You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署后Azure Synapse Analytics链接服务认证类型错误求助

解决Azure DevOps部署Synapse托管身份链接服务时认证类型变为SQL认证的问题

问题现象

通过Azure DevOps的「Synapse workspace deployment」任务部署采用系统分配托管身份认证的Azure Synapse Analytics链接服务,部署后目标工作区的链接服务认证方式被自动设为「SQL authentication」,而非预期的托管身份。对比源和目标的链接服务JSON,发现目标的connectionString被强制转为SecureString类型,这是导致认证类型异常的核心原因。

源环境链接服务JSON片段:

"type": "AzureSqlDW",
"typeProperties": {
    "connectionString": "Integrated Security=False;Encrypt=True;Connection Timeout=30;Data Source=@{linkedService().Server};Initial Catalog=@{linkedService().DB}"
}

目标环境链接服务JSON片段:

"type": "AzureSqlDW",
"typeProperties": {
    "connectionString": {
        "type": "SecureString",
        "value": "**********"
    }
}

已尝试但无效的操作:

  • 将DevOps任务中的connectionString参数设为空
  • 将该参数设为源环境的connectionString原始值

补充:新建Synapse工作区后部署正常,正常场景下生成的TemplateForWorkspace.json中,尽管参数定义为secureString,但链接服务的connectionString并未被包装为SecureString类型:

参数片段:

"AzureSynapseAnalytics1_connectionString": {
    "type": "secureString",
    "metadata": "Secure string for 'connectionString' of 'AzureSynapseAnalytics1'",
    "defaultValue": "Integrated Security=False;Encrypt=True;Connection Timeout=30;Data Source=xxxx.sql.azuresynapse.net;Initial Catalog=test"
}

资源片段:

"name": "[concat(parameters('workspaceName'), '/AzureSynapseAnalytics1')]",
"type": "Microsoft.Synapse/workspaces/linkedServices",
"apiVersion": "2019-06-01-preview",
"properties": {
    "annotations": [],
    "type": "AzureSqlDW",
    "typeProperties": {
        "connectionString": "[parameters('AzureSynapseAnalytics1_connectionString')]"
    }
},
"dependsOn": []

解决方案

1. 调整ARM模板的链接服务定义

确保ARM模板的链接服务资源部分,不要将connectionString包装为SecureString对象,直接引用参数值,同时补充托管身份相关配置(系统分配托管身份需指定租户ID):

"name": "[concat(parameters('workspaceName'), '/AzureSynapseAnalytics1')]",
"type": "Microsoft.Synapse/workspaces/linkedServices",
"apiVersion": "2019-06-01-preview",
"properties": {
    "annotations": [],
    "type": "AzureSqlDW",
    "typeProperties": {
        "connectionString": "[parameters('AzureSynapseAnalytics1_connectionString')]",
        "tenant": "[parameters('tenantId')]" // 系统分配托管身份必须指定租户ID
    },
    "connectVia": {
        "referenceName": "AutoResolveIntegrationRuntime",
        "type": "IntegrationRuntimeReference"
    }
},
"dependsOn": []

2. 修正DevOps部署任务的参数传递

在Azure DevOps的「Synapse workspace deployment」任务中:

  • connectionString参数直接传递源环境的原始字符串值:Integrated Security=False;Encrypt=True;Connection Timeout=30;Data Source=@{linkedService().Server};Initial Catalog=@{linkedService().DB}
  • 确保目标工作区的系统托管身份已被授予目标SQL池的访问权限(如db_datareader/db_datawriter或自定义角色)

3. 临时手动修复(紧急场景)

如果需要快速恢复服务,可直接在Synapse Studio中操作:

  1. 进入目标链接服务的编辑页面
  2. 将认证方式切换为「系统分配托管身份」
  3. 保存后验证连接是否正常

4. 规范模板导出逻辑

若通过Synapse工作区导出模板,需注意:

  • 导出时选择正确的参数化方式,避免工具自动将connectionString转为SecureString类型
  • 导出后手动检查并调整资源定义,确保connectionString保持普通字符串格式

关键原因

当connectionString被包装为SecureString对象时,Synapse会默认识别为SQL认证模式(因为SecureString通常用于存储SQL登录密码)。而托管身份认证的链接服务要求connectionString为普通字符串,配合托管身份配置项(如tenant)来启用托管身份认证流程。

内容的提问来源于stack exchange,提问作者Raffael

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 21:17:09