【问题标题】:Azure API Management with multiple backends具有多个后端的 Azure API 管理
【发布时间】:2020-10-15 16:54:10
【问题描述】:
我有一个 Azure API 管理集并正在运行。 API 调用是对在 Azure 虚拟机上运行 FastAPI 的 Docker 容器进行的。这个后端容器负责根据它收到的查询运行一些 AI 模型。对于单个用户来说一切正常。
问题是:这些 AI 模型是在容器内的配置文件中定义的,并且是特定于用户的。
我想使用 Azure API 管理来根据用户订阅路由请求。换句话说,给定订阅,我想知道要调用哪个后端(每个后端都是一个容器,为 Azure 虚拟机上的特定用户/公司运行特定的 AI 模型)。
解决这个问题的最佳方法是什么?
【问题讨论】:
标签:
azure
api
frontend
backend
【解决方案1】:
我发现您可以使用入站策略来指定要使用的后端,具体取决于用户所属的组。对我的回答的引用来自from here。
转到您的 API 管理,选择组并创建与您的用户相关的组。然后将您的用户添加到他们各自的组中。
转到您的 API,选择入站规则并使用以下方式指定您的后端:
<policies>
<inbound>
<choose>
<when condition="@(context.User.Groups.Select(g => g.Name).Contains("org1"))">
<set-backend-service base-url="https://abc-apim.azure-api.net/org1app" />
</when>
<when condition="@(context.User.Groups.Select(g => g.Name).Contains("org2"))">
<set-backend-service base-url="https://abc-apim.azure-api.net/org2app" />
</when>
<otherwise>
<return-response>
<set-status code="401" reason="Unauthorized" />
<set-header name="WWW-Authenticate" exists-action="override">
<value>Bearer error="Invalid user group"</value>
</set-header>
</return-response>
</otherwise>
</choose>
<base />
</inbound>
<backend>
<base />
</backend>
<outbound>
<base />
</outbound>
<on-error>
<base />
</on-error>
</policies>
我不明白这种方法不是那么优雅,因为您必须在策略中对后端路由进行硬编码。但它有效。