You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用az cli更新容器应用密钥时触发FailedIdentityOperation错误

Azure Container App Secret Set 报错:Client not permitted to perform resource delegation

问题详情

长期通过Azure CLI管理Azure容器应用密钥,此前运行正常,近期执行以下命令时持续失败:

az containerapp secret set -n my-containerapp -g MyResourceGroup \
--secrets MySecretName1=MySecretValue1 \
MySecretName2=keyvaultref:https://example.vault.azure.net/secrets/mysecret,identityref:/subscriptions/sub/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myidentity

错误信息:

(FailedIdentityOperation) 针对资源'/subscriptions/7cc5611c-e06d-4ae0-9e81-dab09605a818/resourceGroups/app-plan-client/providers/Microsoft.App/containerApps/dev-citeo-mailing'的标识操作失败,错误为'Failed to perform resource identity operation. Status: 'BadRequest'. Response: '{"error":{"code":"BadRequest","message":"Client not permitted to perform resource delegation. Requests containing delegatedResources must be made with a valid Microsoft 1st-party app credential."}}'.

环境与排查情况

  • 涉及环境:本地(Linux/WSL/Windows PowerShell)、Azure DevOps构建代理
  • Azure CLI版本:
    {
      "azure-cli": "2.57.0",
      "azure-cli-core": "2.57.0",
      "azure-cli-telemetry": "1.1.0",
      "extensions": {
        "containerapp": "0.3.47"
      }
    }
    
  • 已尝试:更新Azure CLI、切换登录方式(个人凭据/服务主体/服务连接),均无法解决问题

缓解措施

  1. 通过Azure Portal手动配置:直接在容器应用的「机密」页面添加包含Key Vault引用和身份关联的密钥,暂时绕过CLI的问题
  2. 降级containerapp扩展版本:回退到之前验证可用的扩展版本,例如:
    az extension remove --name containerapp
    az extension add --name containerapp --version 0.3.45
    
  3. 使用Bicep/ARM模板部署:通过基础设施即代码的方式定义并更新容器应用密钥,示例Bicep片段:
    resource containerApp 'Microsoft.App/containerApps@2023-05-01' = {
      name: 'my-containerapp'
      resourceGroup: 'MyResourceGroup'
      properties: {
        configuration: {
          secrets: [
            {
              name: 'MySecretName1'
              value: 'MySecretValue1'
            }
            {
              name: 'MySecretName2'
              keyVaultUrl: 'https://example.vault.azure.net/secrets/mysecret'
              identity: '/subscriptions/sub/resourceGroups/rg/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myidentity'
            }
          ]
        }
      }
    }
    

后续处理

该问题属于Azure CLI containerapp扩展的已知兼容性问题,建议关注Azure CLI扩展的更新日志,待官方发布修复版本后升级扩展即可恢复原有命令的使用。

内容的提问来源于stack exchange,提问作者Mahmoud GHORBEL

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 01:42:15