如何通过PowerShell/CLI/ARM自动化实现WebApp的VNet访问限制
Got it, since you already know how to set up VNet access restrictions via the Azure Portal, let's break down how to automate this using PowerShell, Azure CLI, and ARM templates. Each method fits different workflow needs, so pick what works best for you:
First, make sure you have the latest Azure PowerShell module installed. Here's a step-by-step command set to add a VNet access restriction rule to your Web App:
# Define your core resource details $resourceGroupName = "your-resource-group-name" $webAppName = "your-webapp-name" $vnetResourceId = "/subscriptions/your-subscription-id/resourceGroups/vnet-rg/providers/Microsoft.Network/virtualNetworks/your-vnet-name" $subnetId = "$vnetResourceId/subnets/your-subnet-name" # Add the VNet access restriction rule Add-AzWebAppAccessRestrictionRule ` -ResourceGroupName $resourceGroupName ` -WebAppName $webAppName ` -Name "Allow VNet Subnet Access" ` -Priority 100 ` -Action Allow ` -VirtualNetworkResourceId $vnetResourceId ` -SubnetId $subnetId
Quick Notes:
- The
-Priorityvalue needs to be unique—use a lower number than any existing deny rules (if you have them) to ensure this allow rule takes precedence. - To lock down access completely, add a deny rule with a higher priority (e.g., 200) targeting
0.0.0.0/0after setting up your VNet allow rule.
Start by logging into Azure CLI (az login) and setting your target subscription (az account set --subscription your-subscription-id). Then run this command to add the VNet restriction:
az webapp config access-restriction add \ --resource-group your-resource-group-name \ --name your-webapp-name \ --rule-name "Allow VNet Subnet" \ --priority 100 \ --action Allow \ --vnet-name your-vnet-name \ --subnet your-subnet-name \ --vnet-resource-group vnet-resource-group-name # Optional, only needed if your VNet is in a different resource group
Pro Tip: To confirm the rule was applied correctly, run:
az webapp config access-restriction list --resource-group your-resource-group-name --name your-webapp-name
You can embed the access restriction rule directly into your ARM template under the siteConfig property of the Web App resource. Here's a reusable snippet:
{ "type": "Microsoft.Web/sites", "apiVersion": "2023-01-01", "name": "[parameters('webAppName')]", "location": "[parameters('location')]", "dependsOn": [ "[resourceId('Microsoft.Web/serverfarms', parameters('appServicePlanName'))]" ], "properties": { "serverFarmId": "[resourceId('Microsoft.Web/serverfarms', parameters('appServicePlanName'))]", "siteConfig": { "ipSecurityRestrictions": [ { "name": "Allow VNet Subnet Access", "priority": 100, "action": "Allow", "type": "VirtualNetwork", "properties": { "virtualNetworkSubnetId": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), parameters('subnetName'))]" } }, // Optional: Add a default deny rule to block all unapproved traffic { "name": "Deny All Other Traffic", "priority": 200, "action": "Deny", "type": "IPAddress", "properties": { "ipAddress": "0.0.0.0/0" } } ] } } }
Important Reminders:
- Replace all placeholder parameters (like
parameters('webAppName')) with your actual values, or define them in the template'sparameterssection. - Ensure your Web App has VNet integration enabled if you're using a VNet without service endpoints (service endpoints are the recommended approach for this scenario).
内容的提问来源于stack exchange,提问作者ChethanR

