You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已加入Endpoint Creators组,创建AWS类型Azure服务端点仍遇权限问题

问题场景

在Azure DevOps项目中,通过管道执行以下脚本创建AWS服务连接器时,触发权限错误:

env:
  AZURE_DEVOPS_EXT_PAT: $(System.AccessToken)
script: |
  az devops configure -d organization=https://dev.azure.com/${AZ_DO_ORGANIZATION_NAME}/ project=${AZ_DO_PROJECT_NAME}
  az devops service-endpoint create --service-endpoint-configuration service-endpoint.json

对应的service-endpoint.json配置(已替换所有占位符为有效值):

{
  "administratorsGroup": null,
  "authorization": {
    "parameters": {
      "assumeRoleArn": "",
      "externalId": "",
      "roleSessionName": "",
      "sessionToken": null,
      "username": "SECRET_ACCESS_KEY",
      "password": "ACCESS_KEY_ID"
    },
    "scheme": "UsernamePassword"
  },
  "data": {},
  "description": "",
  "groupScopeId": null,
  "isOutdated": false,
  "isReady": true,
  "isShared": false,
  "name": "AZ_DO_SERVICE_ENDPOINT_NAME",
  "operationStatus": null,
  "owner": "Library",
  "readersGroup": null,
  "serviceEndpointProjectReferences": [
    {
      "description": "",
      "name": "AWS",
      "projectReference": {
        "id": "AZ_DO_PROJECT_ID",
        "name": "AZ_DO_PROJECT_NAME"
      }
    }
  ],
  "type": "AWS",
  "url": "https://aws.amazon.com/"
}

执行后收到错误提示:

ERROR: You do not have permission to create a service connection. You need to be a Creator for service connections in this project.

但已确认自身属于项目设置→权限→Endpoint Creators组,需排查问题原因。

可能的原因及排查方向
  • 管道使用的是服务账户权限,而非个人权限
    脚本中使用的$(System.AccessToken)是Azure DevOps管道内置服务账户(Project Build Service或Project Collection Build Service)的令牌,并非你个人的PAT。即使你个人在Endpoint Creators组,该服务账户未必拥有创建服务连接器的权限。
    排查:进入项目设置→权限→服务连接→安全,检查**Project Build Service (<组织名>)或Project Collection Build Service (<组织名>)**是否被授予“创建”权限,若没有则添加对应权限。

  • 个人权限被细粒度设置覆盖
    虽然你属于Endpoint Creators组,但可能存在直接针对你个人账户的拒绝权限设置,或者Endpoint Creators组的“创建服务连接”权限被修改为拒绝/未允许状态。
    排查:在项目设置→权限→服务连接→安全中,直接查看你个人账户的权限明细,确认“创建”权限为允许状态;同时检查Endpoint Creators组的对应权限是否正常。

  • AWS服务连接的特殊配置限制
    配置中owner字段设为Library,可能需要账户拥有项目库的额外操作权限;或者AWS类型服务连接本身需要超出基础创建权限的特殊授权。
    排查:尝试将owner改为Project后重新执行,或确认账户对项目库的权限配置。

  • 权限同步存在延迟
    Azure DevOps权限变更可能存在短暂的同步延迟,若刚加入Endpoint Creators组就执行管道,可能权限尚未生效。
    排查:等待5-10分钟后重新运行管道,或刷新项目权限页面确认设置已同步。

内容的提问来源于stack exchange,提问作者Marius Mitrofan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 18:45:33