id" -o tsv) for endpoint in $endpoints do # 使用通用私有端点连接审批命令,直接传入连接ID即可 az network private-endpoint-connection approve \ --ids $endpoint \ --subscription $(serviceConnection) done } sqlServers="$(az sql server list -g ${{ parameters.resourceGroupName }} --query '[].name' --subscription $(serviceConnection) -o tsv)" for sqlServerName in $sqlServers do echo "Processing $sqlServerName =========================================" enable_sql_private_endpoint $sqlServerName done
补充说明
- 上述命令中
--ids参数直接传入私有端点连接的完整资源ID,无需额外指定资源组、SQL Server名称等参数,逻辑更简洁,也避免参数匹配错误 - 执行脚本的服务主体需要具备目标SQL Server的
Microsoft.Network/privateEndpoints/privateEndpointConnections/approve/action权限,一般给SQL Server范围的Contributor角色即可满足要求 - 若需要批量拒绝待审批的连接,将命令中的
approve替换为reject即可,查看连接详情可替换为show - 如果执行命令时报错,可先将Azure CLI升级到最新版本再重试
内容的提问来源于stack exchange,提问作者Raymondo
相关产品推荐
相关产品推荐

