You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为VNet内的HDInsight Linux虚拟机配置MSI(ARM模板/PowerShell方式)

配置HDInsight Linux集群的MSI以支持AD身份验证的Azure服务通信

嘿,我来帮你搞定这个HDInsight集群配置MSI的问题!不管你用ARM模板还是PowerShell,都能轻松实现,下面分两种方式详细说明,最后还要补全关键的权限配置步骤——毕竟光有MSI还不够,得让它有权限访问目标服务才行。

一、用ARM模板配置MSI

HDInsight支持两种类型的MSI:系统分配MSI(和集群生命周期绑定,集群删除则MSI自动删除)和用户分配MSI(独立于集群,可复用在多个资源上),你可以根据需求选择。

1. 系统分配MSI的ARM模板片段

在你的HDInsight集群资源定义中,添加identity节点:

{
  "type": "Microsoft.HDInsight/clusters",
  "apiVersion": "2021-06-01",
  "name": "[parameters('clusterName')]",
  "location": "[parameters('location')]",
  "identity": {
    "type": "SystemAssigned"
  },
  // 其他集群配置(比如存储、节点规格等)...
}

2. 用户分配MSI的ARM模板片段

如果用用户分配MSI,需要先确保已经创建好用户分配的MSI资源,然后在集群模板中引用它的ID:

{
  "type": "Microsoft.HDInsight/clusters",
  "apiVersion": "2021-06-01",
  "name": "[parameters('clusterName')]",
  "location": "[parameters('location')]",
  "identity": {
    "type": "UserAssigned",
    "userAssignedIdentities": {
      "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('userAssignedMsiName'))]": {}
    }
  },
  // 其他集群配置...
}

3. 部署ARM模板

用PowerShell部署的话(兼容AzureRm模块):

New-AzureRmResourceGroupDeployment -ResourceGroupName "your-resource-group" -TemplateFile "path/to/your/template.json" -TemplateParameterFile "path/to/parameters.json"

二、用PowerShell的New-AzureRmHDInsightCluster配置MSI

注意:New-AzureRmHDInsightCluster属于旧版AzureRm模块,微软现在推荐使用Az模块的New-AzHDInsightCluster,不过我两种方式都给你列出来。

1. 配置系统分配MSI(AzureRm模块)

New-AzureRmHDInsightCluster -ResourceGroupName "your-resource-group" `
                            -ClusterName "your-cluster-name" `
                            -Location "your-region" `
                            -ClusterType Hadoop `
                            -OSType Linux `
                            -Version "4.0" `
                            -HttpCredential (Get-Credential) `
                            -IdentityType SystemAssigned

2. 配置用户分配MSI(AzureRm模块)

先获取用户分配MSI的资源ID,然后传入命令:

$userAssignedMsiId = (Get-AzureRmUserAssignedIdentity -ResourceGroupName "your-resource-group" -Name "your-msi-name").Id

New-AzureRmHDInsightCluster -ResourceGroupName "your-resource-group" `
                            -ClusterName "your-cluster-name" `
                            -Location "your-region" `
                            -ClusterType Hadoop `
                            -OSType Linux `
                            -Version "4.0" `
                            -HttpCredential (Get-Credential) `
                            -IdentityType UserAssigned `
                            -IdentityId $userAssignedMsiId

(可选)Az模块的命令示例

如果你已经迁移到Az模块,命令类似,只是前缀换成Az:

# 系统分配MSI
New-AzHDInsightCluster -ResourceGroupName "your-resource-group" `
                       -ClusterName "your-cluster-name" `
                       -Location "your-region" `
                       -ClusterType Hadoop `
                       -OSType Linux `
                       -Version "4.0" `
                       -HttpCredential (Get-Credential) `
                       -IdentityType SystemAssigned

三、关键步骤:给MSI分配目标服务的权限

创建完带MSI的集群后,必须给这个MSI分配目标Azure服务的访问权限,才能让集群通过AD身份验证访问服务。比如要访问Azure Blob Storage:

  • 打开目标Storage账户的IAM页面
  • 点击添加角色分配
  • 选择合适的角色(比如Storage Blob Data Contributor,根据你的需求调整)
  • 在成员选项卡中,选择托管标识,然后点击+选择成员,找到你的HDInsight集群的MSI(系统分配的话就是集群名称,用户分配的话就是MSI名称)
  • 完成角色分配

四、验证MSI是否生效

你可以登录到HDInsight集群的头节点,用以下命令测试是否能获取到访问目标服务的令牌:

# 以访问Azure Storage为例
curl 'http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://storage.azure.com/' -H Metadata:true

如果能返回包含access_token的JSON响应,说明MSI配置成功,接下来就可以在集群中用这个令牌访问对应的Azure服务了。

内容的提问来源于stack exchange,提问作者CraRevol

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:53:40