You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

私有子网内无公网Azure VM使用Custom Script Extension安装工具的方案咨询

Workarounds for Using Azure Custom Script Extension (CSE) on Internet-Isolated Private VMs

Absolutely, there are solid, practical ways to use CSE on VMs in a private, internet-free network—especially when your installers and scripts live in Azure Storage. Here are the most reliable approaches tailored to your scenario:

1. Azure Storage Private Endpoints + Required Service Tag Access

This is the most scalable and secure long-term solution:

  • Set up a Private Endpoint for your Azure Storage account, linked directly to your VM's virtual network. This lets the VM access storage via private IPs instead of public internet.
  • Configure NSG Outbound Rules: Allow outbound traffic to the MicrosoftCompute service tag. CSE needs this to communicate with Azure's compute management plane to fetch extension configurations and report deployment status.
  • Secure Storage Access: Use a virtual network-restricted SAS token (via storage account firewall settings) or a managed identity (see next section) to grant the VM access to your script container. When configuring CSE, use the private blob URL (e.g., https://yourstorageaccount.privatelink.blob.core.windows.net/container/install-scripts.ps1) in the fileUris setting.
  • Add Private DNS Zone: Link a privatelink.blob.core.windows.net Azure Private DNS Zone to your VM's VNet to ensure the storage account's private endpoint resolves correctly.

2. Pre-Copy Scripts to the VM, Then Run CSE Locally

For one-off deployments or simpler setups:

  • Transfer Files to the VM: Use Azure Bastion (with file upload) or a jump server in the same private network to copy your .exe and .ps1 files directly to the VM's local disk (e.g., C:\temp\).
  • Configure CSE for Local Execution: Skip remote fileUris and set the commandToExecute parameter to run the local script directly. Example:
    "commandToExecute": "powershell.exe -ExecutionPolicy Bypass -File C:\\temp\\setup-tools.ps1"
    
    Note: CSE still needs MicrosoftCompute service tag access to initialize and report status—unless you use offline extension mode, which isn't recommended for tracking deployment state.

3. Managed Identity for SAS-Free Private Access

Build on the private endpoint approach to eliminate SAS tokens entirely:

  • Assign a Managed Identity to your VM (system-assigned or user-assigned).
  • Grant Permissions: Assign the Storage Blob Data Reader role to the managed identity on your script storage container.
  • Configure CSE: Use the storage blob's private URL in fileUris—CSE will automatically use the VM's managed identity to authenticate to storage, no SAS token required.

Alternative: Pre-Build a Custom VM Image

If you're deploying multiple VMs with the same toolset, skip CSE entirely:

  • Use Azure VM Image Builder (configured to access your private storage via private endpoints) to create a custom image with all your tools pre-installed.
  • Deploy new VMs from this image in your private network—no post-deployment internet access or CSE needed.

内容的提问来源于stack exchange,提问作者Manjunath Rao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:48:01