如何限制ServiceFabric集群访问,仅允许API Management的IP接入
Great question! Locking down your Service Fabric (SF) cluster so only API Management (APIM) can send traffic to it is a smart security move, and it’s totally achievable using Azure’s network security controls. Here’s a step-by-step breakdown to make this happen:
Key Background
Service Fabric clusters hosted on Azure rely on Network Security Groups (NSGs) to enforce IP-level access rules. NSGs act as a firewall for your cluster’s subnets/nodes, letting you allow or deny traffic based on IP, port, and protocol. Since you already use a load balancer for port restrictions, adding NSG rules will layer on the IP-based filtering you need.
Step 1: Get API Management’s Outbound IP Addresses
First, you need the public IPs that APIM uses to send outbound traffic to your SF cluster. You can grab these in two ways:
- Azure Portal: Navigate to your APIM instance → Overview → Look for the "Outbound IP addresses" field (it’ll list all public IPs associated with your APIM service).
- Azure CLI: Run this command (replace
<apim-resource-group>and<apim-name>):
Note: If your APIM is deployed inside a virtual network, use the VNet’s address range instead of public IPs.az apim show --resource-group <apim-resource-group> --name <apim-name> --query "publicIpAddresses" --output tsv
Step 2: Locate Your Service Fabric Cluster’s NSG
Your SF cluster’s node pools are linked to an NSG (usually created automatically when you provision the cluster). To find it:
- Go to your SF cluster in the Azure Portal → Nodes → Select your node pool → Under "Settings", click "Network security group".
- Alternatively, find the virtual machine scale set (VMSS) for your node pool, then check its network configuration for the associated NSG.
Step 3: Configure NSG Inbound Rules
Now you’ll set up rules to allow only APIM traffic and block everything else:
Add an Allow Rule for APIM:
- In the NSG’s "Inbound security rules" section, click "Add".
- Fill in the details:
- Priority: Set a high priority (e.g., 100) — this ensures it runs before default deny rules.
- Name: Something like
Allow_APIM_To_SF - Source: Select "IP Addresses" and paste the APIM IPs/ranges you collected.
- Source port ranges: Leave as
*(APIM can use any outbound port). - Destination: Select "Any" or your SF cluster’s subnet address range.
- Destination port ranges: Enter the ports your SF cluster exposes for traffic (e.g.,
80,443for HTTP/HTTPS). - Protocol: Select
TCP(orUDPif your service uses it). - Action:
Allow
- Save the rule.
Ensure Default Deny for All Other Traffic:
- The default NSG inbound rule (
DenyAllInBound) has a low priority (65500), which means it will block all traffic not explicitly allowed by higher-priority rules. You don’t need to change this, but double-check it’s enabled to make sure non-APIM traffic gets blocked.
- The default NSG inbound rule (
Step 4: Verify the Configuration
To confirm everything works as expected:
- Test access from an IP not in your APIM list: Try hitting your SF cluster’s endpoint — it should be blocked (you’ll get a timeout or connection refused).
- Test via APIM: Send a request through your APIM service to the SF cluster — it should succeed.
Bonus Tips
- If your APIM scales out or changes IPs, remember to update the NSG rule with the new addresses.
- For extra security, consider pairing this with APIM’s mutual TLS (mTLS) authentication to add another layer of validation for incoming traffic.
内容的提问来源于stack exchange,提问作者Seppe Goossens

