You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure ARM模板为Azure SQL Server批量添加客户端IP地址?

如何在Azure ARM模板中批量添加多个SQL Server防火墙规则?

嘿,我来帮你搞定ARM模板批量添加SQL防火墙规则的事儿!其实有两种实用的方式,我给你一步步讲清楚:

方法1:使用参数数组+Copy循环(推荐)

这是最灵活的方案,适合需要动态添加任意数量IP规则的场景。核心思路是先定义一个包含所有防火墙规则信息的参数数组,然后用ARM的copy功能循环创建每个规则。

第一步:定义参数数组

先在模板的parameters部分添加一个数组类型的参数,每个元素包含规则名称、起始IP和结束IP:

"parameters": {
  "sqlServerName": {
    "type": "string",
    "metadata": {
      "description": "你的Azure SQL Server名称"
    }
  },
  "firewallRules": {
    "type": "array",
    "metadata": {
      "description": "要添加的防火墙规则数组,每个元素包含name、startIpAddress、endIpAddress"
    },
    "defaultValue": [
      {
        "name": "AllowOfficeIP",
        "startIpAddress": "192.168.1.1",
        "endIpAddress": "192.168.1.1"
      },
      {
        "name": "AllowHomeIP",
        "startIpAddress": "10.0.0.1",
        "endIpAddress": "10.0.0.1"
      },
      {
        "name": "AllowAllMicrosoftAzureIps",
        "startIpAddress": "0.0.0.0",
        "endIpAddress": "0.0.0.0"
      }
    ]
  }
}

第二步:用Copy循环创建规则

在模板的resources部分添加防火墙规则资源,通过copy属性遍历参数数组:

{
  "name": "[concat(parameters('sqlServerName'), '/', parameters('firewallRules')[copyIndex()].name)]",
  "type": "Microsoft.Sql/servers/firewallRules",
  "apiVersion": "2021-11-01", // 建议使用较新的API版本
  "location": "[resourceGroup().location]",
  "copy": {
    "name": "firewallRuleCopy", // 循环的名称,自定义即可
    "count": "[length(parameters('firewallRules'))]" // 循环次数等于数组长度
  },
  "properties": {
    "startIpAddress": "[parameters('firewallRules')[copyIndex()].startIpAddress]",
    "endIpAddress": "[parameters('firewallRules')[copyIndex()].endIpAddress]"
  },
  "dependsOn": [
    "[resourceId('Microsoft.Sql/servers', parameters('sqlServerName'))]" // 依赖SQL Server创建完成
  ]
}

这个方案的好处是:后续要添加或修改IP规则,只需要更新参数数组即可,不用改动模板结构,复用性极强。

方法2:定义多个独立的防火墙规则资源

如果你的IP规则数量固定且很少,也可以直接在模板中定义多个独立的防火墙规则资源,这种方式更直观:

// 第一个防火墙规则
{
  "name": "[concat(parameters('sqlServerName'), '/AllowOfficeIP')]",
  "type": "Microsoft.Sql/servers/firewallRules",
  "apiVersion": "2021-11-01",
  "location": "[resourceGroup().location]",
  "properties": {
    "startIpAddress": "192.168.1.1",
    "endIpAddress": "192.168.1.1"
  },
  "dependsOn": [
    "[resourceId('Microsoft.Sql/servers', parameters('sqlServerName'))]"
  ]
},
// 第二个防火墙规则
{
  "name": "[concat(parameters('sqlServerName'), '/AllowHomeIP')]",
  "type": "Microsoft.Sql/servers/firewallRules",
  "apiVersion": "2021-11-01",
  "location": "[resourceGroup().location]",
  "properties": {
    "startIpAddress": "10.0.0.1",
    "endIpAddress": "10.0.0.1"
  },
  "dependsOn": [
    "[resourceId('Microsoft.Sql/servers', parameters('sqlServerName'))]"
  ]
},
// 允许Azure内部服务访问的规则
{
  "name": "[concat(parameters('sqlServerName'), '/AllowAllMicrosoftAzureIps')]",
  "type": "Microsoft.Sql/servers/firewallRules",
  "apiVersion": "2021-11-01",
  "location": "[resourceGroup().location]",
  "properties": {
    "startIpAddress": "0.0.0.0",
    "endIpAddress": "0.0.0.0"
  },
  "dependsOn": [
    "[resourceId('Microsoft.Sql/servers', parameters('sqlServerName'))]"
  ]
}

几个关键注意事项

  • 防火墙规则名称在同一个SQL Server下必须唯一,所以我们用concat(parameters('sqlServerName'), '/规则名')来确保资源名称的全局唯一性(ARM中子资源的命名格式是父资源/子资源)
  • 建议使用较新的API版本(比如2021-11-01),相比旧版本(如你用的2014-04-01)支持更多特性,也更稳定
  • 每个规则的startIpAddress不能大于endIpAddress,否则部署会报错
  • 0.0.0.0是特殊IP,用于允许所有Azure内部服务访问你的SQL Server,这个规则可以根据需求保留或移除

内容的提问来源于stack exchange,提问作者Pradeep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:11:20