You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

修复部署带私有链接Azure Web Apps时GitHub Actions的Azure CLI资源找不到错误

问题背景

为配置了私有链接的Azure Web App更新GitHub Actions部署脚本时遇到错误,无法通过原有方式部署,按文档修改后仍触发404资源不存在错误。

GitHub Actions脚本片段
deploy:
    runs-on: ubuntu-latest
    needs: build
    environment:
      name: 'Production'
      url: ${{ steps.deploy-to-webapp.outputs.webapp-url }}
    
    steps:
      - name: Azure Login
        uses: azure/login@v1
        with:
          creds: ${{ secrets.AZURE_CREDENTIALS }}

      - name: Download artifact from build job
        uses: actions/download-artifact@v2
        with:
          name: java-app

      - name: Zip the app contents
        uses: papeloto/action-zip@v1
        with:
          files: app.jar
          dest: app.zip

      - name: Set SAS token expiration
        run: echo "expiry=`date -u -d "$EXPIRY_TIME" '+%Y-%m-%dT%H:%MZ'`" >> $GITHUB_ENV

      - name: Azure CLI script
        uses: azure/CLI@v1
        with:
          azcliversion: 2.19.1
          inlineScript: | 
            az extension add --name webapp
            echo "Added Extension"
            az storage container create -n $CONTAINER --account-name $ACCOUNT --resource-group $BASE_GROUP
            echo "Created Container"
            az storage blob upload      -f app.zip --resource-group $BASE_GROUP   --account-name $ACCOUNT -c $CONTAINER -n $ACCOUNT 
            echo "Blob Upload Step Completed"
            ZIP_URL=$(az storage blob generate-sas --full-uri --permissions r --expiry ${{ env.expiry }} --resource-group $BASE_GROUP --account-name $ACCOUNT -c $CONTAINER -n $ACCOUNT | xargs)
            echo "ZIP_URL Created"
            az webapp deploy --name $WEBAPP --resource-group $TEST_GROUP --type zip --src-url  $ZIP_URL --async false
            echo "Deployment Completed"
            az storage container delete -n $CONTAINER --account-name $ACCOUNT
错误输出
Run azure/CLI@v1
Starting script execution via docker image mcr.microsoft.com/azure-cli:2.19.1
WARNING: The installed extension 'webapp' is in preview.
Added Extension

WARNING: There are no credentials provided in your command and environment, we will query for the account key inside your storage account. 
Please provide --connection-string, --account-key or --sas-token as credentials, or use `--auth-mode login` if you have required RBAC roles in your command. For more information about RBAC roles in storage, visit https://docs.microsoft.com/en-us/azure/storage/common/storage-auth-aad-rbac-cli. 
Setting the corresponding environment variables can avoid inputting credentials in your command. Please use --help to get more information.
ERROR: Client-Request-ID=a4d42790-c7ab-11ee-b92c-0242ac110002 Retry policy did not allow for a retry: Server-Timestamp=Sat, 10 Feb 2024 00:30:50 GMT, Server-Request-ID=b66b9e8f-901e-0075-6bb8-5bd530000000, HTTP status code=404, Exception=The specified resource does not exist. ErrorCode: ResourceNotFound<?xml version="1.0" encoding="utf-8"?><Error><Code>ResourceNotFound</Code><Message>The specified resource does not exist.RequestId:b66b9e8f-901e-0075-6bb8-5bd530000000Time:2024-02-10T00:30:51.5358190Z</Message></Error>.
ERROR: The specified resource does not exist. ErrorCode: ResourceNotFound
<?xml version="1.0" encoding="utf-8"?><Error><Code>ResourceNotFound</Code><Message>The specified resource does not exist.
RequestId:b66b9e8f-901e-0075-6bb8-5bd530000000
Time:2024-02-10T00:30:51.5358190Z</Message></Error>
Error: Error: az cli script failed.
cleaning up container...
MICROSOFT_AZURE_CLI_(number)_CONTAINER

Error: az cli script failed.
核心疑问
  1. 凭证缺失提示是否与ResourceNotFound错误相关?
  2. 若是,如何确保CLI步骤认证正常并消除提示?
  3. 若否,为何无法找到确认存在的存储账户?

备注:存储账户与Web App分属不同资源组,登录用的服务主体对两个资源组均拥有Contributor权限,已确认错误由az storage container create命令触发。


解决方案

1. 凭证缺失提示与404错误直接相关

Azure CLI默认尝试通过存储账户密钥访问资源,但你的服务主体使用RBAC权限,未提供密钥时CLI无法正确认证访问存储账户,进而触发"资源不存在"的404错误(实际是认证失败导致的权限问题,返回错误码混淆)。

2. 修复认证问题的具体步骤

在所有az storage命令中添加--auth-mode login参数,强制CLI使用已登录的服务主体身份(RBAC)进行认证:

修改后的Azure CLI脚本片段:

az extension add --name webapp
echo "Added Extension"
az storage container create -n $CONTAINER --account-name $ACCOUNT --resource-group $BASE_GROUP --auth-mode login
echo "Created Container"
az storage blob upload -f app.zip --resource-group $BASE_GROUP --account-name $ACCOUNT -c $CONTAINER -n $ACCOUNT --auth-mode login
echo "Blob Upload Step Completed"
ZIP_URL=$(az storage blob generate-sas --full-uri --permissions r --expiry ${{ env.expiry }} --resource-group $BASE_GROUP --account-name $ACCOUNT -c $CONTAINER -n $ACCOUNT --auth-mode login | xargs)
echo "ZIP_URL Created"
az webapp deploy --name $WEBAPP --resource-group $TEST_GROUP --type zip --src-url  $ZIP_URL --async false
echo "Deployment Completed"
az storage container delete -n $CONTAINER --account-name $ACCOUNT --auth-mode login

3. 额外检查项

  • 确认所有环境变量($CONTAINER、$ACCOUNT、$BASE_GROUP、$TEST_GROUP、$WEBAPP)在GitHub Actions环境中已正确定义,无拼写错误。
  • 验证存储账户的网络配置:若存储账户启用了防火墙或私有端点,需确保服务主体所在的身份上下文能访问存储资源(或允许Azure服务访问存储账户)。
  • 确认服务主体拥有存储账户的Storage Blob Data Contributor角色(仅Contributor角色可能不足以操作Blob存储资源)。

内容的提问来源于stack exchange,提问作者Trec Apps

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 12:25:11