私有子网内无公网Azure VM使用Custom Script Extension安装工具的方案咨询
Workarounds for Using Azure Custom Script Extension (CSE) on Internet-Isolated Private VMs
Absolutely, there are solid, practical ways to use CSE on VMs in a private, internet-free network—especially when your installers and scripts live in Azure Storage. Here are the most reliable approaches tailored to your scenario:
1. Azure Storage Private Endpoints + Required Service Tag Access
This is the most scalable and secure long-term solution:
- Set up a Private Endpoint for your Azure Storage account, linked directly to your VM's virtual network. This lets the VM access storage via private IPs instead of public internet.
- Configure NSG Outbound Rules: Allow outbound traffic to the
MicrosoftComputeservice tag. CSE needs this to communicate with Azure's compute management plane to fetch extension configurations and report deployment status. - Secure Storage Access: Use a virtual network-restricted SAS token (via storage account firewall settings) or a managed identity (see next section) to grant the VM access to your script container. When configuring CSE, use the private blob URL (e.g.,
https://yourstorageaccount.privatelink.blob.core.windows.net/container/install-scripts.ps1) in thefileUrissetting. - Add Private DNS Zone: Link a
privatelink.blob.core.windows.netAzure Private DNS Zone to your VM's VNet to ensure the storage account's private endpoint resolves correctly.
2. Pre-Copy Scripts to the VM, Then Run CSE Locally
For one-off deployments or simpler setups:
- Transfer Files to the VM: Use Azure Bastion (with file upload) or a jump server in the same private network to copy your
.exeand.ps1files directly to the VM's local disk (e.g.,C:\temp\). - Configure CSE for Local Execution: Skip remote
fileUrisand set thecommandToExecuteparameter to run the local script directly. Example:
Note: CSE still needs"commandToExecute": "powershell.exe -ExecutionPolicy Bypass -File C:\\temp\\setup-tools.ps1"MicrosoftComputeservice tag access to initialize and report status—unless you use offline extension mode, which isn't recommended for tracking deployment state.
3. Managed Identity for SAS-Free Private Access
Build on the private endpoint approach to eliminate SAS tokens entirely:
- Assign a Managed Identity to your VM (system-assigned or user-assigned).
- Grant Permissions: Assign the
Storage Blob Data Readerrole to the managed identity on your script storage container. - Configure CSE: Use the storage blob's private URL in
fileUris—CSE will automatically use the VM's managed identity to authenticate to storage, no SAS token required.
Alternative: Pre-Build a Custom VM Image
If you're deploying multiple VMs with the same toolset, skip CSE entirely:
- Use Azure VM Image Builder (configured to access your private storage via private endpoints) to create a custom image with all your tools pre-installed.
- Deploy new VMs from this image in your private network—no post-deployment internet access or CSE needed.
内容的提问来源于stack exchange,提问作者Manjunath Rao
相关产品推荐
相关产品推荐

