Azure API Management实例从External模式切换至Internal模式的API/脚本咨询
Hey there, you’re right that the Azure Portal doesn’t have a direct toggle to switch an existing APIM instance from External to Internal mode—but we can absolutely get this done using Azure CLI, PowerShell, or the Azure REST API. Here’s how to do each:
Azure CLI Method
This is one of the quickest ways to update the virtual network configuration. Run this command, replacing the placeholders with your resource details:
az apim update --name "your-apim-instance-name" --resource-group "your-resource-group-name" --virtual-network Internal --public-ip-addresses ""
--virtual-network Internalswitches the VNet mode to internal--public-ip-addresses ""clears out the public IP addresses associated with the instance (since Internal mode doesn’t expose a public IP)
Azure PowerShell Method
If you prefer PowerShell, use these commands to modify and update your APIM instance:
# Get the APIM instance object $apimResource = Get-AzApiManagement -ResourceGroupName "your-resource-group-name" -Name "your-apim-instance-name" # Update the VNet type to Internal and clear public IPs $apimResource.VirtualNetworkType = "Internal" $apimResource.PublicIpAddresses = @() # Save the changes Set-AzApiManagement -InputObject $apimResource
Azure REST API Method
You can also send a PUT request to the Azure Management API to update the configuration. Here’s the basic structure:
- Request URL:
https://management.azure.com/subscriptions/{subscription-id}/resourceGroups/{resource-group-name}/providers/Microsoft.ApiManagement/service/{apim-instance-name}?api-version=2023-03-01-preview - Request Body (JSON):
{ "properties": { "virtualNetworkType": "Internal", "publicIpAddresses": [] }, "sku": { "name": "Premium", // Make sure this matches your current SKU "capacity": 1 }, "location": "your-region" // Match your APIM's region }
Note: You’ll need to authenticate the request using Azure AD (e.g., a service principal or user token).
Important Things to Keep in Mind
- Downtime: The switch process will cause a brief outage for your APIM instance—plan this during a maintenance window.
- VNet Prerequisite: Your APIM instance must already be deployed in a virtual network (External mode can be VNet-integrated or not, but Internal mode requires VNet integration).
- Access Post-Switch: After switching, your APIM will only be accessible from within the virtual network or via your front-end Application Gateway (make sure the gateway is properly configured to route traffic to APIM’s internal IP).
内容的提问来源于stack exchange,提问作者Jasper

