You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Azure DevOps用ARM模板部署容器应用遇认证错误求助

问题

已部署Azure容器注册表(ACR),并在订阅级别为Azure服务连接配置了ACR拉取/推送权限。通过Azure DevOps流水线构建并推送镜像至ACR的步骤正常,且已准备好容器应用环境。随后使用ARM模板创建容器应用,任务配置及模板资源如下:

流水线任务配置

- task: AzureResourceManagerTemplateDeployment@3
  displayName: "Create Container App"
  inputs:
    deploymentScope: 'Resource Group'
    azureResourceManagerConnection: $(serviceConnection)
    subscriptionId: '$(SubscriptionID)'
    action: 'Create Or Update Resource Group'
    resourceGroupName: '$(ResourceGroupName)'
    location: 'West Europe'
    templateLocation: 'Linked artifact'
    csmFile: '$(Pipeline.Workspace)/drop/armtemplates/container_deployment.json'
    csmParametersFile: '$(Pipeline.Workspace)/drop/armtemplates/container_parameters.json'
    deploymentMode: 'Incremental'
  continueOnError: false

ARM模板资源部分

"resources": [
        {
            "type": "Microsoft.App/containerApps",
            "apiVersion": "2023-05-01",
            "name": "[parameters('containerAppName')]",
            "location": "[parameters('location')]",
            "properties": {
                "managedEnvironmentId": "[resourceId('Microsoft.App/managedEnvironments', parameters('containerAppEnvName'))]",
                "configuration": {
                    "ingress": {
                        "external": true,
                        "targetPort": "[parameters('targetPort')]",
                        "allowInsecure": false,
                        "traffic": [
                            {
                                "latestRevision": true,
                                "weight": 100
                            }
                        ]
                    }
                },
                "template": {
                    "revisionSuffix": "firstrevision",
                    "containers": [
                        {
                            "name": "[parameters('containerAppName')]",
                            "image": "[parameters('containerImage')]",
                            "resources": {
                                "cpu": "[json(parameters('cpuCore'))]",
                                "memory": "[format('{0}Gi', parameters('memorySize'))]"
                            }
                        }
                    ],
                    "scale": {
                        "minReplicas": "[parameters('minReplicas')]",
                        "maxReplicas": "[parameters('maxReplicas')]"
                    }
                }
            }
        }
    ]
}

部署时出现错误:
错误详情:以下字段无效或缺失。字段'template.containers.NameContainerApp.image'无效,详情为:'Invalid value: "containerregistryname.azurecr.io/todolistapp:latest": GET https:?scope=repository%3Atodolistapp%3Apull&service=containerregistryname.azurecr.io: UNAUTHORIZED: authentication required

请问在此场景下具体需要何种授权?

解决方案
  • 给容器应用托管环境的系统分配托管标识配置ACR拉取权限
    容器应用是通过其所属的托管环境(Managed Environment)拉取镜像,而非DevOps流水线的服务连接。需在ACR的访问控制(IAM)页面,为托管环境的系统分配托管标识添加AcrPull角色:

    1. 进入目标ACR的IAM页面,点击“添加角色分配”
    2. 角色选择AcrPull
    3. 成员类型选择“托管标识”,点击“选择成员”
    4. 找到对应容器应用环境的托管标识(名称与容器应用环境名一致),完成添加
  • 或在ARM模板中配置镜像拉取凭证(适用于不使用托管标识的场景)
    在ARM模板的configuration节点下添加registries配置,指定ACR的访问凭证:

    "configuration": {
        "ingress": {
            "external": true,
            "targetPort": "[parameters('targetPort')]",
            "allowInsecure": false,
            "traffic": [
                {
                    "latestRevision": true,
                    "weight": 100
                }
            ]
        },
        "registries": [
            {
                "server": "containerregistryname.azurecr.io",
                "username": "[parameters('acrUsername')]",
                "passwordSecretRef": "acr-password"
            }
        ]
    }
    

    同时需在容器应用的secrets中添加对应的密码密钥(acr-password),值为ACR的访问密码(可使用服务主体密钥或ACR管理员密码,生产环境不推荐使用管理员密码)

内容的提问来源于stack exchange,提问作者Sergio

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 14:37:13