使用Azure CLI分配用户托管身份到WebApp时遇LinkedInvalidPropertyId错误
Azure CLI分配用户托管身份到WebApp时的路径前缀异常问题
问题重现步骤
- 执行以下命令获取名为
myIdentity的托管身份资源ID:
# 获取现有托管身份myIdentity的资源ID identityResourceId=$(az identity show --name 'myIdentity' \ --resource-group 'myResourceGroup' --query id -o tsv)
- 打印变量验证资源ID格式正确:
echo "ResourceId: $identityResourceId" # 输出结果: ResourceId: /subscriptions/mySubscriptionId/resourceGroups/myResourceGroup/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myIdentity
- 执行WebApp身份分配命令时抛出
LinkedInvalidPropertyId错误:
az webapp identity assign --resource-group myResourceGroup --name myWebApp --identities $identityResourceId
错误信息:
(LinkedInvalidPropertyId) Property id 'C:/Program Files/Git/subscriptions/mySubscription/resourceGroups/myResourceGroup/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myIdentity' at path '' is invalid. Expect fully qualified resource Id that start with '/subscriptions/{subscriptionId}' or '/providers/{resourceProviderNamespace}/'. Code: LinkedInvalidPropertyId Message: Property id 'C:/Program Files/Git/subscriptions/mySubscription/resourceGroups/myResourceGroup/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myIdentity' at path '' is invalid. Expect fully qualified resource Id that start with '/subscriptions/{subscriptionId}' or '/providers/{resourceProviderNamespace}/'.
问题原因
这是Git Bash的路径解析特性导致的:Git Bash会将以/开头的字符串识别为类Unix路径,并自动转换为Windows下的绝对路径(映射到Git安装目录),所以原本的/subscriptions/...被替换成了C:/Program Files/Git/subscriptions/...。
解决方案
方案1:用双引号包裹变量
执行分配命令时,将变量用双引号包裹,避免Git Bash解析路径:
az webapp identity assign --resource-group myResourceGroup --name myWebApp --identities "$identityResourceId"
方案2:禁用Git Bash的路径转换
临时禁用路径转换(仅对当前命令生效):
MSYS_NO_PATHCONV=1 az webapp identity assign --resource-group myResourceGroup --name myWebApp --identities $identityResourceId
或者全局设置环境变量MSYS_NO_PATHCONV=1,永久禁用路径转换。
方案3:更换终端执行命令
使用PowerShell或CMD替代Git Bash运行Azure CLI命令,这类终端不会对Unix风格路径做自动转换。
内容的提问来源于stack exchange,提问作者Nagesh Chauhan
相关产品推荐
相关产品推荐

