使用Terraform部署ACI时无法访问ACR镜像:InaccessibleImage错误
使用Terraform部署Azure容器实例(ACI)时无法访问Azure容器注册表(ACR)
报错信息
│ Error: creating Container Group (Subscription: "redacted" │ Resource Group Name: "myresourcegoup" │ Container Group Name: "mycontainergroup): performing ContainerGroupsCreateOrUpdate: containerinstance.ContainerInstanceClient#ContainerGroupsCreateOrUpdate: Failure sending request: StatusCode=0 -- Original Error: Code="InaccessibleImage" Message="The image 'mycompany.azurecr.io/myimage:latest' in container group 'mycontainergroup' is not accessible. Please check the image and registry credential."
可复现问题的最小Terraform代码
resource "azurerm_container_group" "generic" { name = local.aci_name location = var.location resource_group_name = "myresourcegroup" os_type = "Linux" ip_address_type = "None" # Specifies that no IP is assigned identity { type = "UserAssigned" # real deal has the identity coming from previous steps but fails even like this identity_ids = ["/subscriptions/redacted/resourceGroups/myresourcegrouo/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myidentity"] } container { name = local.aci_name image = "mycompany.azurecr.io/myimage:latest" cpu = "0.5" memory = "1.5" } # No ports block needed since no network access is required }
已尝试的检查项
- 容器镜像可正常访问,能通过
docker pull命令顺利拉取 - 分配给ACI的用户托管标识已拥有ACR的
AcrPull权限 - 即使为该标识授予
Owner等更高权限,问题仍存在 - 即使使用ACR中不存在的镜像或无效ACR仓库,仍会出现相同的
InaccessibleImage错误 - 使用无效标识会出现不同错误,说明标识未被忽略
- 已咨询多个顶尖大模型及资深运维人员,仍未解决问题,希望通过Terraform完成部署而非手动操作
内容的提问来源于stack exchange,提问作者Seppo420
相关产品推荐
相关产品推荐

