You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取Azure访问密钥与令牌,实现网站启停虚拟机

Got it, let's break this down simply—since you're used to AWS IAM access keys for VM control, Azure uses Service Principals as the equivalent identity, and you can get a client ID/secret plus access tokens to call Azure APIs for VM start/stop without wading through overly complex tutorials. Here's the streamlined workflow:

Core Concept

In Azure, the equivalent of AWS IAM access keys is a Service Principal—a dedicated identity for your website to authenticate with Azure. You'll need three key values from it:

  • appId (client ID)
  • password (client secret)
  • tenant (Azure AD tenant ID)

Plus, you'll generate short-lived access tokens using these values to call Azure's management API for VM operations.

Step 1: Create a Service Principal with VM Control Permissions

The fastest way is using the Azure CLI (you can install it locally or use the Azure Cloud Shell in the portal):

az ad sp create-for-rbac --name "VMManagementServicePrincipal" --role "Virtual Machine Contributor"
  • --name: Give your service principal a meaningful name (e.g., tied to your website)
  • --role: "Virtual Machine Contributor" is the minimal permission set needed to start/stop VMs (follows the least-privilege security principle, just like AWS IAM)

When you run this command, you'll get a JSON output like this:

{
  "appId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "displayName": "VMManagementServicePrincipal",
  "password": "xxxxxx~xxxxxx~xxxxxx",
  "tenant": "xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
}

Save these values securely—treat the password like you would an AWS secret access key.

Step 2: Generate an Access Token

Use these service principal credentials to get an access token (valid for ~1 hour; refresh when it expires). You can do this via a simple HTTP POST request, or use tools like curl:

curl -X POST -H "Content-Type: application/x-www-form-urlencoded" \
https://login.microsoftonline.com/{YOUR_TENANT_ID}/oauth2/token \
-d "grant_type=client_credentials&client_id={YOUR_APP_ID}&client_secret={YOUR_PASSWORD}&resource=https://management.azure.com/"

Replace the placeholders with the values from Step 1. The response will include an access_token field—this is what you'll use to authenticate API calls.

Step 3: Call Azure API to Start/Stop VMs

Use the access token to send requests to Azure's Compute API:

Start a VM

curl -X POST -H "Authorization: Bearer {YOUR_ACCESS_TOKEN}" \
https://management.azure.com/subscriptions/{YOUR_SUBSCRIPTION_ID}/resourceGroups/{YOUR_RESOURCE_GROUP}/providers/Microsoft.Compute/virtualMachines/{YOUR_VM_NAME}/start?api-version=2023-07-01

Stop a VM

curl -X POST -H "Authorization: Bearer {YOUR_ACCESS_TOKEN}" \
https://management.azure.com/subscriptions/{YOUR_SUBSCRIPTION_ID}/resourceGroups/{YOUR_RESOURCE_GROUP}/providers/Microsoft.Compute/virtualMachines/{YOUR_VM_NAME}/powerOff?api-version=2023-07-01
  • You can find your subscription ID in the Azure Portal under "Subscriptions"
  • resource group and VM name are the names you used when creating the VM

Key Practical Notes

  • Security: Never hardcode the service principal's password or access tokens in your website code. Use a secure secrets manager like Azure Key Vault to store them, just like you would with AWS Secrets Manager.
  • Portal Alternative: If you prefer a GUI instead of CLI, go to Azure Active Directory → App registrations → New registration. After creating the app, add a client secret (under "Certificates & secrets") and assign the "Virtual Machine Contributor" role to it (via the subscription/resource group's "Access control (IAM)" blade).
  • Cross-OS Support: This workflow works for all VM types (Ubuntu, Linux distros, Windows Server)—the API calls are identical regardless of the VM OS.

内容的提问来源于stack exchange,提问作者user1405338

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:51:08