✔️ 適用於: 由 Microsoft.Storage 資源提供者建立的經典 NFS 檔案共用
✔️ 適用於: 使用 Microsoft.FileShares 資源提供者建立的 NFS 檔案共用
✖️ 不適用於: SMB 檔案共享
用戶端作業系統會強制 NFS 檔案分享權限,而不是 Azure 檔案儲存體 服務。 根壓縮是 NFS 中的系統管理安全性功能,可防止由用戶端機器對 NFS 伺服器未經授權的根層級存取。 這項功能是保護使用者資料和系統設定免遭未受信任或遭入侵用戶端操作的重要部分。。
系統管理員應在多個使用者或系統存取 NFS 共用的環境中啟用根壓縮,特別是在用戶端機器未受完全信任的案例中。 藉由將根使用者轉換成匿名使用者,根壓縮可確保即使用戶端機器遭到入侵,攻擊者也無法惡意探索根權限,來存取或修改 NFS 伺服器上的重要檔案。
在本文中,您會了解如何設定及變更 NFS Azure 檔案共用的根壓縮設定。
根壓縮如何搭配 Azure 檔案儲存體使用
Root squash 的運作方式,是將 root 使用者的使用者 ID(UID)和群組 ID(GID)映射為伺服器上匿名使用者所屬的 UID 和 GID。 存取檔案系統的根用戶會自動轉換為匿名且權限較低的使用者及群組,權限有限。
儘管根擠壓是 NFS 中的預設行為,但在建立 NFS Azure 檔案共享時,其並非預設選項。 您必須在檔案共用上明確啟用根擠壓。 您可以在建立 NFS Azure 檔案共用時或稍後執行此動作。
根壓縮設定
可選擇下列三種 root squash 設定:
-
沒有根壁球:關閉根壁球。 此選項主要適用於無磁碟用戶端或工作負載文件所指定的工作負載。 這個設定是建立新 NFS Azure 檔案分享時的預設設定。
-
所有壓縮:將所有 UID 和 GID 對應至匿名使用者。 使用此設定用於需要所有用戶端只讀存取的共享。
-
根壓縮:將 UID/GID 0 (root) 的要求對應至匿名 UID/GID。 此設定不適用於其他可能同樣敏感的 UID 或 GID,例如使用者箱或群組工作人員。
下表突出顯示當您設定特定的根權限壓縮選項時,從伺服器端觀察到的 UID 行為。
|
選項 |
用戶端 UID |
伺服器 UID |
| root_squash |
0 |
65534 |
| root_squash |
1000 |
1000 |
| no_root_squash |
0 |
0 |
| no_root_squash |
1000 |
1000 |
| all_squash |
0 |
65534 |
| all_squash |
1000 |
65534 |
對於使用 Microsoft.Storage 資源提供者的 Azure 傳統檔案共用,您可以透過 Azure 入口網站、Azure PowerShell 或 Azure CLI 設定 root squash 設定。
登入 Azure 入口網站,並前往包含 NFS Azure 檔案分享的 FileStorage 儲存帳號。
在服務選單中,資料 儲存區,選擇 經典檔案分享。
選取您想變更根權限壓縮設定的檔案共用。
在服務功能表上,選取 [屬性]。 然後視需要切換 [根壓縮] 設定。
選取 [儲存] 以更新根壓縮值。
登入 Azure 並選取您的訂用帳戶。
Connect-AzAccount
Select-AzSubscription -SubscriptionId "<your-subscription-id>"
若要在檔案共用上啟用根壓縮,請執行下列命令。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
Update-AzRmStorageShare `
-ResourceGroupName <resource-group-name> `
-StorageAccountName <storage-account-name> `
-Name <file-share-name> `
-RootSquash RootSquash
若要在檔案共用上停用根壓縮,請執行下列命令。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
Update-AzRmStorageShare `
-ResourceGroupName <resource-group-name> `
-StorageAccountName <storage-account-name> `
-Name <file-share-name> `
-RootSquash NoRootSquash
若要強制所有使用者的壓縮,請執行下列命令,以將所有使用者識別碼對應至匿名。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
Update-AzRmStorageShare `
-ResourceGroupName <resource-group-name> `
-StorageAccountName <storage-account-name> `
-Name <file-share-name> `
-RootSquash AllSquash
若要檢視檔案共用的根壓縮屬性,請執行下列命令。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
Get-AzRmStorageShare `
-ResourceGroupName <resource-group-name> `
-StorageAccountName <storage-account-name> `
-Name <file-share-name> | fl -Property ResourceGroupName, StorageAccountName, Name, QuotaGiB,AccessTier,EnabledProtocols,RootSquash
登入 Azure 並設定您的訂用帳戶。
az login
az account set --subscription "<your-subscription-id>"
若要在檔案共用上啟用根壓縮,請執行下列命令。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
az storage share-rm update \
--resource-group <resource-group-name> \
--storage-account <storage-account-name> \
--name <file-share-name> \
--root-squash RootSquash
若要在檔案共用上停用根壓縮,請執行下列命令。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
az storage share-rm update \
--resource-group <resource-group-name> \
--storage-account <storage-account-name> \
--name <file-share-name> \
--root-squash NoRootSquash
若要強制所有使用者的壓縮,請執行下列命令,以將所有使用者識別碼對應至匿名。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
az storage share-rm update \
--resource-group <resource-group-name> \
--storage-account <storage-account-name> \
--name <file-share-name> \
--root-squash AllSquash
若要檢視檔案共用的根壓縮屬性,請執行下列命令。 將 <resource-group-name>、<storage-account-name> 和 <file-share-name> 取代為您自己的值。
az storage share-rm show \
--resource-group <resource-group-name> \
--storage-account <storage-account-name> \
--name <file-share-name>
對於使用 Microsoft.FileShares 資源提供者的 Azure 檔案共用,您可以使用 Azure 入口網站、Azure PowerShell 或 Azure CLI 來設定 root squash 設定。
登入 Azure 入口網站,然後進入檔案分享。
在服務功能表的 [設定] 底下,選取 [組態]。
視需要切換根權限壓縮設定。
選取 [儲存] 以更新根壓縮值。
若要使用 Azure PowerShell 變更檔案共用(Microsoft.FileShares)上的 root squash 設定,請執行下列命令。 用你的數值替換變數。 允許的 -RootSquash 值為 AllSquash、 NoRootSquash、 RootSquash和 。
# To learn more about the Az.FileShare module, see https://www.powershellgallery.com/packages/Az.FileShare/1.0.0
Install-Module -Name Az.FileShare -Repository PSGallery -RequiredVersion 1.0.0
$resourceGroup = "<your-resource-group-name>"
$shareName = "<your-file-share-name>"
Update-AzFileShare -ResourceName $shareName -ResourceGroupName $resourceGroup -RootSquash RootSquash
若要使用 Azure CLI 變更檔案共用(Microsoft.FileShares)的 root squash 設定,請執行下列命令。 允許的 --root-squash 值為 AllSquash、 NoRootSquash、 RootSquash和 。
# Install the fileshare extension
az extension add --name fileshare
# Specify your values
shareName="<your-file-share-name>"
resourceGroup="<your-resource-group-name>"
# Update the root squash setting
az fileshare update --name $shareName --resource-group $resourceGroup --root-squash RootSquash
另請參閱