You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取与az ad sp create-for-rbac输出一致的Service Principal JSON认证密钥?

解决方法

方法1:直接用原命令重置并生成兼容格式

最简便的方式是复用你最初创建Service Principal的命令,添加--reset参数,它会直接重置目标SP的凭证,同时输出和--json-auth完全一致的格式:

az ad sp create-for-rbac --name "my-ci-sp" --role contributor \
  --scopes /subscriptions/<subscription-id>/resourceGroups/<group-name> \
  --json-auth --reset

执行后得到的JSON内容可以直接替换你CI中原来的凭证,字段和结构完全匹配。

方法2:手动转换az ad app credential reset的输出格式

如果你必须使用az ad app credential reset命令,可以结合jq工具将输出转换为--json-auth的结构(需要手动补充订阅ID和固定的Azure服务端点):

az ad sp credential reset --id <my-sp-id> --query '{clientId: appId, clientSecret: password, tenantId: tenant, subscriptionId: "<your-subscription-id>", activeDirectoryEndpointUrl: "https://login.microsoftonline.com", resourceManagerEndpointUrl: "https://management.azure.com/", activeDirectoryGraphResourceId: "https://graph.windows.net/", sqlManagementEndpointUrl: "https://management.core.windows.net:8443/", galleryEndpointUrl: "https://gallery.azure.com/", managementEndpointUrl: "https://management.core.windows.net/"}' --output json

说明:

  • <your-subscription-id>替换为你的Azure订阅ID
  • 所有端点URL为公云环境的默认值,若使用主权云(如Azure中国),需要替换为对应环境的端点

内容的提问来源于stack exchange,提问作者Martin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 18:39:51