如何在Deployment Script中使用禁用本地认证的现有存储账户?
问题描述
根据微软官方文档《Use existing storage account》说明,存储账户的allowSharedKeyAccess属性需设为true,因为Azure容器实例(ACI)仅能通过访问密钥挂载存储账户。但我们订阅应用了内置策略《Storage accounts should prevent shared key access》,会阻止创建时该属性为true的存储账户。
运行以下Bicep模板时,遇到KeyBasedAuthenticationNotPermitted错误:
resource addRoleAssignments 'Microsoft.Resources/deploymentScripts@2023-08-01' = { name: resourceName location: resourceGroup().location kind: 'AzurePowerShell' identity: { type: 'UserAssigned' userAssignedIdentities: { '${userAssignedIdentity.id}': {} } } properties: { azPowerShellVersion: '13.2' environmentVariables: [] scriptContent: loadTextContent('../../../.scripts/AddRoleAssignments.ps1') arguments: '-TenantId ${tenantId} -SubscriptionId ${subscriptionId} -ResourceGroup ${resourceGroupName} -UserManagedIdentity ${identityName} -RoleAssignmentsBase64 \"${allRoleAssignmentsEncoded}\"' cleanupPreference: 'OnSuccess' retentionInterval: 'P1D' // Deployment scripts are idempotent, so we can use utcnow on Tag to force an update forceUpdateTag: 'Run-${timestamp}' containerSettings: {containerGroupName: containerName} storageAccountSettings: {storageAccountName: storageAccountDeploymentName, storageAccountKey: listKeys(resourceId('Microsoft.Storage/storageAccounts', storageAccount.name), '2023-01-01').keys[0].value} } }
错误信息:
Status: failed Error: Code: DeploymentScriptOperationFailed Message: Key based authentication is not permitted on this storage account. RequestId:d2cb5954-d01a-00ba-6c8a-aadc2d000000 Time:2025-04-11T02:35:31.0724116Z Status: 403 (Key based authentication is not permitted on this storage account.) ErrorCode: KeyBasedAuthenticationNotPermitted
请问是否有解决办法?能否为现有存储账户添加该策略例外,再在Deployment Script参数中指定该账户?
解决办法
1. 为目标存储账户添加策略例外(可行)
可以直接给需要使用的存储账户创建策略豁免,绕过《Storage accounts should prevent shared key access》的限制:
- 进入Azure门户,找到目标存储账户,进入「策略」>「豁免」
- 点击「添加豁免」,选择应用的内置策略,设置豁免范围为该存储账户,指定豁免有效期(按需设置)
- 完成后更新存储账户的
allowSharedKeyAccess属性为true(如果之前被策略阻止未设置的话) - 之后在Deployment Script的
storageAccountSettings中指定该账户即可正常使用密钥访问
2. 改用托管标识访问存储账户(推荐)
如果不想启用共享密钥访问,可以修改Deployment Script配置,使用托管标识来访问存储账户,无需依赖共享密钥:
- 给Deployment Script使用的用户分配标识(UserAssignedIdentity)添加存储账户的「存储Blob数据参与者」或「存储账户操作员」角色
- 修改Bicep模板,移除
storageAccountSettings中的storageAccountKey参数,Deployment Script会自动使用托管标识进行身份验证
3. 调整策略范围(全局场景)
如果多个存储账户需要使用共享密钥,可以修改内置策略的分配范围,排除特定资源组或存储账户,避免逐个添加豁免:
- 找到策略分配,进入「编辑分配」
- 在「范围」中排除不需要应用该策略的资源组或存储账户
- 保存后,被排除的存储账户即可设置
allowSharedKeyAccess为true
内容的提问来源于stack exchange,提问作者Guilherme Matheus
相关产品推荐
相关产品推荐

