You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过编程方式将IP地址添加到Azure Event Grid命名空间的IP允许列表

如何通过编程方式将IP地址添加到Azure Event Grid命名空间的IP允许列表

嗨,我完全懂你手动添加180个IP的痛苦——这种重复工作交给代码来做才是正确的打开方式!下面给你几个实用的编程化方案,覆盖CLI、PowerShell、基础设施即代码和SDK,你可以根据自己的技术栈选:

1. 使用Azure CLI批量更新

这是最直接的方式,适合喜欢用命令行的场景。如果你的IP列表已经存在文本文件(比如ips.txt,每行一个IP/CIDR),可以按以下步骤操作:

步骤一:获取现有IP规则(可选,保留原有规则)

先把当前命名空间的IP规则导出到变量,避免覆盖已有的规则:

current_rules=$(az eventgrid namespace show --name <你的命名空间名称> --resource-group <资源组名称> --query 'publicNetworkAccessSettings.ipRules' -o json)

步骤二:处理新IP列表

把文本文件里的IP转成JSON数组格式:

new_ips=$(cat ips.txt | jq -R . | jq -s .)

(如果没有安装jq,可以手动把IP写成["x.x.x.x/32", "y.y.y.y/24"]这样的数组字符串)

步骤三:合并规则并更新命名空间

合并新旧规则并去重,然后执行更新:

combined_rules=$(echo "$current_rules $new_ips" | jq -s 'add | unique')
az eventgrid namespace update --name <你的命名空间名称> --resource-group <资源组名称> --public-network-access Enabled --ip-rules "$combined_rules"

如果是首次设置IP规则,直接跳过前两步,用下面的命令就行:

az eventgrid namespace update --name <你的命名空间名称> --resource-group <资源组名称> --public-network-access Enabled --ip-rules '["1.1.1.1/32", "2.2.2.0/24"]'

2. 使用Azure PowerShell脚本

如果你熟悉PowerShell,可以写个脚本批量处理:

# 配置参数
$namespaceName = "你的命名空间名称"
$resourceGroupName = "你的资源组名称"
$ipListPath = "ips.txt" # 你的IP列表文件路径

# 读取IP列表
$newIpList = Get-Content $ipListPath

# 获取现有命名空间配置
$namespace = Get-AzEventGridNamespace -Name $namespaceName -ResourceGroupName $resourceGroupName

# 合并新旧IP规则并去重
$existingIpRanges = if ($namespace.PublicNetworkAccessSettings.IpRules) {
    $namespace.PublicNetworkAccessSettings.IpRules.IpAddressOrRange
} else {
    @()
}
$allIpRanges = ($existingIpRanges + $newIpList) | Select-Object -Unique

# 创建IP规则对象
$updatedIpRules = $allIpRanges | ForEach-Object {
    New-AzEventGridNamespaceIpRuleObject -IpAddressOrRange $_ -Action Allow
}

# 执行更新
Update-AzEventGridNamespace -Name $namespaceName -ResourceGroupName $resourceGroupName -PublicNetworkAccess Enabled -IpRule $updatedIpRules

3. 使用Bicep/ARM模板(基础设施即代码)

如果你的Azure资源是用IaC管理的,直接在Bicep文件里定义IP规则数组,然后部署更新就行:

resource eventGridNamespace 'Microsoft.EventGrid/namespaces@2024-06-01-preview' = {
  name: '你的命名空间名称'
  location: '你的资源区域'
  properties: {
    publicNetworkAccess: 'Enabled'
    publicNetworkAccessSettings: {
      ipRules: [
        // 这里可以批量添加所有IP/CIDR
        { ipAddressOrRange: '1.1.1.1/32', action: 'Allow' }
        { ipAddressOrRange: '2.2.2.0/24', action: 'Allow' }
        // 更多IP规则...
      ]
    }
    // 保留其他原有配置(比如MQTT broker设置)
  }
}

然后用CLI部署更新:

az deployment group create --resource-group <资源组名称> --template-file <你的Bicep文件路径>

4. 使用Azure SDK(以Python为例)

如果需要集成到自己的应用程序里,可以用Azure官方SDK。下面是Python版本的示例:

from azure.identity import DefaultAzureCredential
from azure.mgmt.eventgrid import EventGridManagementClient

# 配置参数
subscription_id = "你的订阅ID"
resource_group_name = "你的资源组名称"
namespace_name = "你的命名空间名称"
ip_list_path = "ips.txt"

# 初始化客户端
credential = DefaultAzureCredential()
client = EventGridManagementClient(credential, subscription_id)

# 获取现有命名空间配置
namespace = client.namespaces.get(resource_group_name, namespace_name)
existing_ip_ranges = [rule.ip_address_or_range for rule in (namespace.public_network_access_settings.ip_rules or [])]

# 读取新IP列表
with open(ip_list_path, 'r') as f:
    new_ip_ranges = [line.strip() for line in f if line.strip()]

# 合并去重
all_ip_ranges = list(set(existing_ip_ranges + new_ip_ranges))
updated_ip_rules = [{"ip_address_or_range": ip, "action": "Allow"} for ip in all_ip_ranges]

# 执行更新
update_payload = {
    "public_network_access": "Enabled",
    "public_network_access_settings": {
        "ip_rules": updated_ip_rules
    }
}
client.namespaces.update(resource_group_name, namespace_name, update_payload)

注意事项

  • 确保你的账号拥有EventGrid Namespace Contributor或同等权限,才能执行更新操作。
  • IP规则支持单个IP(比如1.1.1.1/32)和CIDR范围(比如192.168.0.0/24)。
  • 更新时publicNetworkAccess必须设置为Enabled,否则IP规则不会生效。

备注:内容来源于stack exchange,提问作者Marc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.15 15:04:35