如何为VNet内的HDInsight Linux虚拟机配置MSI(ARM模板/PowerShell方式)
配置HDInsight Linux集群的MSI以支持AD身份验证的Azure服务通信
嘿,我来帮你搞定这个HDInsight集群配置MSI的问题!不管你用ARM模板还是PowerShell,都能轻松实现,下面分两种方式详细说明,最后还要补全关键的权限配置步骤——毕竟光有MSI还不够,得让它有权限访问目标服务才行。
一、用ARM模板配置MSI
HDInsight支持两种类型的MSI:系统分配MSI(和集群生命周期绑定,集群删除则MSI自动删除)和用户分配MSI(独立于集群,可复用在多个资源上),你可以根据需求选择。
1. 系统分配MSI的ARM模板片段
在你的HDInsight集群资源定义中,添加identity节点:
{ "type": "Microsoft.HDInsight/clusters", "apiVersion": "2021-06-01", "name": "[parameters('clusterName')]", "location": "[parameters('location')]", "identity": { "type": "SystemAssigned" }, // 其他集群配置(比如存储、节点规格等)... }
2. 用户分配MSI的ARM模板片段
如果用用户分配MSI,需要先确保已经创建好用户分配的MSI资源,然后在集群模板中引用它的ID:
{ "type": "Microsoft.HDInsight/clusters", "apiVersion": "2021-06-01", "name": "[parameters('clusterName')]", "location": "[parameters('location')]", "identity": { "type": "UserAssigned", "userAssignedIdentities": { "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('userAssignedMsiName'))]": {} } }, // 其他集群配置... }
3. 部署ARM模板
用PowerShell部署的话(兼容AzureRm模块):
New-AzureRmResourceGroupDeployment -ResourceGroupName "your-resource-group" -TemplateFile "path/to/your/template.json" -TemplateParameterFile "path/to/parameters.json"
二、用PowerShell的New-AzureRmHDInsightCluster配置MSI
注意:New-AzureRmHDInsightCluster属于旧版AzureRm模块,微软现在推荐使用Az模块的New-AzHDInsightCluster,不过我两种方式都给你列出来。
1. 配置系统分配MSI(AzureRm模块)
New-AzureRmHDInsightCluster -ResourceGroupName "your-resource-group" ` -ClusterName "your-cluster-name" ` -Location "your-region" ` -ClusterType Hadoop ` -OSType Linux ` -Version "4.0" ` -HttpCredential (Get-Credential) ` -IdentityType SystemAssigned
2. 配置用户分配MSI(AzureRm模块)
先获取用户分配MSI的资源ID,然后传入命令:
$userAssignedMsiId = (Get-AzureRmUserAssignedIdentity -ResourceGroupName "your-resource-group" -Name "your-msi-name").Id New-AzureRmHDInsightCluster -ResourceGroupName "your-resource-group" ` -ClusterName "your-cluster-name" ` -Location "your-region" ` -ClusterType Hadoop ` -OSType Linux ` -Version "4.0" ` -HttpCredential (Get-Credential) ` -IdentityType UserAssigned ` -IdentityId $userAssignedMsiId
(可选)Az模块的命令示例
如果你已经迁移到Az模块,命令类似,只是前缀换成Az:
# 系统分配MSI New-AzHDInsightCluster -ResourceGroupName "your-resource-group" ` -ClusterName "your-cluster-name" ` -Location "your-region" ` -ClusterType Hadoop ` -OSType Linux ` -Version "4.0" ` -HttpCredential (Get-Credential) ` -IdentityType SystemAssigned
三、关键步骤:给MSI分配目标服务的权限
创建完带MSI的集群后,必须给这个MSI分配目标Azure服务的访问权限,才能让集群通过AD身份验证访问服务。比如要访问Azure Blob Storage:
- 打开目标Storage账户的IAM页面
- 点击添加角色分配
- 选择合适的角色(比如
Storage Blob Data Contributor,根据你的需求调整) - 在成员选项卡中,选择托管标识,然后点击+选择成员,找到你的HDInsight集群的MSI(系统分配的话就是集群名称,用户分配的话就是MSI名称)
- 完成角色分配
四、验证MSI是否生效
你可以登录到HDInsight集群的头节点,用以下命令测试是否能获取到访问目标服务的令牌:
# 以访问Azure Storage为例 curl 'http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://storage.azure.com/' -H Metadata:true
如果能返回包含access_token的JSON响应,说明MSI配置成功,接下来就可以在集群中用这个令牌访问对应的Azure服务了。
内容的提问来源于stack exchange,提问作者CraRevol
相关产品推荐
相关产品推荐

