You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure虚拟机Custom Script Extension无法从存储账户下载文件求助

Azure CustomScriptExtension 409错误修复方案

错误原因

存储账户已禁用公共访问,但CustomScriptExtension未正确通过托管身份认证,导致尝试以公共方式下载Blob失败,触发409冲突错误。

遗漏的配置与修正步骤

  • Bicep模板托管身份配置错误
    原模板中managedIdentity : []为空数组,未指定托管身份的认证信息,导致扩展无法使用虚拟机的托管身份访问私有Blob。需在settings中添加托管身份的clientId,同时确保引用虚拟机的托管身份信息。
  • 缺少scriptFileName参数定义
    原模板的commandToExecute中使用了${scriptFileName}变量,但未定义该参数,部署时会触发变量未找到错误,需补充参数定义。
  • RBAC权限生效延迟
    Azure角色权限分配通常需要5-10分钟生效,若刚分配权限就部署扩展,可能因权限未生效导致访问失败,建议等待足够时间后重试。
  • 扩展版本过低
    原模板使用的typeHandlerVersion: '1.10'版本较旧,对托管身份的支持不完善,建议升级至最新稳定版本(如1.14)。

修正后的完整Bicep模板(系统分配托管身份场景)

param arcMachineName string = 'TestServer'
param location string = resourceGroup().location
param scriptFileName string = 'Test.ps1'

// 引用已创建的虚拟机(系统分配托管身份)
resource vm 'Microsoft.Compute/virtualMachines@2022-03-01' existing = {
  name: arcMachineName
}

resource customscriptextension 'Microsoft.Compute/virtualMachines/extensions@2022-03-01' = {  
  name: '${arcMachineName}/customScriptExtension'
  location: location
  properties: {
    publisher: 'Microsoft.Compute'
    type: 'CustomScriptExtension'
    typeHandlerVersion: '1.14'
    autoUpgradeMinorVersion: true
    settings: {
      fileUris: [
        'https://test.blob.core.windows.net/test/Test.ps1'
      ]
      commandToExecute: 'powershell -ExecutionPolicy Unrestricted -File ${scriptFileName}'
      // 配置托管身份clientId,关联虚拟机的系统分配身份
      managedIdentity: {
        clientId: vm.identity.clientId
      }
    }
  }
}

验证权限有效性

可通过以下命令测试托管身份是否能正常访问目标Blob:

az storage blob show --account-name test --container-name test --name Test.ps1 --auth-mode login --identity

若命令能返回Blob详情,则说明权限配置正确。

内容的提问来源于stack exchange,提问作者DevHelp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 18:01:08