如何将新秘密添加到启用了私有端点的Azure KeyVault
我有一个启用了私有端点的密钥维护。
我允许我们在钥匙值防火墙上使用WAN IP,但是当我浏览“秘密”选项卡时,我会收到以下错误: -
“与数据平面的连接失败。请刷新并重试。 如果在保险库上启用了私人链接,并且问题仍然存在 请按照以下链接中的步骤操作 https://go.microsoft.com/fosoft.com/fwlink/?linkid=2156688 。 “
此外,我在与KeyVault端点地址的子网上具有VM。但是仅通过代理允许在这些VM上进行Internet访问。这些VM的子网在KeyVault Firewall上允许。
如果尝试从Azure Console访问KeyVault 。从这些VM到代理,我会得到以下错误: -
“刷新浏览器重试。
microsoft_azure_keyvault扩展名无法加载。
请访问Portal自助执行诊断。”
我注意到我们的Azure托管DNS区域有一个DNS问题。 “ KeyVaultName.VaultCore.azure.net”在这些Azure VMS上或在本地网络上的“ KeyVaultName.privatelink.vaultcore.azure.net”不相称。因此,现在我添加了一个主机文件条目,以将“ keyVaultName.vaultcore.azure.net”解析到私有端点IP地址。
但是,KeyVault控制台访问仍然给出了这些Azure VM上的上述错误。
我如何使用控制台访问现有的秘密并在此保险库中添加新的秘密(或Azure VMS中的PowerShell是访问这些保险箱的唯一选择)?
I have a keyvault which has private endpoint enabled.
I have allowed our WAN IP on the keyvault firewall but when I browse to the "Secrets" tab then I get the following error:-
" The connection to data plane failed. Please refresh and try again.
If Private Links are enabled on the vault and the issue persists
please follow the steps in the following link
https://go.microsoft.com/fwlink/?linkid=2156688 . "
Also, I have VMs on the same subnet as the keyvault endpoint address. But the internet access is only allowed through proxy on those VMs. The subnets for these VMs are allowed on the keyvault firewall.
If try to access the keyvault from Azure console from these VMs through proxy I get following error:-
"Refresh the browser to try again.
Microsoft_Azure_KeyVault extension failed to load.
Please visit Portal Self Help to perform diagnostics."
There is a DNS problem I have noticed with our Azure hosted DNS zone. "keyvaultname.vaultcore.azure.net" does not alias to "keyvaultname.privatelink.vaultcore.azure.net" on these Azure VMs or on on-prem network. So for now I added a host file entry to resolve "keyvaultname.vaultcore.azure.net" to the private endpoint IP address.
But still the keyvault console access gives the above error on these Azure VMs.
How can I access existing secrets and add new ones to this vault using console (or powershell from the Azure VMs will be the only option to access these)?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
正如您所说,请重新检查并确保防火墙规则,以创建和测试IP,如果达到该端点。
另外,建议您采用提琴手的跟踪,以更深入地分析该问题。
尝试下面尝试:
诊断私人链接在Azure Key Vault上配置问题|微软文档
As you said you have , please recheck and make sure firewall rule to allow that IP is created and tested if thats reaching that endpoint.
Also suggest you take a Fiddler trace to analyse the issue deeper.
Try below :
Diagnose private links configuration issues on Azure Key Vault | Microsoft Docs