使用Azurite跨容器复制Blob时遭遇请求认证失败问题
问题场景
使用Azure Blob Storage SDK 12.10.0,通过默认Azurite连接字符串执行Blob跨容器复制操作时,触发以下错误:
AuthorizationFailure, (Exception: HttpResponseError: Server failed to authenticate the request. Make sure the value of the Authorization header is formed correctly including the signature.)
所用默认连接字符串:
DefaultEndpointsProtocol=http;AccountName=devstoreaccount1;AccountKey=Eby8vdM02xNOcqFe4xJtfl0s3bY5lZ0+ZGF4uEXC1Ls+zmLsd3H1qDGJiOggYo==;BlobEndpoint=http://127.0.0.1:10000/devstoreaccount1;
已确认URL格式正确,且锁定SDK版本为12.10.0,错误仍未解决。
排查与解决步骤
1. 匹配Azurite与SDK版本兼容性
Azure Blob Storage SDK 12.10.0要求Azurite版本不低于3.14.0,旧版本Azurite无法正确处理SDK 12.x生成的签名算法。升级Azurite到最新稳定版本后重试。
2. 修正连接字符串格式
部分SDK版本对连接字符串末尾的多余分号敏感,建议调整为无尾部分号的格式:
DefaultEndpointsProtocol=http;AccountName=devstoreaccount1;AccountKey=Eby8vdM02xNOcqFe4xJtfl0s3bY5lZ0+ZGF4uEXC1Ls+zmLsd3H1qDGJiOggYo==;BlobEndpoint=http://127.0.0.1:10000/devstoreaccount1
3. 确保源Blob URL使用正确格式
跨容器复制时,start_copy_from_url方法的源Blob URL必须是Azurite本地可访问的地址,需使用127.0.0.1而非localhost,示例:
http://127.0.0.1:10000/devstoreaccount1/source-container/source-blob-name
主机名不匹配会导致签名计算时的校验失败。
4. 显式指定共享密钥认证模式
部分场景下SDK会默认尝试Azure AD认证,需强制指定共享密钥认证:
from azure.storage.blob import BlobServiceClient conn_str = "你的连接字符串" blob_service_client = BlobServiceClient.from_connection_string(conn_str) # 确认客户端使用共享密钥认证 if not hasattr(blob_service_client._credential, 'account_key'): raise ValueError("未启用共享密钥认证模式")
5. 重置Azurite本地缓存
Azurite的本地存储缓存可能存在异常,操作步骤:
- 停止Azurite服务
- 删除默认数据目录:Windows为
%USERPROFILE%\.azurite,Linux/macOS为~/.azurite - 重新启动Azurite服务后重试复制操作
6. 同步系统时间
签名计算依赖准确的系统时间,若本地时间与Azurite服务时间偏差超过15分钟,会触发认证失败。同步本地系统时间至网络标准时间后重试。
内容的提问来源于stack exchange,提问作者Siri Mudunuri

