You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否用Azure Bicep创建容器注册表令牌凭据?部署报错求助

问题描述

尝试通过Azure Bicep创建容器注册表并同步创建访问令牌,使用的Bicep代码片段如下:

param tokenExpiry string = dateTimeAdd(utcNow(), 'P30D')

resource MyToken 'Microsoft.ContainerRegistry/registries/tokens@2022-12-01' = {
  parent: containerRegistry
  name: 'MyToken'
  properties: {
    status: 'enabled'
    scopeMapId: resourceId('Microsoft.ContainerRegistry/registries/scopeMaps', containerRegistry.name, '_repositories_pull')
    credentials: {
      passwords: [
        {
           name: 'password1'
           expiry: tokenExpiry
          }
      ]
    }
  }
}

部署时出现报错:

[{"code":"PasswordCannotBeAdded","message":"New passwords can be added only through 'generateCredentials'."}]

尝试给password添加value属性后,仍然失败,报错:

[{"code":"PasswordPropertiesImmutable","message":"Password properties cannot be changed. To retain the password, please provide an empty value for a password. To add a new password please use 'generateCredentials'."}]

目前未找到在Bicep中调用generateCredentials的方法,仅找到使用New-AzContainerRegistryToken PowerShell cmdlet的相关信息。希望通过Bicep确保注册表中始终存在特定的访问令牌集,刷新时只需重新运行Bicep即可,想确认是否可以通过这种方式实现,还是必须先创建无凭据的令牌,再通过REST API单独创建密码?

解决方案

你并没有误用Bicep,问题源于Azure容器注册表的令牌凭据管理逻辑限制:

  1. Bicep仅能管理令牌基础属性,无法直接生成密码
    Azure容器注册表的generateCredentials是操作类API,而非资源的持久化属性。Bicep作为声明式IaC工具,负责定义资源的静态属性,无法直接调用这类需要动态生成凭据的操作。

  2. 实现目标的正确步骤

    • 第一步:用Bicep创建无凭据的令牌,移除credentials块,只定义核心属性:
      resource MyToken 'Microsoft.ContainerRegistry/registries/tokens@2022-12-01' = {
        parent: containerRegistry
        name: 'MyToken'
        properties: {
          status: 'enabled'
          scopeMapId: resourceId('Microsoft.ContainerRegistry/registries/scopeMaps', containerRegistry.name, '_repositories_pull')
        }
      }
      
    • 第二步:Bicep部署完成后,通过PowerShell/Azure CLI/REST API调用generateCredentials生成密码:
      • PowerShell示例:
        New-AzContainerRegistryToken -RegistryName <注册表名称> -ResourceGroupName <资源组名称> -Name MyToken -GenerateCredential
        
      • Azure CLI示例:
        az acr token credential generate --name MyToken --registry <注册表名称> --expiry 30d
        
  3. 优化实现"刷新时重新运行即可"的需求
    若希望单次执行完成部署+凭据生成,可将Bicep部署和凭据生成脚本整合到自动化流程(如Azure DevOps Pipeline、GitHub Actions):

    • 先执行Bicep部署命令创建令牌
    • 再运行凭据生成脚本,同时将生成的密码存入Azure密钥保管库,方便后续取用

内容的提问来源于stack exchange,提问作者Michael Stum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 08:13:24