You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ContainerClient类时遭遇顽固ClientAuthenticationError求助

Azure Blob存储ClientAuthenticationError排查与解决

在Azure流水线运行集成测试时,持续触发ClientAuthenticationError,以下是最小可复现代码:

import os
from azure.storage.blob import BlobServiceClient
from azure.core.credentials import AzureSasCredential

SAS_TOKEN = os.environ["SAS_TOKEN"]

credential = AzureSasCredential(SAS_TOKEN)
account_name = "ACCOUNT_NAME"
account_url = f"https://{account_name}.blob.core.windows.net"
container_name = "CONTAINER_NAME"

blob_service_client = BlobServiceClient(account_url, credential=credential)
container = blob_service_client.get_container_client(container_name)
parquet_names = container.list_blob_names(name_starts_with="PATTERN")
list_of_parquet = list(parquet_names)

对应的报错回溯:

File "/home/vsts/work/1/s/./tests/run_tests.py", line 24, in access_datalake_locally
  list_of_parquet = list(parquet_names)
File "/opt/hostedtoolcache/Python/3.10.15/x64/lib/python3.10/site-packages/azure/core/paging.py", line 123, in __next__
  return next(self._page_iterator)
File "/opt/hostedtoolcache/Python/3.10.15/x64/lib/python3.10/site-packages/azure/core/paging.py", line 75, in __next__
  self._response = self._get_next(self.continuation_token)
File "/opt/hostedtoolcache/Python/3.10.15/x64/lib/python3.10/site-packages/azure/storage/blob/_list_blobs_helper.py", line 175, in _get_next_cb
  process_storage_error(error)
File "/opt/hostedtoolcache/Python/3.10.15/x64/lib/python3.10/site-packages/azure/storage/blob/_shared/response_handlers.py", line 186, in process_storage_error
  exec("raise error from None")   # pylint: disable=exec-used # nosec
File "<string>", line 1, in <module>
azure.core.exceptions.ClientAuthenticationError: Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.

我推测可能的原因有三点:

  • 将parquet_names对象转换为list类型时出现问题;
  • credential对象的构造方式有误(已尝试直接传入SAS_TOKEN,报错相同);
  • 环境变量SAS_TOKEN的值不正确。

排查与解决建议

1. 优先验证SAS_TOKEN有效性

  • 检查SAS_TOKEN格式:必须以?开头(单独传入时),避免遗漏前缀;若从存储账户/容器复制令牌,确保完整复制所有参数
  • 确认权限与范围:SAS令牌需包含**读取(r)**权限,作用范围覆盖目标容器,且有效期未过期
  • 本地验证:在本地手动设置正确的SAS_TOKEN运行代码,排除流水线环境变量注入问题

2. 调整Client初始化方式

  • 尝试将SAS_TOKEN直接附加到账户URL初始化客户端,跳过AzureSasCredential:
    account_url_with_sas = f"https://{account_name}.blob.core.windows.net?{SAS_TOKEN.lstrip('?')}"
    blob_service_client = BlobServiceClient(account_url_with_sas)
    
  • 核对ACCOUNT_NAME和CONTAINER_NAME是否与目标资源完全一致,避免拼写错误

3. 排除分页迭代影响

  • 先调用容器的简单验证方法,比如检查已知Blob是否存在:
    exists = container.get_blob_client("existing-blob-name.parquet").exists()
    print(exists)
    
    若此操作仍报错,说明问题核心在认证环节,而非list转换

4. 流水线环境额外检查

  • 确认流水线中SAS_TOKEN的注入逻辑:是否存在转义、截断或额外空格(比如变量设置时误加引号)
  • 检查存储账户防火墙配置:是否允许流水线代理的IP地址或Azure服务访问

内容的提问来源于stack exchange,提问作者Tom Hosker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 17:44:55