如何在Azure中获取所有storage accounts列表?(含C#及Azure Functions实现)
Great questions! Let's tackle each one step by step:
1. 获取所有Storage Accounts using Azure Functions
Absolutely, you can build an Azure Function to retrieve all Storage Accounts in your subscription (or even across multiple subscriptions, if you have the right permissions). Here's how to approach it:
- Permissions First: Your Azure Function needs proper access to enumerate Storage Accounts. The simplest way is to enable a system-assigned managed identity for your Function App, then assign it a role like
Storage Account ReaderorContributorat the subscription/resource group level. This avoids hardcoding credentials entirely. - Use Azure Management Libraries: For .NET functions, leverage the
Azure.ResourceManager.StorageNuGet package. For Python/JavaScript, use the corresponding Azure SDK packages (azure-mgmt-storagefor Python,@azure/arm-storagefor JS).
Here's a quick C# example of an HTTP-triggered function that fetches all Storage Accounts in a subscription:
using Azure.Identity; using Azure.ResourceManager; using Azure.ResourceManager.Storage; using Microsoft.Azure.Functions.Worker; using Microsoft.Azure.Functions.Worker.Http; using System.Net; public class StorageAccountFetcher { [Function("GetAllStorageAccounts")] public async Task<HttpResponseData> Run([HttpTrigger(AuthorizationLevel.Function, "get")] HttpRequestData req) { // Authenticate using the Function's managed identity var armClient = new ArmClient(new DefaultAzureCredential()); // Replace with your subscription ID, or fetch it dynamically if needed var subscriptionId = "<your-subscription-id>"; var subscription = armClient.GetSubscriptionResource(new Azure.Core.ResourceIdentifier($"/subscriptions/{subscriptionId}")); // Fetch all Storage Accounts in the target subscription var storageAccounts = await subscription.GetStorageAccounts().GetAllAsync().ToListAsync(); // Format and return the response var response = req.CreateResponse(HttpStatusCode.OK); await response.WriteAsJsonAsync(storageAccounts.Select(sa => new { Name = sa.Data.Name, ResourceId = sa.Data.Id, Location = sa.Data.Location })); return response; } }
For other languages, the core logic stays the same: authenticate via managed identity, use the ARM SDK to list storage accounts under your target scope.
2. Single SAS Token for All Storage Accounts?
Unfortunately, this isn't possible. SAS tokens are strictly scoped to a single Storage Account (or a container/queue within it)—there's no way to generate one SAS that grants access to multiple Storage Accounts. Here's why:
- SAS tokens are signed using the access keys (or user delegation key) of a specific Storage Account. The signature is tied directly to that account's credentials, so it can't be used to authenticate against another account.
- Even user delegation SAS tokens (which use Azure AD to sign) are still limited to a single Storage Account.
Alternative Solutions:
- Use Azure AD Authentication: Instead of relying on SAS tokens, use Azure AD identities (like your Function's managed identity) to access all Storage Accounts. As long as the identity has the right roles (e.g.,
Storage Blob Data Readeron each account or at a higher scope), you can authenticate without needing any SAS tokens. This is the recommended approach for modern Azure applications. - Generate Per-Account SAS Tokens: If you must use SAS tokens, you'll need to generate a separate SAS for each Storage Account. Your Azure Function can loop through the list of accounts (from the first step), generate a SAS for each one, and return a collection of account-SAS pairs. You can then use each SAS with
StorageCredentials(string sasToken)for its corresponding account.
内容的提问来源于stack exchange,提问作者HudsonPH

