如何在存储账户ARM模板中通过迭代器添加多个现有虚拟网络和子网
ARM模板批量添加虚拟网络规则优化方案
我已通过如下ARM模板添加现有虚拟网络,完成Azure存储账户的创建。
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "storageAccountName": { "type": "string", "metadata": { "description": "Specifies the name of the Azure Storage account." } }, "storageAccountType": { "type": "string", "defaultValue": "Standard_LRS", "allowedValues": [ "Standard_LRS", "Standard_GRS", "Standard_RAGRS", "Standard_ZRS", "Premium_LRS" ], "metadata": { "description": "Storage Account type." } }, "storageAccessTier": { "type": "string", "defaultValue": "Hot", "allowedValues": [ "Hot", "Cool" ], "metadata": { "description": "Set the access tier of the Storage Account." } }, "storageKind": { "type": "string", "defaultValue": "StorageV2", "allowedValues": [ "StorageV2", "Storage" ], "metadata": { "description": "Set the storage kind of the Storage Account." } }, "storageAccounthttpsTrafficOnlyEnabled": { "type": "bool", "defaultValue": true, "metadata": { "description": "Enable or disable enforcing HTTPS only access." } }, "allowBlobPublicAccess": { "type": "bool", "defaultValue": false, "metadata": { "description": "Enable or disable blob public access" } }, "isHnsEnabled": { "type": "bool", "defaultValue": true, "metadata": { "description": "Enable or disable ADLS Gen2 hierarchical namespace" } }, "containerNames": { "type": "array", "metadata": { "description": "The container names" } }, "location": { "type": "string", "metadata": { "description": "Specifies the location in which the Azure Storage resources should be deployed." } }, "environment": { "type": "string", "metadata": { "description": "Specify the environment name" } }, "subscriptionOwner": { "type": "string", "metadata": { "description": "Specify the email address of the subscription owner" } }, "vnetResourceGroupName": { "type": "string", "metadata": { "description": "The name of the existing resource group which contains the virtual network" } }, "vnetName": { "type": "string", "metadata": { "description": "The name of the existing virtual network" } }, "subnet01Name": { "type": "string", "metadata": { "description": "The name of the db subnet" } }, "subnet02Name": { "type": "string", "metadata": { "description": "The name of the default subnet" } }, "subnet03Name": { "type": "string", "metadata": { "description": "The name of the ise1 subnet" } }, "subnet04Name": { "type": "string", "metadata": { "description": "The name of the ise2 subnet" } }, "subnet05Name": { "type": "string", "metadata": { "description": "The name of the ise3 subnet" } }, "subnet06Name": { "type": "string", "metadata": { "description": "The name of the ise4 subnet" } }, "subnet07Name": { "type": "string", "metadata": { "description": "The name of the tools subnet" } } }, "variables": { "vnetResourceId": "[resourceId(parameters('vnetResourceGroupName'),'Microsoft.Network/virtualNetworks',parameters('vnetName'))]" }, "resources": [ { "type": "Microsoft.Storage/storageAccounts", "apiVersion": "2020-08-01-preview", "name": "[parameters('storageAccountName')]", "location": "[parameters('location')]", "sku": { "name": "[parameters('storageAccountType')]", "tier": "Standard" }, "kind": "[parameters('storageKind')]", "properties": { "accessTier": "[parameters('storageAccessTier')]", "allowBlobPublicAccess": "[parameters('allowBlobPublicAccess')]", "isHnsEnabled": "[parameters('isHnsEnabled')]", "supportsHttpsTrafficOnly": "[parameters('storageAccounthttpsTrafficOnlyEnabled')]", "networkAcls": { "resourceAccessRules": [ ], "bypass": "AzureServices", "virtualNetworkRules": [ { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet01Name'))]", "action": "Allow", "state": "Succeeded" }, { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet02Name'))]", "action": "Allow", "state": "Succeeded" }, { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet03Name'))]", "action": "Allow", "state": "Succeeded" }, { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet04Name'))]", "action": "Allow", "state": "Succeeded" }, { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet05Name'))]", "action": "Allow", "state": "Succeeded" }, { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet06Name'))]", "action": "Allow", "state": "Succeeded" }, { "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet07Name'))]", "action": "Allow", "state": "Succeeded" } ], "ipRules": [ { "value": "xxxxxxxx", "action": "Allow" } ], "defaultAction": "Deny" } } }, { "type": "Microsoft.Storage/storageAccounts/blobServices/containers", "apiVersion": "2020-08-01-preview", "name": "[concat(parameters('storageAccountName'),'/default/', parameters('containerNames')[copyIndex()])]", "copy": { "name": "containercopy", "count": "[length(parameters('containerNames'))]" }, "dependsOn": [ "[resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName'))]" ] } ], "outputs": { "storageAccountName": { "type": "string", "value": "[parameters('storageAccountName')]" }, "containerNames": { "type": "array", "value": "[parameters('containerNames')]" } } }
