如何编程/脚本获取Azure资源的InternalDnsSuffix?含停机VM及批量场景
Great questions—let’s unpack this clearly since Azure’s internal DNS suffixes are fundamentally tied to virtual networks (VNets), not directly to resource groups, subscriptions, or subnets. That’s the key starting point here.
First, a quick clarification: The InternalDnsSuffix is a property of the VNet that your VM resides in. Subnets inherit this suffix from their parent VNet, resource groups can contain multiple VNets (each with their own suffix), and a subscription can have dozens of VNets. So all queries will ultimately lead back to the VNet associated with your VM/subnet.
You can use Azure CLI, PowerShell, Azure SDKs, or the REST API to fetch this value—no need for a running VM. Here are practical examples:
For a Specific VNet (Direct Query)
Azure CLI
az network vnet show --name <your-vnet-name> --resource-group <your-rg-name> --query 'dnsSettings.internalDnsSuffix' -o tsv
PowerShell
Get-AzVirtualNetwork -Name <your-vnet-name> -ResourceGroupName <your-rg-name> | Select-Object -ExpandProperty DnsSettings | Select-Object InternalDnsSuffix
For a Subnet (Trace to Parent VNet)
Since subnets don’t have their own suffix, you first get the subnet’s parent VNet, then query the VNet:
Azure CLI
# Get the VNet name from the subnet VNET_NAME=$(az network subnet show --name <your-subnet-name> --resource-group <your-rg-name> --vnet-name <your-vnet-name> --query 'id' | cut -d'/' -f9) # Get the suffix from the VNet az network vnet show --name $VNET_NAME --resource-group <your-rg-name> --query 'dnsSettings.internalDnsSuffix' -o tsv
PowerShell
$subnet = Get-AzVirtualNetworkSubnetConfig -Name <your-subnet-name> -VirtualNetwork (Get-AzVirtualNetwork -Name <your-vnet-name> -ResourceGroupName <your-rg-name>) $vnet = Get-AzVirtualNetwork -ResourceId $subnet.VirtualNetwork.Id $vnet.DnsSettings.InternalDnsSuffix
Even if the VM is deallocated/stopped, its network configuration (NIC, subnet, VNet association) is still stored in Azure. You just trace the VM’s network interface back to the VNet:
Azure CLI
# Get the VM's NIC ID NIC_ID=$(az vm show --name <your-vm-name> --resource-group <your-rg-name> --query 'networkProfile.networkInterfaces[0].id' -o tsv) # Get the subnet ID from the NIC SUBNET_ID=$(az network nic show --ids $NIC_ID --query 'ipConfigurations[0].subnet.id' -o tsv) # Extract VNet name from subnet ID VNET_NAME=$(echo $SUBNET_ID | cut -d'/' -f9) # Get the suffix az network vnet show --name $VNET_NAME --resource-group <your-rg-name> --query 'dnsSettings.internalDnsSuffix' -o tsv
PowerShell
$vm = Get-AzVM -Name <your-vm-name> -ResourceGroupName <your-rg-name> $nic = Get-AzNetworkInterface -ResourceId $vm.NetworkProfile.NetworkInterfaces[0].Id $subnetId = $nic.IpConfigurations[0].Subnet.Id # Extract VNet ID from subnet ID $vnetId = ($subnetId -split '/')[0..6] -join '/' $vnet = Get-AzVirtualNetwork -ResourceId $vnetId $vnet.DnsSettings.InternalDnsSuffix
You can loop through a list of VMs (filtered by resource group, subscription, or tag) to fetch their suffixes in bulk. Here are examples:
PowerShell Batch Example
# Get all VMs in a resource group $vmList = Get-AzVM -ResourceGroupName <your-rg-name> # Loop through each VM and collect suffixes $vmDnsDetails = foreach ($vm in $vmList) { $nic = Get-AzNetworkInterface -ResourceId $vm.NetworkProfile.NetworkInterfaces[0].Id $subnetId = $nic.IpConfigurations[0].Subnet.Id $vnetId = ($subnetId -split '/')[0..6] -join '/' $vnet = Get-AzVirtualNetwork -ResourceId $vnetId [PSCustomObject]@{ VMName = $vm.Name ResourceGroup = $vm.ResourceGroupName InternalDnsSuffix = $vnet.DnsSettings.InternalDnsSuffix } } # View results in a table $vmDnsDetails | Format-Table -AutoSize
Bash/Azure CLI Batch Example
#!/bin/bash RG_NAME="your-resource-group" # Get all VM names in the resource group VM_NAMES=$(az vm list --resource-group $RG_NAME --query '[].name' -o tsv) for vm in $VM_NAMES; do # Trace from VM to VNet NIC_ID=$(az vm show --name $vm --resource-group $RG_NAME --query 'networkProfile.networkInterfaces[0].id' -o tsv) SUBNET_ID=$(az network nic show --ids $NIC_ID --query 'ipConfigurations[0].subnet.id' -o tsv) VNET_NAME=$(echo $SUBNET_ID | cut -d'/' -f9) DNS_SUFFIX=$(az network vnet show --name $VNET_NAME --resource-group $RG_NAME --query 'dnsSettings.internalDnsSuffix' -o tsv) echo "VM: $vm | Internal DNS Suffix: $DNS_SUFFIX" done
If you prefer code, the logic is identical: trace the VM → NIC → Subnet → VNet. Here’s a Python snippet:
from azure.identity import DefaultAzureCredential from azure.mgmt.compute import ComputeManagementClient from azure.mgmt.network import NetworkManagementClient credential = DefaultAzureCredential() subscription_id = "your-subscription-id" compute_client = ComputeManagementClient(credential, subscription_id) network_client = NetworkManagementClient(credential, subscription_id) vm_name = "your-vm-name" rg_name = "your-resource-group" # Get VM's NIC ID vm = compute_client.virtual_machines.get(rg_name, vm_name) nic_id = vm.network_profile.network_interfaces[0].id nic_name = nic_id.split('/')[-1] nic_rg = nic_id.split('/')[4] # Get subnet ID from NIC nic = network_client.network_interfaces.get(nic_rg, nic_name) subnet_id = nic.ip_configurations[0].subnet.id vnet_id = '/'.join(subnet_id.split('/')[:7]) vnet_name = vnet_id.split('/')[-1] vnet_rg = vnet_id.split('/')[4] # Get the internal DNS suffix vnet = network_client.virtual_networks.get(vnet_rg, vnet_name) print(f"VM: {vm_name} | Internal DNS Suffix: {vnet.dns_settings.internal_dns_suffix}")
内容的提问来源于stack exchange,提问作者user7411898

