You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署ACI时无法访问ACR镜像:InaccessibleImage错误

使用Terraform部署Azure容器实例(ACI)时无法访问Azure容器注册表(ACR)

报错信息

│ Error: creating Container Group (Subscription: "redacted"
│ Resource Group Name: "myresourcegoup"
│ Container Group Name: "mycontainergroup): performing ContainerGroupsCreateOrUpdate: containerinstance.ContainerInstanceClient#ContainerGroupsCreateOrUpdate: Failure sending request: StatusCode=0 -- Original Error: Code="InaccessibleImage" Message="The image 'mycompany.azurecr.io/myimage:latest' in container group 'mycontainergroup' is not accessible. Please check the image and registry credential."

可复现问题的最小Terraform代码

resource "azurerm_container_group" "generic" {
  name                = local.aci_name
  location            = var.location
  resource_group_name = "myresourcegroup"
  os_type             = "Linux"
  ip_address_type     = "None"  # Specifies that no IP is assigned

  identity {
    type         = "UserAssigned"
    # real deal has the identity coming from previous steps but fails even like this
    identity_ids = ["/subscriptions/redacted/resourceGroups/myresourcegrouo/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myidentity"]

  }
  container {
    name   = local.aci_name
    image  = "mycompany.azurecr.io/myimage:latest"
    cpu    = "0.5"
    memory = "1.5"
  }
  # No ports block needed since no network access is required
}

已尝试的检查项

  • 容器镜像可正常访问,能通过docker pull命令顺利拉取
  • 分配给ACI的用户托管标识已拥有ACR的AcrPull权限
  • 即使为该标识授予Owner等更高权限,问题仍存在
  • 即使使用ACR中不存在的镜像或无效ACR仓库,仍会出现相同的InaccessibleImage错误
  • 使用无效标识会出现不同错误,说明标识未被忽略
  • 已咨询多个顶尖大模型及资深运维人员,仍未解决问题,希望通过Terraform完成部署而非手动操作

内容的提问来源于stack exchange,提问作者Seppo420

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 16:22:48