上述模板中通过多个独立参数传入虚拟网络和子网信息,可通过copy迭代器实现多个现有虚拟网络及子网的批量添加,优化模板结构,具体实现如下:
核心优化点
- 移除原模板中冗余的单VNet、独立子网参数,替换为数组类型的通用参数,支持跨资源组、多VNet的子网批量配置
- 利用ARM模板的属性copy迭代能力,自动生成虚拟网络规则和IP放行规则,无需手动逐个定义
- 兼容原有功能逻辑,存储账户、容器创建的配置逻辑完全保留
优化后完整模板
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "storageAccountName": { "type": "string", "metadata": { "description": "指定Azure存储账户的名称" } }, "storageAccountType": { "type": "string", "defaultValue": "Standard_LRS", "allowedValues": [ "Standard_LRS", "Standard_GRS", "Standard_RAGRS", "Standard_ZRS", "Premium_LRS" ], "metadata": { "description": "存储账户类型" } }, "storageAccessTier": { "type": "string", "defaultValue": "Hot", "allowedValues": [ "Hot", "Cool" ], "metadata": { "description": "存储账户访问层配置" } }, "storageKind": { "type": "string", "defaultValue": "StorageV2", "allowedValues": [ "StorageV2", "Storage" ], "metadata": { "description": "存储账户的存储类型" } }, "storageAccounthttpsTrafficOnlyEnabled": { "type": "bool", "defaultValue": true, "metadata": { "description": "是否启用仅HTTPS访问强制策略" } }, "allowBlobPublicAccess": { "type": "bool", "defaultValue": false, "metadata": { "description": "是否允许Blob公共访问" } }, "isHnsEnabled": { "type": "bool", "defaultValue": true, "metadata": { "description": "是否启用ADLS Gen2层级命名空间" } }, "containerNames": { "type": "array", "metadata": { "description": "容器名称列表" } }, "location": { "type": "string", "metadata": { "description": "Azure存储资源部署的区域" } }, "environment": { "type": "string", "metadata": { "description": "环境名称" } }, "subscriptionOwner": { "type": "string", "metadata": { "description": "订阅所有者的邮箱地址" } }, "allowedSubnets": { "type": "array", "metadata": { "description": "需要放行的子网资源ID列表,支持跨资源组、跨VNet的子网" } }, "allowedIpRanges": { "type": "array", "defaultValue": [], "metadata": { "description": "需要放行的公网IP段列表" } } }, "resources": [ { "type": "Microsoft.Storage/storageAccounts", "apiVersion": "2020-08-01-preview", "name": "[parameters('storageAccountName')]", "location": "[parameters('location')]", "sku": { "name": "[parameters('storageAccountType')]", "tier": "Standard" }, "kind": "[parameters('storageKind')]", "properties": { "accessTier": "[parameters('storageAccessTier')]", "allowBlobPublicAccess": "[parameters('allowBlobPublicAccess')]", "isHnsEnabled": "[parameters('isHnsEnabled')]", "supportsHttpsTrafficOnly": "[parameters('storageAccounthttpsTrafficOnlyEnabled')]", "networkAcls": { "resourceAccessRules": [], "bypass": "AzureServices", "copy": [ { "name": "virtualNetworkRules", "count": "[length(parameters('allowedSubnets'))]", "input": { "id": "[parameters('allowedSubnets')[copyIndex('virtualNetworkRules')]]", "action": "Allow", "state": "Succeeded" } }, { "name": "ipRules", "count": "[length(parameters('allowedIpRanges'))]", "input": { "value": "[parameters('allowedIpRanges')[copyIndex('ipRules')]]", "action": "Allow" } } ], "defaultAction": "Deny" } } }, { "type": "Microsoft.Storage/storageAccounts/blobServices/containers", "apiVersion": "2020-08-01-preview", "name": "[concat(parameters('storageAccountName'),'/default/', parameters('containerNames')[copyIndex()])]", "copy": { "name": "containercopy", "count": "[length(parameters('containerNames'))]" }, "dependsOn": [ "[resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName'))]" ] } ], "outputs": { "storageAccountName": { "type": "string", "value": "[parameters('storageAccountName')]" }, "containerNames": { "type": "array", "value": "[parameters('containerNames')]" } } }
部署参数示例
"allowedSubnets": { "value": [ "/subscriptions/你的订阅ID/resourceGroups/vnet资源组名/providers/Microsoft.Network/virtualNetworks/vnet名称/subnets/db-subnet", "/subscriptions/你的订阅ID/resourceGroups/vnet资源组名/providers/Microsoft.Network/virtualNetworks/vnet名称/subnets/default-subnet", "/subscriptions/你的订阅ID/resourceGroups/其他资源组名/providers/Microsoft.Network/virtualNetworks/其他vnet名称/subnets/other-subnet" ] }
内容的提问来源于stack exchange,提问作者Pradeep
相关产品推荐
相关产品推荐

