如何获取与az ad sp create-for-rbac输出一致的Service Principal JSON认证密钥?
解决方法
方法1:直接用原命令重置并生成兼容格式
最简便的方式是复用你最初创建Service Principal的命令,添加--reset参数,它会直接重置目标SP的凭证,同时输出和--json-auth完全一致的格式:
az ad sp create-for-rbac --name "my-ci-sp" --role contributor \ --scopes /subscriptions/<subscription-id>/resourceGroups/<group-name> \ --json-auth --reset
执行后得到的JSON内容可以直接替换你CI中原来的凭证,字段和结构完全匹配。
方法2:手动转换az ad app credential reset的输出格式
如果你必须使用az ad app credential reset命令,可以结合jq工具将输出转换为--json-auth的结构(需要手动补充订阅ID和固定的Azure服务端点):
az ad sp credential reset --id <my-sp-id> --query '{clientId: appId, clientSecret: password, tenantId: tenant, subscriptionId: "<your-subscription-id>", activeDirectoryEndpointUrl: "https://login.microsoftonline.com", resourceManagerEndpointUrl: "https://management.azure.com/", activeDirectoryGraphResourceId: "https://graph.windows.net/", sqlManagementEndpointUrl: "https://management.core.windows.net:8443/", galleryEndpointUrl: "https://gallery.azure.com/", managementEndpointUrl: "https://management.core.windows.net/"}' --output json
说明:
<your-subscription-id>替换为你的Azure订阅ID- 所有端点URL为公云环境的默认值,若使用主权云(如Azure中国),需要替换为对应环境的端点
内容的提问来源于stack exchange,提问作者Martin
相关产品推荐
相关产品推荐

