You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep创建带客户托管密钥的Azure容器注册表失败求助

使用Bicep创建带客户托管密钥的Azure容器注册表(ACR)失败:Invalid KeyId错误

我尝试用Bicep创建启用**客户托管加密密钥(Customer Managed Encryption Keys)**的Azure容器注册表(ACR),但ACR创建失败。Key Vault、用户分配标识、角色分配及加密密钥都已成功创建,唯独ACR报错:

Invalid KeyId '/subscriptions//resourceGroups//providers/Microsoft.KeyVault/vaults/mykeyvaultname/keys/key-mycontainerregistry' specified in encryption property for registry 'mycontainerregistry'
(Code: IdentitiesClientError)

已核对传入ACR模块的标识参数(资源ID、客户端ID)与Azure中实际值完全匹配。

创建Key Vault的Bicep代码

param azureRegion string
param tenantId string
var keyVaultName = 'mykeyvaultname'

@description('Set up a key vault')
resource keyVault 'Microsoft.KeyVault/vaults@2023-07-01' = {
  name: keyVaultName
  location: azureRegion
  tags:{
    client: 'qPlatform'
    dataclassification: 'Confidential'
    businesscriticality: 'Mission-critical'
    environment: environment
  }
  properties: {
    tenantId: tenantId
    sku: {
      family: 'A'
      name: 'premium'
    }
    enabledForDiskEncryption: true
    enabledForTemplateDeployment: true
    enabledForDeployment: true
    enablePurgeProtection: true
    enableSoftDelete: true
    enableRbacAuthorization: true
    publicNetworkAccess: 'Enabled'
    softDeleteRetentionInDays: 90
  }
}

output keyVaultName string = keyVault.name
output keyVaultId string = keyVault.id

为用户分配标识配置Key Vault权限的代码

param containerRegistryManagedIdentityName string
param keyVaultName string

@description('Get the existing KeyVault reference')
resource keyVault 'Microsoft.KeyVault/vaults@2019-09-01' existing = {
  name: keyVaultName
}

@description('This is the built-in Key Vault Crypto User User role.')
resource keyVaultCryptoUserRoleRoleDefinition 'Microsoft.Authorization/roleDefinitions@2018-01-01-preview' existing = {
  scope: subscription()
  name: '12338af0-0e69-4776-bea7-57ae8d297424'
}

@description('Get the existing managed identity for the container registry')
resource containerRegistryManagedIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2018-11-30' existing = {
  name: containerRegistryManagedIdentityName
  scope: resourceGroup()
}

@description('Grant the container registry identity with key vault crypto user role permissions over the key vault.')
resource storageKeyVaultCryptoUserRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  scope: keyVault
  name: guid(keyVault.id, containerRegistryManagedIdentity.id, keyVaultCryptoUserRoleRoleDefinition.id)
  properties: {
    roleDefinitionId: keyVaultCryptoUserRoleRoleDefinition.id
    principalId: containerRegistryManagedIdentity.properties.principalId
  }
}

创建加密密钥及ACR的代码

param environment string
param azureRegion string
param sku string = 'Premium'
param keyVaultName string
param identityClientId string
param identityId string

var name = 'mycontainerregistry'

resource keyVault 'Microsoft.KeyVault/vaults@2021-10-01' existing = {
  name: keyVaultName
}

var keyName = 'key-${name}'

resource key 'Microsoft.KeyVault/vaults/keys@2019-09-01' = {
  name: keyName
  parent: keyVault
  properties: {
    attributes: {
      enabled: true
    }
    keySize: 2048
    kty: 'RSA'
  }
}

resource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {
  name: name
  location: azureRegion
  tags:{
    client: 'qPlatform'
    dataclassification: 'Confidential'
    businesscriticality: 'High'
    environment: environment
  }
  sku: {
    name: sku
  }
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${identityId}':{}
    }
  }
  properties: {
    adminUserEnabled: true
    encryption: {
      keyVaultProperties: {
        identity: identityClientId
        keyIdentifier: key.id
      }
      status: 'enabled'
    }
  }
}

问题原因及解决办法

1. 统一Key Vault API版本

不同模块中使用了Key Vault的多个API版本(2023-07-01、2019-09-01、2021-10-01),版本差异可能导致密钥ID解析异常。建议全模块统一使用最新兼容版本(如2023-07-01)。

2. 修正ACR加密配置的身份参数

ACR加密配置中,encryption.keyVaultProperties.identity字段需要传入用户分配标识的资源ID,而非客户端ID。修改ACR模块的加密部分:

encryption: {
  keyVaultProperties: {
    identity: identityId // 替换为标识资源ID,原clientId参数可移除
    keyIdentifier: key.id
  }
  status: 'enabled'
}

3. 补充RBAC权限

Key Vault启用了enableRbacAuthorization: true,此时访问策略失效,需确保用户分配标识拥有足够权限:

  • 除Key Vault Crypto User角色外,添加Key Vault Reader角色,确保ACR能读取密钥元数据
  • 确认角色分配的作用域为Key Vault资源本身,而非父资源组

4. 添加资源依赖

密钥创建后可能存在短暂的Azure内部复制延迟,在ACR资源中添加对密钥的显式依赖:

resource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {
  name: name
  location: azureRegion
  // 其他配置保持不变
  dependsOn: [key] // 确保密钥完全就绪后再部署ACR
}

5. 检查密钥ID完整性

报错中的密钥ID缺少订阅ID和资源组名称,需确认Key Vault现有资源引用正确,key资源与父Key Vault的关联无误,避免变量引用错误导致ID不完整。

内容的提问来源于stack exchange,提问作者Kieran-GenIq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 01:52:17