在AKS中通过工作负载身份与Event Hub触发器运行Azure Function遇阻
解决方案
1. 修正Event Hub连接的环境变量配置
使用工作负载身份时,无需手动指定tokenFilePath,正确的环境变量配置应为:
EventHubConnection__clientId: <你的应用程序客户端ID> EventHubConnection__credential: workloadidentity EventHubConnection__fullyQualifiedNamespace: <你的Event Hub命名空间>.servicebus.windows.net EventHubConnection__tenantId: <你的租户ID>
手动指定tokenFilePath会绕过Workload Identity的自动注入流程,导致使用K8S原生ServiceAccount token(默认生命周期1年),触发Azure AD的70023错误。
2. 确保Workload Identity注入生效
检查Pod的Workload Identity注入状态:
- 确认部署的Pod已正确设置标签:
azure.workload.identity/use: "true" - 确认K8S ServiceAccount已与Azure AD应用程序完成绑定(通过
az workload-identity federation create命令完成) - 查看Pod的卷挂载配置,应包含Workload Identity的token卷:
volumes: - name: azure-identity-token projected: sources: - serviceAccountToken: audience: api://AzureADTokenExchange expirationSeconds: 3600 path: azure-identity-token
若缺少该卷挂载,说明Workload Identity注入未生效,需重新检查绑定流程。
3. 解决AADSTS70023错误
该错误因K8S ServiceAccount默认token生命周期(1年)超出Azure AD允许的最大1小时1分钟限制导致,需为目标ServiceAccount设置短生命周期token:
- 创建或更新ServiceAccount时添加注解:
apiVersion: v1 kind: ServiceAccount metadata: annotations: azure.workload.identity/service-account-token-expiration: "3600" name: <你的ServiceAccount名称> - 或用kubectl命令更新现有ServiceAccount:
kubectl annotate serviceaccount <你的ServiceAccount名称> azure.workload.identity/service-account-token-expiration=3600
更新后重新部署Pod,新token会自动注入/var/run/secrets/azure/tokens/azure-identity-token路径,生命周期为1小时,符合Azure AD要求。
4. 验证权限配置
确认与ServiceAccount绑定的Azure AD应用程序已被授予Event Hub的Azure Event Hubs Data Receiver角色(或对应权限),避免出现权限不足的后续错误。
内容的提问来源于stack exchange,提问作者Sandy
相关产品推荐
相关产品推荐

