You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure Automation的PS DSC中正确定义PSDscAllowPlainTextPassword

解决Azure Automation DSC中PSDscAllowPlainTextPassword的配置问题

要绕过这个明文密码相关的报错,你需要在节点(node)块内部直接声明PSDscAllowPlainTextPassword = $true,这是告知DSC编译器允许当前节点资源使用明文存储密码的关键配置。

修改后的完整配置文件

#command to create config file
configuration NonProd {

Import-DscResource -ModuleName ComputerManagementDsc
Import-DscResource -Module NetworkingDsc
Import-DscResource -ModuleName PSDscResources
Import-DscResource -Module cChoco

$filesharecreds = Get-AutomationPSCredential -Name InfraFileShareCreds

node Server {
    # 声明允许明文密码,必须放在节点块内、资源定义之前
    PSDscAllowPlainTextPassword = $true

    LocalConfigurationManager { 
        RebootNodeIfNeeded = $false
    } 

    file installers {
        Ensure          = "Present"
        Type            = "directory"
        Recurse         = $true
        Matchsource     = $true
        sourcepath      = "\\share.file.core.windows.net\installers"
        destinationpath = "c:\\temp\installers"
        credential      = $filesharecreds
    }

  } #node config

} #configuration

关键说明

  • PSDscAllowPlainTextPassword = $true必须放在节点块内部,且在所有资源(如示例中的file资源)定义之前,才能被DSC编译器正确识别。
  • 该配置为节点级别,作用于当前节点下所有需要使用密码的DSC资源。

重新执行导入与编译步骤

保持你原有的命令不变即可:

Import-AzAutomationDscConfiguration -SourcePath ".\\NonProd.ps1" -ResourceGroupName "rg" -AutomationAccountName "aa" -Published -force
Start-AzAutomationDscCompilationJob -ConfigurationName "NonProd" -ResourceGroupName "rg" -AutomationAccountName "aa"

重要提醒

虽然该设置能快速解决当前问题,但明文存储密码存在严重安全风险,建议在生产环境中尽快切换到MOF加密方式,通过Azure Automation证书加密DSC配置中的敏感信息。

内容的提问来源于stack exchange,提问作者Guy Wood

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 06:57:39