【发布时间】:2017-12-15 05:08:43
【问题描述】:
我正在开发一个脚本,该脚本可以从我配置了 RBAC 的每个订阅中的所有存储帐户中获取多个参数。我已经测试了该脚本在本地完全可以正常工作,但是当我尝试将它带到 Azure 自动化(以便我可以安排它在未来工作)时,我遇到了很多 Get-AzureRmStorageAccountKey 命令问题,因为它似乎没有输出任何东西。
这不是我正在编写的整个脚本,而是相关部分:
$VerbosePreference = 'Continue'
$connectionName = "AzureRunAsConnection"
try
{
# Get the connection "AzureRunAsConnection "
$servicePrincipalConnection=Get-AutomationConnection -Name $connectionName
"Logging in to Azure..."
Add-AzureRmAccount `
-ServicePrincipal `
-TenantId $servicePrincipalConnection.TenantId `
-ApplicationId $servicePrincipalConnection.ApplicationId `
-CertificateThumbprint $servicePrincipalConnection.CertificateThumbprint
}
catch {
if (!$servicePrincipalConnection)
{
$ErrorMessage = "Connection $connectionName not found."
throw $ErrorMessage
} else{
Write-Error -Message $_.Exception
throw $_.Exception
}
}
$storageaccounts = get-azurermstorageaccount
ForEach ($account in $storageaccounts)
{
$PrimaryKey = Get-AzureRmStorageAccountKey -ResourceGroupName $account.ResourceGroupName
$PrimaryKey
在我脚本的最后一行,我希望得到变量 $PrimaryKey 的输出,但它是空的,正如我也目睹了当我的脚本移动到下一部分时遇到错误说它无法引用一个空值。
当我在 Powershell ISE 上本地运行此程序时,一切都很好,并且我列出了所有主 SAS 密钥。我用 ISE 的 Azure 自动化模块尝试了这个,它在本地测试中也很有效。在 Azure 上测试草稿后,即使详细登录,我也完全没有得到任何结果,最后的输出是。
Environments
------------
{[AzureChinaCloud, AzureChinaCloud], [AzureCloud, AzureCloud],
[AzureGermanCloud, AzureGermanCloud], [AzureUSGovernme...
有没有人有经验,这是自动化脚本不会泄露被视为私有信息(例如 SAS 密钥)的某种预期行为吗?对我来说,问题是我不能在这里使用固定变量(至少我不知道我怎么能),因为我对所有现有的存储帐户运行这个脚本,我希望脚本在没有人工干预的情况下工作,即使创建了新帐户。
干杯。
【问题讨论】:
标签: powershell azure azure-automation