You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure存储账户AuthorizationFailure错误排查求助

排查Azure Web App通过私有端点访问Blob存储的AuthorizationFailure错误

问题背景

我正在构建一个Web应用,用于从Blob存储账户读取文件并计算特定指标。该应用部署为Azure Web App资源,仅允许公司VPN用户访问。Web应用和存储账户都配置了私有端点,确保公网无法访问。

应用通过Azure Pipelines代码部署,已创建服务连接。Web应用资源在存储账户中被分配了Storage Blob Data Contributor和Storage Queue Data Contributor角色。

读取数据的Python脚本如下:

def fetch_access_data(connection_string, admin_container_name, access_blob_name):
    blob_service_client = BlobServiceClient.from_connection_string(connection_string)
    blob_client = blob_service_client.get_blob_client(container=admin_container_name, blob=access_blob_name)
    stream = io.BytesIO(blob_client.download_blob().readall())
    df_access = pd.read_excel(stream)
    return df_access

错误信息

HttpResponseError: This request is not authorized to perform this operation. RequestId:RequestId Failure Content:

return (<Code>AuthorizationFailure</Code>)
This request is not authorized to perform this operation. RequestId:RequestId Time:2024-11-12T07:44:22.7022630Z

已知情况

使用相同连接字符串在Azure Storage Explorer中可正常访问存储账户,包括下载、上传文件。

已尝试操作

  • 修改连接字符串,添加端点IP;
  • 将存储账户设置为仅允许特定IP地址和虚拟网络访问。

排查方向及解决方法

1. 验证连接字符串的正确性

  • 确认连接字符串使用私有端点的Blob服务URL,格式应为BlobEndpoint=https://<storage-account-name>.privatelink.blob.core.windows.net/,而非公网默认的blob.core.windows.net。
  • 检查连接字符串中的账户密钥/SAS令牌有效性:如果用账户密钥,确认未被轮换或禁用;如果用SAS,确保权限包含Read,资源类型覆盖Container和Blob,且有效期未过期。

2. 检查私有端点网络配置

  • 确认Web App和存储账户的私有端点处于同一虚拟网络/对等互联网络,且子网NSG允许Web App到存储私有端点的443端口出站流量。
  • 验证存储账户的私有DNS区域已关联到Web App所在虚拟网络,确保域名解析正常。DNS解析失败会导致请求 fallback 到公网,被存储账户防火墙拦截触发授权错误。

3. 确认RBAC角色的实际生效逻辑

  • 如果代码使用连接字符串的账户密钥,RBAC角色不会生效——RBAC仅对托管标识或SAS身份验证生效。需确认是否误用了RBAC角色作为连接字符串的权限依据。
  • 若计划用托管标识,需确保Web App已启用系统/用户分配托管标识,且该标识被分配了Storage Blob Data Contributor角色,角色范围覆盖目标存储账户或容器。

4. 调整存储账户防火墙规则

  • 使用私有端点时,存储账户的防火墙规则应设置为允许通过私有端点访问,而非仅限制特定IP/VNet(除非同时需要双重限制)。
  • 若未使用托管标识,检查是否开启了"允许受信任的Microsoft服务访问"选项,确保Web App的请求来源被允许。

5. 切换到托管标识验证

尝试替换连接字符串为托管标识身份验证,排查是否为连接字符串权限问题。示例代码:

from azure.identity import DefaultAzureCredential
from azure.storage.blob import BlobServiceClient
import io
import pandas as pd

def fetch_access_data(storage_account_name, admin_container_name, access_blob_name):
    credential = DefaultAzureCredential()
    blob_service_client = BlobServiceClient(
        account_url=f"https://{storage_account_name}.privatelink.blob.core.windows.net/",
        credential=credential
    )
    blob_client = blob_service_client.get_blob_client(container=admin_container_name, blob=access_blob_name)
    stream = io.BytesIO(blob_client.download_blob().readall())
    df_access = pd.read_excel(stream)
    return df_access

内容的提问来源于stack exchange,提问作者G Foutzopoulos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 09:48:11