如何修改Azure ARM策略实现仅拒绝指定SKU的存储账户创建
调整后的完整配置
1. 新增存储SKU禁止列表参数
在原有参数基础上增加listOfDisallowedStorageSkus参数,用来配置需要拒绝的存储账户SKU名称:
{ "listOfResourceTypesNotAllowed": { "type": "Array", "metadata": { "description": "The list of resource types that cannot be deployed.", "displayName": "Not allowed resource types", "strongType": "resourceTypes" }, "allowedValues": [ "Microsoft.DocumentDB/databaseAccounts", "Microsoft.Storage/storageAccounts" ] }, "listOfDisallowedStorageSkus": { "type": "Array", "metadata": { "description": "List of storage account SKU names that are not allowed to deploy", "displayName": "Disallowed storage account SKUs" }, // 示例默认值,可根据实际需求修改 "defaultValue": ["Premium_LRS", "Premium_ZRS"] } }
2. 修改策略规则
调整判断逻辑,同时满足资源类型在禁止列表、且属于Cosmos DB 或 属于指定SKU的存储账户时才触发拒绝:
{ "if": { "allOf": [ { "field": "type", "in": "[parameters('listOfResourceTypesNotAllowed')]" }, { "anyOf": [ { "field": "type", "equals": "Microsoft.DocumentDB/databaseAccounts" }, { "allOf": [ { "field": "type", "equals": "Microsoft.Storage/storageAccounts" }, { "field": "Microsoft.Storage/storageAccounts/sku.name", "in": "[parameters('listOfDisallowedStorageSkus')]" } ] } ] } ] }, "then": { "effect": "Deny" } }
3. 完整策略定义
替换原有策略的properties部分即可,注意因为修改了内置规则,需要转为自定义策略使用:
{ "properties": { "displayName": "Not allowed resource types and storage SKUs", "policyType": "Custom", "mode": "All", "description": "Deny Cosmos DB deployment and storage accounts with specified SKUs", "parameters": { "listOfResourceTypesNotAllowed": { "type": "Array", "metadata": { "description": "The list of resource types that cannot be deployed.", "displayName": "Not allowed resource types", "strongType": "resourceTypes" }, "allowedValues": [ "Microsoft.DocumentDB/databaseAccounts", "Microsoft.Storage/storageAccounts" ] }, "listOfDisallowedStorageSkus": { "type": "Array", "metadata": { "description": "List of storage account SKU names that are not allowed to deploy", "displayName": "Disallowed storage account SKUs" }, "defaultValue": ["Premium_LRS", "Premium_ZRS"] } }, "policyRule": { "if": { "allOf": [ { "field": "type", "in": "[parameters('listOfResourceTypesNotAllowed')]" }, { "anyOf": [ { "field": "type", "equals": "Microsoft.DocumentDB/databaseAccounts" }, { "allOf": [ { "field": "type", "equals": "Microsoft.Storage/storageAccounts" }, { "field": "Microsoft.Storage/storageAccounts/sku.name", "in": "[parameters('listOfDisallowedStorageSkus')]" } ] } ] } ] }, "then": { "effect": "Deny" } } }, "type": "Microsoft.Authorization/policyDefinitions", "name": "custom-deny-resources-and-storage-skus" }
逻辑说明
- 外层
allOf要求两个条件同时满足才会触发拒绝效果 - 第一个条件判断资源类型是否在禁止的资源列表里,保留了你原有规则的基础逻辑
- 第二个条件通过
anyOf拆分两种拦截场景:- 资源是Cosmos DB时直接拦截,和原有逻辑一致
- 资源是存储账户时,额外判断SKU名称是否在禁止列表中,只有匹配到才会拦截
你可以根据实际需求修改listOfDisallowedStorageSkus的取值,支持的存储SKU包括Standard_LRS、Standard_GRS、Standard_RAGRS、Standard_ZRS、Premium_LRS、Premium_ZRS等。
内容的提问来源于stack exchange,提问作者Nayden Van
相关产品推荐
相关产品推荐

