You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在存储账户ARM模板中通过迭代器添加多个现有虚拟网络和子网

ARM模板批量添加虚拟网络规则优化方案

我已通过如下ARM模板添加现有虚拟网络,完成Azure存储账户的创建。

{
    "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
    "contentVersion": "1.0.0.0",
    "parameters": {
        "storageAccountName": {
            "type": "string",
            "metadata": {
                "description": "Specifies the name of the Azure Storage account."
            }
        },
        "storageAccountType": {
            "type": "string",
            "defaultValue": "Standard_LRS",
            "allowedValues": [
                "Standard_LRS",
                "Standard_GRS",
                "Standard_RAGRS",
                "Standard_ZRS",
                "Premium_LRS"
            ],
            "metadata": {
                "description": "Storage Account type."
            }
        },
        "storageAccessTier": {
            "type": "string",
            "defaultValue": "Hot",
            "allowedValues": [
                "Hot",
                "Cool"
            ],
            "metadata": {
                "description": "Set the access tier of the Storage Account."
            }
        },
        "storageKind": {
            "type": "string",
            "defaultValue": "StorageV2",
            "allowedValues": [
                "StorageV2",
                "Storage"
            ],
            "metadata": {
                "description": "Set the storage kind of the Storage Account."
            }
        },
        "storageAccounthttpsTrafficOnlyEnabled": {
            "type": "bool",
            "defaultValue": true,
            "metadata": {
                "description": "Enable or disable enforcing HTTPS only access."
            }
        },
        "allowBlobPublicAccess": {
            "type": "bool",
            "defaultValue": false,
            "metadata": {
                "description": "Enable or disable blob public access"
            }
        },
        "isHnsEnabled": {
            "type": "bool",
            "defaultValue": true,
            "metadata": {
                "description": "Enable or disable ADLS Gen2 hierarchical namespace"
            }
        },
        "containerNames": {
            "type": "array",
            "metadata": {
                "description": "The container names"
            }
        },
        "location": {
            "type": "string",
            "metadata": {
                "description": "Specifies the location in which the Azure Storage resources should be deployed."
            }
        },
        "environment": {
            "type": "string",
            "metadata": {
                "description": "Specify the environment name"
            }
        },
        "subscriptionOwner": {
            "type": "string",
            "metadata": {
                "description": "Specify the email address of the subscription owner"
            }
        },
        "vnetResourceGroupName": {
            "type": "string",
            "metadata": {
                "description": "The name of the existing resource group which contains the virtual network"
            }
        },
        "vnetName": {
            "type": "string",
            "metadata": {
                "description": "The name of the existing virtual network"
            }
        },
        "subnet01Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the db subnet"
            }
        },
        "subnet02Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the default subnet"
            }
        },
        "subnet03Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the ise1 subnet"
            }
        },
        "subnet04Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the ise2 subnet"
            }
        },
        "subnet05Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the ise3 subnet"
            }
        },
        "subnet06Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the ise4 subnet"
            }
        },
        "subnet07Name": {
            "type": "string",
            "metadata": {
                "description": "The name of the tools subnet"
            }
        }
    },
    "variables": {
        "vnetResourceId": "[resourceId(parameters('vnetResourceGroupName'),'Microsoft.Network/virtualNetworks',parameters('vnetName'))]"
    },
    "resources": [
        {
            "type": "Microsoft.Storage/storageAccounts",
            "apiVersion": "2020-08-01-preview",
            "name": "[parameters('storageAccountName')]",
            "location": "[parameters('location')]",
            "sku": {
                "name": "[parameters('storageAccountType')]",
                "tier": "Standard"
            },
            "kind": "[parameters('storageKind')]",
            "properties": {
                "accessTier": "[parameters('storageAccessTier')]",
                "allowBlobPublicAccess": "[parameters('allowBlobPublicAccess')]",
                "isHnsEnabled": "[parameters('isHnsEnabled')]",
                "supportsHttpsTrafficOnly": "[parameters('storageAccounthttpsTrafficOnlyEnabled')]",
                "networkAcls": {
                    "resourceAccessRules": [
                    ],
                    "bypass": "AzureServices",
                    "virtualNetworkRules": [
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet01Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        },
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet02Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        },
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet03Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        },
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet04Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        },
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet05Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        },
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet06Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        },
                        {
                            "id": "[concat(variables('vnetResourceId'), '/subnets/',parameters('subnet07Name'))]",
                            "action": "Allow",
                            "state": "Succeeded"
                        }
                    ],
                    "ipRules": [
                        {
                            "value": "xxxxxxxx",
                            "action": "Allow"
                        }
                    ],
                    "defaultAction": "Deny"
                }
            }
        },
        {
            "type": "Microsoft.Storage/storageAccounts/blobServices/containers",
            "apiVersion": "2020-08-01-preview",
            "name": "[concat(parameters('storageAccountName'),'/default/', parameters('containerNames')[copyIndex()])]",
            "copy": {
                "name": "containercopy",
                "count": "[length(parameters('containerNames'))]"
            },
            "dependsOn": [
                "[resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName'))]"
            ]
        }
    ],
    "outputs": {
        "storageAccountName": {
            "type": "string",
            "value": "[parameters('storageAccountName')]"
        },
        "containerNames": {
            "type": "array",
            "value": "[parameters('containerNames')]"
        }
    }
}

上述模板中通过多个独立参数传入虚拟网络和子网信息,可通过copy迭代器实现多个现有虚拟网络及子网的批量添加,优化模板结构,具体实现如下:

