使用GitHub开发ARM templates时,如何隔离本地数据仅推送通用文件?
Great question—this is a super common scenario when working with ARM templates and Git, especially when you need to keep sensitive or environment-specific data out of public repos. Here are the most practical approaches I recommend:
1. Use .gitignore with Example Parameter Files
This is the cleanest and most widely adopted method for separating shared vs. local config:
- Step 1: Create a shared "example" parameter file in your repo (e.g.,
parameters.example.json) with empty values or placeholders like"adminUsername": ""or"adminUsername": "[PLACEHOLDER]". Commit this to GitHub so collaborators can use it as a template. - Step 2: Copy this example file locally to a new file (e.g.,
parameters.local.json) and fill in your personal/sensitive values. - Step 3: Add the local file to your
.gitignoreby adding this line:parameters.local.json - Bonus: Add a note in your README telling collaborators to copy the example file to their local version and populate it with their own data.
2. Mark Existing Parameter Files as "Skip Worktree"
If you already have a parameter file committed to GitHub and don’t want to split it into example/local files, use Git’s skip-worktree flag to ignore local changes:
- Lock the file from being pushed: Run this command in your repo:
This tells Git to ignore any local edits to the file—your filled-in values will stay local, and Git will never try to push them to GitHub.git update-index --skip-worktree parameters.json - Unlock if you need to push changes to the shared version: If you update the empty/placeholder values in the repo file, run:
Commit the changes, then re-lock it with the first command.git update-index --no-skip-worktree parameters.json
3. Use ARM Parameter File Overrides (Native ARM Feature)
ARM supports passing multiple parameter files during deployment, which lets you keep a base shared file and a local override file:
- Step 1: Commit a base parameter file (e.g.,
parameters-base.json) to GitHub with empty or generic values. - Step 2: Create a local override file (e.g.,
parameters-local.json) that only includes the parameters you need to fill in locally (you don’t have to repeat all parameters—ARM merges them). - Step 3: Deploy using both files (the local override will take precedence):
az deployment group create --template-file main.json --parameters @parameters-base.json @parameters-local.json - Step 4: Add
parameters-local.jsonto.gitignoreso it never gets pushed.
4. Use Environment Variables or VSCode Snippets (Dynamic Filling)
For more flexibility, you can use placeholders in your shared parameter file and replace them locally with environment variables or VSCode tools:
- Add placeholders to your shared parameter file:
"adminPassword": "${LOCAL_ADMIN_PASSWORD}", "storageAccountName": "${LOCAL_STORAGE_ACCOUNT}" - Option A: Use a simple script to replace placeholders before deployment (e.g., a PowerShell or bash script that swaps
${VAR}with your local environment variables). - Option B: Use VSCode’s "Replace in File" feature or user snippets to quickly fill in values when you need to debug/deploy, then revert to placeholders before committing (though this is more manual, so the first three methods are better for consistency).
All these methods ensure your local, private data stays off GitHub while keeping the shared template and parameter structure accessible to your team.
内容的提问来源于stack exchange,提问作者Gregory Suvalian

