如何获取Azure访问密钥与令牌,实现网站启停虚拟机
Got it, let's break this down simply—since you're used to AWS IAM access keys for VM control, Azure uses Service Principals as the equivalent identity, and you can get a client ID/secret plus access tokens to call Azure APIs for VM start/stop without wading through overly complex tutorials. Here's the streamlined workflow:
In Azure, the equivalent of AWS IAM access keys is a Service Principal—a dedicated identity for your website to authenticate with Azure. You'll need three key values from it:
appId(client ID)password(client secret)tenant(Azure AD tenant ID)
Plus, you'll generate short-lived access tokens using these values to call Azure's management API for VM operations.
Step 1: Create a Service Principal with VM Control Permissions
The fastest way is using the Azure CLI (you can install it locally or use the Azure Cloud Shell in the portal):
az ad sp create-for-rbac --name "VMManagementServicePrincipal" --role "Virtual Machine Contributor"
--name: Give your service principal a meaningful name (e.g., tied to your website)--role: "Virtual Machine Contributor" is the minimal permission set needed to start/stop VMs (follows the least-privilege security principle, just like AWS IAM)
When you run this command, you'll get a JSON output like this:
{ "appId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx", "displayName": "VMManagementServicePrincipal", "password": "xxxxxx~xxxxxx~xxxxxx", "tenant": "xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" }
Save these values securely—treat the password like you would an AWS secret access key.
Step 2: Generate an Access Token
Use these service principal credentials to get an access token (valid for ~1 hour; refresh when it expires). You can do this via a simple HTTP POST request, or use tools like curl:
curl -X POST -H "Content-Type: application/x-www-form-urlencoded" \ https://login.microsoftonline.com/{YOUR_TENANT_ID}/oauth2/token \ -d "grant_type=client_credentials&client_id={YOUR_APP_ID}&client_secret={YOUR_PASSWORD}&resource=https://management.azure.com/"
Replace the placeholders with the values from Step 1. The response will include an access_token field—this is what you'll use to authenticate API calls.
Step 3: Call Azure API to Start/Stop VMs
Use the access token to send requests to Azure's Compute API:
Start a VM
curl -X POST -H "Authorization: Bearer {YOUR_ACCESS_TOKEN}" \ https://management.azure.com/subscriptions/{YOUR_SUBSCRIPTION_ID}/resourceGroups/{YOUR_RESOURCE_GROUP}/providers/Microsoft.Compute/virtualMachines/{YOUR_VM_NAME}/start?api-version=2023-07-01
Stop a VM
curl -X POST -H "Authorization: Bearer {YOUR_ACCESS_TOKEN}" \ https://management.azure.com/subscriptions/{YOUR_SUBSCRIPTION_ID}/resourceGroups/{YOUR_RESOURCE_GROUP}/providers/Microsoft.Compute/virtualMachines/{YOUR_VM_NAME}/powerOff?api-version=2023-07-01
- You can find your
subscription IDin the Azure Portal under "Subscriptions" resource groupandVM nameare the names you used when creating the VM
Key Practical Notes
- Security: Never hardcode the service principal's
passwordor access tokens in your website code. Use a secure secrets manager like Azure Key Vault to store them, just like you would with AWS Secrets Manager. - Portal Alternative: If you prefer a GUI instead of CLI, go to Azure Active Directory → App registrations → New registration. After creating the app, add a client secret (under "Certificates & secrets") and assign the "Virtual Machine Contributor" role to it (via the subscription/resource group's "Access control (IAM)" blade).
- Cross-OS Support: This workflow works for all VM types (Ubuntu, Linux distros, Windows Server)—the API calls are identical regardless of the VM OS.
内容的提问来源于stack exchange,提问作者user1405338

