Durable Functions部署后调用失败:请求未授权执行操作
按照Durable Functions Python VS Code快速教程部署示例应用后,无法调用已发布的函数,函数应用日志报错如下:
[Information] func1-control-00: CreateLeaseIfNotExistAsync - leaseContainerName: func1-leases, leaseType: ownership, partitionId: func1-control-00
[Error] An error occurred while processing messages on func1-workitems:
DurableTask.AzureStorage.Storage.DurableTaskStorageException: This request is not authorized to perform this operation.
---> Microsoft.WindowsAzure.Storage.StorageException: This request is not authorized to perform this operation.
at Microsoft.WindowsAzure.Storage.Core.Executor.Executor.ExecuteAsyncInternal[T](RESTCommand1 cmd, IRetryPolicy policy, OperationContext operationContext, CancellationToken token) at Microsoft.WindowsAzure.Storage.Queue.CloudQueue.CreateIfNotExistsAsync(QueueRequestOptions options, OperationContext operationContext, CancellationToken cancellationToken) at DurableTask.AzureStorage.TimeoutHandler.ExecuteWithTimeout[T](String operationName, String account, AzureStorageOrchestrationServiceSettings settings, Func3 operation, AzureStorageOrchestrationServiceStats stats, String clientRequestId) in //src/DurableTask.AzureStorage/TimeoutHandler.cs:line 133
at DurableTask.AzureStorage.Storage.AzureStorageClient.MakeStorageRequest[T](Func`3 storageRequest, String accountName, String operationName, String clientRequestId, Boolean force) in //src/DurableTask.AzureStorage/Storage/AzureStorageClient.cs:line 137
解决方案
- 核对存储连接字符串:进入Azure门户的函数应用,在「配置」→「应用程序设置」中找到
AzureWebJobsStorage,确认连接字符串与对应存储账户的主/次密钥完全一致。 - 配置存储账户权限:确保函数应用的身份(托管标识或连接字符串对应的账户)拥有存储账户的「存储队列数据参与者」和「存储Blob数据参与者」角色。若使用托管标识,需在存储账户的「访问控制(IAM)」中添加角色分配。
- 调整存储防火墙规则:如果存储账户开启了防火墙,需勾选「允许受信任的Microsoft服务访问此存储账户」,或者将函数应用的出站IP添加到存储账户的允许列表中。
- 检查存储资源状态:手动确认存储账户中是否存在
func1-leases容器和func1-workitems队列,若缺失,可尝试手动创建,或重启函数应用触发自动创建(需确保权限足够)。 - 更新Durable扩展版本:在VS Code中更新Azure Functions的Durable扩展,或部署时使用最新版本的扩展包,避免旧版本的兼容性问题。
内容的提问来源于stack exchange,提问作者Marek Grzenkowicz