核心优化点

  • 移除原模板中冗余的单VNet、独立子网参数,替换为数组类型的通用参数,支持跨资源组、多VNet的子网批量配置
  • 利用ARM模板的属性copy迭代能力,自动生成虚拟网络规则和IP放行规则,无需手动逐个定义
  • 兼容原有功能逻辑,存储账户、容器创建的配置逻辑完全保留

优化后完整模板

{
    "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
    "contentVersion": "1.0.0.0",
    "parameters": {
        "storageAccountName": {
            "type": "string",
            "metadata": {
                "description": "指定Azure存储账户的名称"
            }
        },
        "storageAccountType": {
            "type": "string",
            "defaultValue": "Standard_LRS",
            "allowedValues": [
                "Standard_LRS",
                "Standard_GRS",
                "Standard_RAGRS",
                "Standard_ZRS",
                "Premium_LRS"
            ],
            "metadata": {
                "description": "存储账户类型"
            }
        },
        "storageAccessTier": {
            "type": "string",
            "defaultValue": "Hot",
            "allowedValues": [
                "Hot",
                "Cool"
            ],
            "metadata": {
                "description": "存储账户访问层配置"
            }
        },
        "storageKind": {
            "type": "string",
            "defaultValue": "StorageV2",
            "allowedValues": [
                "StorageV2",
                "Storage"
            ],
            "metadata": {
                "description": "存储账户的存储类型"
            }
        },
        "storageAccounthttpsTrafficOnlyEnabled": {
            "type": "bool",
            "defaultValue": true,
            "metadata": {
                "description": "是否启用仅HTTPS访问强制策略"
            }
        },
        "allowBlobPublicAccess": {
            "type": "bool",
            "defaultValue": false,
            "metadata": {
                "description": "是否允许Blob公共访问"
            }
        },
        "isHnsEnabled": {
            "type": "bool",
            "defaultValue": true,
            "metadata": {
                "description": "是否启用ADLS Gen2层级命名空间"
            }
        },
        "containerNames": {
            "type": "array",
            "metadata": {
                "description": "容器名称列表"
            }
        },
        "location": {
            "type": "string",
            "metadata": {
                "description": "Azure存储资源部署的区域"
            }
        },
        "environment": {
            "type": "string",
            "metadata": {
                "description": "环境名称"
            }
        },
        "subscriptionOwner": {
            "type": "string",
            "metadata": {
                "description": "订阅所有者的邮箱地址"
            }
        },
        "allowedSubnets": {
            "type": "array",
            "metadata": {
                "description": "需要放行的子网资源ID列表,支持跨资源组、跨VNet的子网"
            }
        },
        "allowedIpRanges": {
            "type": "array",
            "defaultValue": [],
            "metadata": {
                "description": "需要放行的公网IP段列表"
            }
        }
    },
    "resources": [
        {
            "type": "Microsoft.Storage/storageAccounts",
            "apiVersion": "2020-08-01-preview",
            "name": "[parameters('storageAccountName')]",
            "location": "[parameters('location')]",
            "sku": {
                "name": "[parameters('storageAccountType')]",
                "tier": "Standard"
            },
            "kind": "[parameters('storageKind')]",
            "properties": {
                "accessTier": "[parameters('storageAccessTier')]",
                "allowBlobPublicAccess": "[parameters('allowBlobPublicAccess')]",
                "isHnsEnabled": "[parameters('isHnsEnabled')]",
                "supportsHttpsTrafficOnly": "[parameters('storageAccounthttpsTrafficOnlyEnabled')]",
                "networkAcls": {
                    "resourceAccessRules": [],
                    "bypass": "AzureServices",
                    "copy": [
                        {
                            "name": "virtualNetworkRules",
                            "count": "[length(parameters('allowedSubnets'))]",
                            "input": {
                                "id": "[parameters('allowedSubnets')[copyIndex('virtualNetworkRules')]]",
                                "action": "Allow",
                                "state": "Succeeded"
                            }
                        },
                        {
                            "name": "ipRules",
                            "count": "[length(parameters('allowedIpRanges'))]",
                            "input": {
                                "value": "[parameters('allowedIpRanges')[copyIndex('ipRules')]]",
                                "action": "Allow"
                            }
                        }
                    ],
                    "defaultAction": "Deny"
                }
            }
        },
        {
            "type": "Microsoft.Storage/storageAccounts/blobServices/containers",
            "apiVersion": "2020-08-01-preview",
            "name": "[concat(parameters('storageAccountName'),'/default/', parameters('containerNames')[copyIndex()])]",
            "copy": {
                "name": "containercopy",
                "count": "[length(parameters('containerNames'))]"
            },
            "dependsOn": [
                "[resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName'))]"
            ]
        }
    ],
    "outputs": {
        "storageAccountName": {
            "type": "string",
            "value": "[parameters('storageAccountName')]"
        },
        "containerNames": {
            "type": "array",
            "value": "[parameters('containerNames')]"
        }
    }
}

部署参数示例

"allowedSubnets": {
    "value": [
        "/subscriptions/你的订阅ID/resourceGroups/vnet资源组名/providers/Microsoft.Network/virtualNetworks/vnet名称/subnets/db-subnet",
        "/subscriptions/你的订阅ID/resourceGroups/vnet资源组名/providers/Microsoft.Network/virtualNetworks/vnet名称/subnets/default-subnet",
        "/subscriptions/你的订阅ID/resourceGroups/其他资源组名/providers/Microsoft.Network/virtualNetworks/其他vnet名称/subnets/other-subnet"
    ]
}

内容的提问来源于stack exchange,提问作者Pradeep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 09:42:00