You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Runbook中PowerShell获取AKS凭证失败问题求助

Azure Runbook中PowerShell获取AKS集群凭证失败问题排查与解决

问题描述

在Azure Runbook中执行PowerShell脚本获取AKS集群凭证时出错,脚本内容如下:

Install-Module -Name Kubernetes -AllowClobber -Scope CurrentUser

Import-Module -Name Az
Import-Module -Name Az.Aks
Import-Module -Name Kubernetes

Connect-AzAccount -Identity
Set-AzContext -SubscriptionId "8ab15eb5-cd64-4b44-a934-8e798f6c13e1"

$AzureContext = (Connect-AzAccount -Identity).context

Kubectl get nodes

$kubeconfig = Get-AzAksCredential -ResourceGroupName $resourceGroupName -Name $aksClusterName -Admin

执行时出现的错误截图:
错误截图

解决建议

  • 调整kubectl执行顺序:Kubectl get nodes必须放在获取AKS凭证之后执行,当前脚本在未生成kubeconfig时就调用该命令,必然失败,需将该行移至Get-AzAksCredential之后。
  • 补全未定义变量:脚本中*$resourceGroupName和$aksClusterName*未赋值,需先添加变量定义:
    $resourceGroupName = "你的AKS资源组名称"
    $aksClusterName = "你的AKS集群名称"
    
  • 优化Azure上下文配置:重复调用Connect-AzAccount -Identity冗余,改为一次获取并复用上下文:
    $AzureContext = Connect-AzAccount -Identity
    Set-AzContext -Context $AzureContext -SubscriptionId "8ab15eb5-cd64-4b44-a934-8e798f6c13e1"
    
  • 确认Runbook身份权限:托管身份需拥有AKS集群的Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action权限,可在AKS集群或资源组上为其分配Azure Kubernetes Service Cluster Admin Role角色。
  • 优化模块安装逻辑:避免重复安装模块,添加存在性判断:
    if (-not (Get-Module -ListAvailable -Name Kubernetes)) {
        Install-Module -Name Kubernetes -AllowClobber -Scope CurrentUser -Force
    }
    
  • 显式指定kubeconfig路径:通过-OutputFile参数指定kubeconfig输出路径,并设置环境变量让kubectl识别:
    $kubeconfigPath = Join-Path $env:TEMP "aks-kubeconfig"
    Get-AzAksCredential -ResourceGroupName $resourceGroupName -Name $aksClusterName -Admin -OutputFile $kubeconfigPath
    $env:KUBECONFIG = $kubeconfigPath
    # 之后执行kubectl命令
    Kubectl get nodes
    

内容的提问来源于stack exchange,提问作者Hardik Patel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 10:02:26