Azure Stack中Runbook部署及自动化账户创建技术问询
Got it, let's walk through the exact steps to create an Automation Account and deploy Runbooks in Azure Stack, plus address the policy-related confusion you're facing from your public Azure setup.
First, unlike your public Azure environment where a simulated Azure Stack policy is blocking you, Azure Stack's default setup doesn't restrict creating Automation Accounts—you just need the right permissions (like Contributor or Automation Contributor role on your Azure Stack subscription/resource group). Here's how to do it:
- Log into your Azure Stack portal (not public Azure) and search for "Automation Accounts" in the top search bar.
- Click Create to start the setup wizard.
- Fill in the required details:
- Select your Azure Stack-specific subscription and resource group (or create a new resource group if needed).
- Name your Automation Account (follow Azure's naming rules).
- Choose your Azure Stack region (usually
localor a region defined by your Azure Stack operator).
- Skip any optional settings (like managed identities) unless you have specific needs, then click Review + Create to confirm and deploy the account.
If you hit a policy block in Azure Stack (unlikely by default), reach out to your Azure Stack tenant administrator to check if there's a custom policy restricting Microsoft.Automation/automationAccounts/write operations. They can either adjust the policy or grant you an exception.
Once your Automation Account is ready, follow these steps to get your Runbooks up and running:
1. Create or Import a Runbook
- Navigate to your Automation Account in the Azure Stack portal.
- From the left menu, select Runbooks under Process Automation.
- Click Create a runbook:
- Pick the Runbook type (PowerShell, PowerShell Workflow, Python, Graphical, etc.—most types supported in public Azure work here, but double-check Azure Stack's feature compatibility for niche types).
- Name your Runbook, add a description, then click Create.
- Alternatively, if you're migrating a Runbook from public Azure:
- Export the Runbook from your public Azure Automation Account as a
.ps1(or corresponding format) file. - Back in Azure Stack, click Import a runbook from the Runbooks page, upload the file, and ensure you select the correct Runbook type.
- Critical: Update any public Azure-specific references in the Runbook (like resource IDs, Azure service endpoints) to use Azure Stack equivalents. For example, use
Connect-AzAccount -EnvironmentName AzureStackCloudto authenticate to Azure Stack instead of the default public cloud environment.
- Export the Runbook from your public Azure Automation Account as a
2. Test and Publish the Runbook
- Open the Runbook in edit mode, then use the Test pane to run a test execution. This lets you verify it works with Azure Stack resources (like VMs, storage accounts) before going live.
- Fix any errors (common issues include incorrect endpoint references or missing permissions for the Automation Account).
- Once testing passes, click Publish to make the Runbook available for production runs.
3. Configure Execution Triggers (Optional)
- To automate Runbook runs, set up triggers like:
- Schedules: Go to Schedules in your Automation Account, create a schedule, then link it to your Runbook.
- Webhooks: Generate a webhook to trigger the Runbook from external systems.
- Azure Monitor Alerts: Link the Runbook to an alert rule to respond to specific resource events in Azure Stack.
- If you need the Runbook to access resources outside your Azure Stack environment, set up a Hybrid Runbook Worker: Install the Hybrid Worker agent on the target machine, then register it with your Azure Stack Automation Account.
- Permissions: Ensure your Automation Account has the necessary roles to access target resources (e.g., assign the VM Contributor role to the Automation Account for VM management tasks).
- PowerShell Compatibility: Use Azure PowerShell modules compatible with Azure Stack—you can import modules directly from the Automation Account's Modules page if needed.
- Environment Context: Always explicitly target the Azure Stack environment in your Runbook scripts to avoid conflicts with public Azure configurations.
内容的提问来源于stack exchange,提问作者shakti prasad mohapatra

