如何在Azure Automation的PS DSC中正确定义PSDscAllowPlainTextPassword
解决Azure Automation DSC中PSDscAllowPlainTextPassword的配置问题
要绕过这个明文密码相关的报错,你需要在节点(node)块内部直接声明PSDscAllowPlainTextPassword = $true,这是告知DSC编译器允许当前节点资源使用明文存储密码的关键配置。
修改后的完整配置文件
#command to create config file configuration NonProd { Import-DscResource -ModuleName ComputerManagementDsc Import-DscResource -Module NetworkingDsc Import-DscResource -ModuleName PSDscResources Import-DscResource -Module cChoco $filesharecreds = Get-AutomationPSCredential -Name InfraFileShareCreds node Server { # 声明允许明文密码,必须放在节点块内、资源定义之前 PSDscAllowPlainTextPassword = $true LocalConfigurationManager { RebootNodeIfNeeded = $false } file installers { Ensure = "Present" Type = "directory" Recurse = $true Matchsource = $true sourcepath = "\\share.file.core.windows.net\installers" destinationpath = "c:\\temp\installers" credential = $filesharecreds } } #node config } #configuration
关键说明
PSDscAllowPlainTextPassword = $true必须放在节点块内部,且在所有资源(如示例中的file资源)定义之前,才能被DSC编译器正确识别。- 该配置为节点级别,作用于当前节点下所有需要使用密码的DSC资源。
重新执行导入与编译步骤
保持你原有的命令不变即可:
Import-AzAutomationDscConfiguration -SourcePath ".\\NonProd.ps1" -ResourceGroupName "rg" -AutomationAccountName "aa" -Published -force
Start-AzAutomationDscCompilationJob -ConfigurationName "NonProd" -ResourceGroupName "rg" -AutomationAccountName "aa"
重要提醒
虽然该设置能快速解决当前问题,但明文存储密码存在严重安全风险,建议在生产环境中尽快切换到MOF加密方式,通过Azure Automation证书加密DSC配置中的敏感信息。
内容的提问来源于stack exchange,提问作者Guy Wood
相关产品推荐
相关产品推荐

