You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AKS中通过工作负载身份与Event Hub触发器运行Azure Function遇阻

解决方案

1. 修正Event Hub连接的环境变量配置

使用工作负载身份时,无需手动指定tokenFilePath,正确的环境变量配置应为:

EventHubConnection__clientId: <你的应用程序客户端ID>
EventHubConnection__credential: workloadidentity
EventHubConnection__fullyQualifiedNamespace: <你的Event Hub命名空间>.servicebus.windows.net
EventHubConnection__tenantId: <你的租户ID>

手动指定tokenFilePath会绕过Workload Identity的自动注入流程,导致使用K8S原生ServiceAccount token(默认生命周期1年),触发Azure AD的70023错误。

2. 确保Workload Identity注入生效

检查Pod的Workload Identity注入状态:

  • 确认部署的Pod已正确设置标签:azure.workload.identity/use: "true"
  • 确认K8S ServiceAccount已与Azure AD应用程序完成绑定(通过az workload-identity federation create命令完成)
  • 查看Pod的卷挂载配置,应包含Workload Identity的token卷:
    volumes:
    - name: azure-identity-token
      projected:
        sources:
        - serviceAccountToken:
            audience: api://AzureADTokenExchange
            expirationSeconds: 3600
            path: azure-identity-token
    

若缺少该卷挂载,说明Workload Identity注入未生效,需重新检查绑定流程。

3. 解决AADSTS70023错误

该错误因K8S ServiceAccount默认token生命周期(1年)超出Azure AD允许的最大1小时1分钟限制导致,需为目标ServiceAccount设置短生命周期token:

  • 创建或更新ServiceAccount时添加注解:
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      annotations:
        azure.workload.identity/service-account-token-expiration: "3600"
      name: <你的ServiceAccount名称>
    
  • 或用kubectl命令更新现有ServiceAccount:
    kubectl annotate serviceaccount <你的ServiceAccount名称> azure.workload.identity/service-account-token-expiration=3600
    

更新后重新部署Pod,新token会自动注入/var/run/secrets/azure/tokens/azure-identity-token路径,生命周期为1小时,符合Azure AD要求。

4. 验证权限配置

确认与ServiceAccount绑定的Azure AD应用程序已被授予Event Hub的Azure Event Hubs Data Receiver角色(或对应权限),避免出现权限不足的后续错误。


内容的提问来源于stack exchange,提问作者Sandy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 23:54:57