You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改Azure ARM策略实现仅拒绝指定SKU的存储账户创建

调整后的完整配置

1. 新增存储SKU禁止列表参数

在原有参数基础上增加listOfDisallowedStorageSkus参数,用来配置需要拒绝的存储账户SKU名称:

{
    "listOfResourceTypesNotAllowed": {
        "type": "Array",
        "metadata": {
            "description": "The list of resource types that cannot be deployed.",
            "displayName": "Not allowed resource types",
            "strongType": "resourceTypes"
        },
        "allowedValues": [
            "Microsoft.DocumentDB/databaseAccounts",
            "Microsoft.Storage/storageAccounts"
        ]
    },
    "listOfDisallowedStorageSkus": {
        "type": "Array",
        "metadata": {
            "description": "List of storage account SKU names that are not allowed to deploy",
            "displayName": "Disallowed storage account SKUs"
        },
        // 示例默认值,可根据实际需求修改
        "defaultValue": ["Premium_LRS", "Premium_ZRS"]
    }
}

2. 修改策略规则

调整判断逻辑,同时满足资源类型在禁止列表、且属于Cosmos DB 或 属于指定SKU的存储账户时才触发拒绝:

{
    "if": {
        "allOf": [
            {
                "field": "type",
                "in": "[parameters('listOfResourceTypesNotAllowed')]"
            },
            {
                "anyOf": [
                    {
                        "field": "type",
                        "equals": "Microsoft.DocumentDB/databaseAccounts"
                    },
                    {
                        "allOf": [
                            {
                                "field": "type",
                                "equals": "Microsoft.Storage/storageAccounts"
                            },
                            {
                                "field": "Microsoft.Storage/storageAccounts/sku.name",
                                "in": "[parameters('listOfDisallowedStorageSkus')]"
                            }
                        ]
                    }
                ]
            }
        ]
    },
    "then": {
        "effect": "Deny"
    }
}

3. 完整策略定义

替换原有策略的properties部分即可,注意因为修改了内置规则,需要转为自定义策略使用:

{
    "properties": {
      "displayName": "Not allowed resource types and storage SKUs",
      "policyType": "Custom",
      "mode": "All",
      "description": "Deny Cosmos DB deployment and storage accounts with specified SKUs",
      "parameters": {
        "listOfResourceTypesNotAllowed": {
          "type": "Array",
          "metadata": {
            "description": "The list of resource types that cannot be deployed.",
            "displayName": "Not allowed resource types",
            "strongType": "resourceTypes"
          },
          "allowedValues": [
            "Microsoft.DocumentDB/databaseAccounts",
            "Microsoft.Storage/storageAccounts"
          ]
        },
        "listOfDisallowedStorageSkus": {
          "type": "Array",
          "metadata": {
            "description": "List of storage account SKU names that are not allowed to deploy",
            "displayName": "Disallowed storage account SKUs"
          },
          "defaultValue": ["Premium_LRS", "Premium_ZRS"]
        }
      },
      "policyRule": {
        "if": {
            "allOf": [
                {
                    "field": "type",
                    "in": "[parameters('listOfResourceTypesNotAllowed')]"
                },
                {
                    "anyOf": [
                        {
                            "field": "type",
                            "equals": "Microsoft.DocumentDB/databaseAccounts"
                        },
                        {
                            "allOf": [
                                {
                                    "field": "type",
                                    "equals": "Microsoft.Storage/storageAccounts"
                                },
                                {
                                    "field": "Microsoft.Storage/storageAccounts/sku.name",
                                    "in": "[parameters('listOfDisallowedStorageSkus')]"
                                }
                            ]
                        }
                    ]
                }
            ]
        },
        "then": {
            "effect": "Deny"
        }
      }
    },
    "type": "Microsoft.Authorization/policyDefinitions",
    "name": "custom-deny-resources-and-storage-skus"
}

逻辑说明

  • 外层allOf要求两个条件同时满足才会触发拒绝效果
  • 第一个条件判断资源类型是否在禁止的资源列表里,保留了你原有规则的基础逻辑
  • 第二个条件通过anyOf拆分两种拦截场景:
    • 资源是Cosmos DB时直接拦截,和原有逻辑一致
    • 资源是存储账户时,额外判断SKU名称是否在禁止列表中,只有匹配到才会拦截
      你可以根据实际需求修改listOfDisallowedStorageSkus的取值,支持的存储SKU包括Standard_LRS、Standard_GRS、Standard_RAGRS、Standard_ZRS、Premium_LRS、Premium_ZRS等。

内容的提问来源于stack exchange,提问作者Nayden Van

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 00:30:00