You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署azurerm_container_group遇400错误:镜像无法访问

Azure容器组无法访问ACR镜像(已配置AcrPull角色仍报错)

问题描述

Error: creating Container Group (Subscription: "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
Resource Group Name: "mudkip-rg"
Container Group Name: "mudkipcg"):
performing ContainerGroupsCreateOrUpdate: unexpected status 400 (400 Bad Request) with error: InaccessibleImage: The image 'mudkipcr.azurecr.io/mudkip:latest' in container group 'mudkipcg' is not accessible. Please check the image and registry credential.

  • 已确认ACR中存在目标镜像,本地登录ACR后可通过docker pull mudkipcr.azurecr.io/mudkip:latest拉取成功
  • 已通过Terraform配置azurerm_role_assignment为容器组的系统分配身份授予ACR的AcrPull权限,且Azure门户中已确认角色分配存在
  • 尝试过的其他方案:给资源组分配权限、使用用户分配身份,暂未尝试用户名密码方式

问题分析

核心问题有两个可能:

  1. 容器组创建时,系统分配身份的RBAC角色分配尚未生效(Azure权限同步存在延迟)
  2. 容器组配置中未明确指定使用托管身份来访问ACR,导致默认尝试无权限访问

解决方案

1. 修正Terraform配置,明确启用托管身份访问ACR

需要在容器组配置中添加image_registry_credential块指定使用托管身份,同时添加依赖确保角色分配先完成:

terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "4.13.0"
    }
  }

  required_version = "1.10.2"
}

provider "azurerm" {
  features {}
}

resource "azurerm_resource_group" "mudkip" {
  name     = "mudkip-rg"
  location = "Brazil South"
}

resource "azurerm_container_registry" "mudkip" {
  name                = "mudkipcr"
  resource_group_name = azurerm_resource_group.mudkip.name
  location            = azurerm_resource_group.mudkip.location
  sku                 = "Basic"
}

resource "azurerm_container_group" "mudkip" {
  name                = "mudkipcg"
  resource_group_name = azurerm_resource_group.mudkip.name
  location            = azurerm_resource_group.mudkip.location
  os_type             = "Linux"

  identity {
    type = "SystemAssigned"
  }

  # 关键配置:指定用托管身份访问ACR
  image_registry_credential {
    server = azurerm_container_registry.mudkip.login_server
    username = ""
    password = ""
    identity = azurerm_container_group.mudkip.identity[0].principal_id
  }

  container {
    name   = "mudkip"
    image  = "${azurerm_container_registry.mudkip.login_server}/mudkip:latest"
    cpu    = "0.5"
    memory = "1.5"

    ports {
      port = 80
    }
  }

  # 确保角色分配完成后再创建容器组
  depends_on = [azurerm_role_assignment.mudkip-role-cr]
}

resource "azurerm_role_assignment" "mudkip-role-cr" {
  scope                = azurerm_container_registry.mudkip.id
  role_definition_name = "AcrPull"
  principal_id         = azurerm_container_group.mudkip.identity[0].principal_id
}

2. 额外检查项

  • ACR网络策略:如果ACR设置为"允许选定网络",需将容器组所在虚拟网络加入ACR允许列表,或临时切换为"允许所有网络"排查网络问题
  • 角色作用域:确认角色分配的作用域是ACR资源本身,而非资源组,避免权限范围不足
  • 权限同步等待:如果修正配置后仍报错,等待5-10分钟让Azure RBAC权限完全同步后再重新部署

可选测试方案(不推荐用于生产)

若上述方案无效,可临时使用ACR管理员账户测试(注意安全性):

# 先启用ACR管理员账户
resource "azurerm_container_registry" "mudkip" {
  # ... 原有配置 ...
  admin_enabled = true
}

# 容器组配置中使用管理员凭证
resource "azurerm_container_group" "mudkip" {
  # ... 原有配置 ...
  image_registry_credential {
    server   = azurerm_container_registry.mudkip.login_server
    username = azurerm_container_registry.mudkip.admin_username
    password = azurerm_container_registry.mudkip.admin_password
  }
}

内容的提问来源于stack exchange,提问作者gsistelos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 13:53:17