You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过Azure CLI创建AKS 1.28.3集群,遇identifierUris验证错误

问题原因

这个错误是因为你的Azure AD租户启用了应用程序域名限制,AKS自动为系统分配托管标识生成的identifierUris(即http://8c4b04.mytestinga-duotifysandbox-0aad06.westus2.cloudapp.azure.com)不属于租户已验证的域名或其子域名,触发了Azure AD的安全校验规则。

修复方案

方案1:调整Azure AD租户的域名限制设置

  1. 登录Azure门户,进入Azure Active Directory
  2. 左侧导航栏选择外部标识 -> 用户设置
  3. 找到管理企业应用程序的设置部分,点击"限制可用于创建应用程序的域"旁边的"编辑"
  4. 若该选项为"已启用",可选择:
    • 将cloudapp.azure.com添加到允许的域名列表中(适用于接受该域名作为合法标识的场景)
    • 暂时关闭该限制(仅测试场景使用,生产环境不建议)

方案2:使用用户分配的托管标识(推荐生产环境)

手动创建符合域名要求的用户分配托管标识,再关联到AKS集群:

  1. 创建用户分配托管标识(替换your-verified-domain.com为租户已验证的域名):
    az identity create -g duotifysandbox -n myaks-managed-identity --identifier-uris "https://your-verified-domain.com/myaks-managed-identity"
    
  2. 获取该标识的资源ID,在AKS创建命令中指定使用此标识:
    az aks create `
        -n 'mytestingaks' `
        -l 'westus2' `
        -g 'duotifysandbox' `
        --kubernetes-version '1.28.3' `
        --node-vm-size 'Standard_NC6' `
        --enable-cluster-autoscaler `
        --node-count 1 `
        --min-count 1 `
        --max-count 1 `
        --enable-managed-identity `
        --assign-identity "/subscriptions/你的订阅ID/resourceGroups/duotifysandbox/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myaks-managed-identity" `
        --network-plugin azure `
        --network-policy calico `
        -o json
    

方案3:确认租户已验证域名

先确认Azure AD租户下的已验证域名:

  1. 进入Azure AD -> 自定义域名
  2. 查看列表中状态为"已验证"的域名,确保后续使用的identifierUris基于这些域名或其子域名。

内容的提问来源于stack exchange,提问作者Will Huang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 13:42:36