You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Deployment Script中使用禁用本地认证的现有存储账户?

问题描述

根据微软官方文档《Use existing storage account》说明,存储账户的allowSharedKeyAccess属性需设为true,因为Azure容器实例(ACI)仅能通过访问密钥挂载存储账户。但我们订阅应用了内置策略《Storage accounts should prevent shared key access》,会阻止创建时该属性为true的存储账户。

运行以下Bicep模板时,遇到KeyBasedAuthenticationNotPermitted错误:

resource addRoleAssignments 'Microsoft.Resources/deploymentScripts@2023-08-01' = {
  name: resourceName
  location: resourceGroup().location
  kind: 'AzurePowerShell'
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${userAssignedIdentity.id}': {}
    }
  }
  properties: {
    azPowerShellVersion: '13.2'
    environmentVariables: []
    scriptContent: loadTextContent('../../../.scripts/AddRoleAssignments.ps1')
    arguments: '-TenantId ${tenantId} -SubscriptionId ${subscriptionId} -ResourceGroup ${resourceGroupName} -UserManagedIdentity ${identityName} -RoleAssignmentsBase64 \"${allRoleAssignmentsEncoded}\"'
    cleanupPreference: 'OnSuccess'
    retentionInterval: 'P1D'
    // Deployment scripts are idempotent, so we can use utcnow on Tag to force an update
    forceUpdateTag: 'Run-${timestamp}'
    containerSettings: {containerGroupName: containerName}
    storageAccountSettings: {storageAccountName: storageAccountDeploymentName, storageAccountKey: listKeys(resourceId('Microsoft.Storage/storageAccounts', storageAccount.name), '2023-01-01').keys[0].value}
  }
}

错误信息:

Status: failed
Error: 
    Code: DeploymentScriptOperationFailed
    Message: Key based authentication is not permitted on this storage account.
RequestId:d2cb5954-d01a-00ba-6c8a-aadc2d000000
Time:2025-04-11T02:35:31.0724116Z
Status: 403 (Key based authentication is not permitted on this storage account.)
ErrorCode: KeyBasedAuthenticationNotPermitted

请问是否有解决办法?能否为现有存储账户添加该策略例外,再在Deployment Script参数中指定该账户?

解决办法

1. 为目标存储账户添加策略例外(可行)

可以直接给需要使用的存储账户创建策略豁免,绕过《Storage accounts should prevent shared key access》的限制:

  • 进入Azure门户,找到目标存储账户,进入「策略」>「豁免」
  • 点击「添加豁免」,选择应用的内置策略,设置豁免范围为该存储账户,指定豁免有效期(按需设置)
  • 完成后更新存储账户的allowSharedKeyAccess属性为true(如果之前被策略阻止未设置的话)
  • 之后在Deployment Script的storageAccountSettings中指定该账户即可正常使用密钥访问

2. 改用托管标识访问存储账户(推荐)

如果不想启用共享密钥访问,可以修改Deployment Script配置,使用托管标识来访问存储账户,无需依赖共享密钥:

  • 给Deployment Script使用的用户分配标识(UserAssignedIdentity)添加存储账户的「存储Blob数据参与者」或「存储账户操作员」角色
  • 修改Bicep模板,移除storageAccountSettings中的storageAccountKey参数,Deployment Script会自动使用托管标识进行身份验证

3. 调整策略范围(全局场景)

如果多个存储账户需要使用共享密钥,可以修改内置策略的分配范围,排除特定资源组或存储账户,避免逐个添加豁免:

  • 找到策略分配,进入「编辑分配」
  • 在「范围」中排除不需要应用该策略的资源组或存储账户
  • 保存后,被排除的存储账户即可设置allowSharedKeyAccess为true

内容的提问来源于stack exchange,提问作者Guilherme Matheus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 10:24:56