You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 8 WebApi部署到APIM访问Azure Blob报403认证失败求助

.NET 8 WebApi部署到APIM后访问Azure Blob存储报403认证失败

我有一个.NET 8 WebApi项目,使用Azure.Storage.Blobs SDK(v12.19.1)通过访问密钥访问Azure存储账户。在本地主机或Azure虚拟机运行时无问题,但部署到API管理服务(APIM)后,操作失败并返回403 (Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature)。

SDK注册代码

var azureConnectionString = builder.Configuration.GetConnectionString("StorageConnectionString");
services.AddAzureClients(clientBuilder =>
{
    clientBuilder.AddBlobServiceClient(azureConnectionString);
});

引发异常的代码

var containerClient = _client.GetBlobContainerClient("uploads");

if (!await containerClient.ExistsAsync())
    await containerClient.CreateAsync();

连接字符串格式

"StorageConnectionString": "DefaultEndpointsProtocol=https;AccountName={ACCOUNT_NAME};AccountKey={VALUE_REMOVED};EndpointSuffix=core.windows.net"

已排查操作

  • 反复检查并轮换了存储账户访问密钥(其他环境正常,排除密钥本身问题)
  • 尝试过多个相关技术解决方案

核心差异与疑问

本地主机和Azure虚拟机时区为MSDT(-7),而APIM服务使用UTC时区。根据相关资料,时区差异可能导致此认证错误,但不清楚如何解决始终运行在UTC的API服务的该问题。

堆栈跟踪信息

"Status":403,
"ErrorCode":"AuthenticationFailed",
"ClassName":"Azure.RequestFailedException",
"Message":"Service request failed.\r\nStatus: 403 (Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.)\r\n
ErrorCode: AuthenticationFailed\r\n\r\n
Headers:\r\n
    Transfer-Encoding: chunked\r\n
    Server: Microsoft-HTTPAPI/2.0\r\n
    x-ms-request-id: f7bcf6cf-d01e-002d-3537-3922f1000000\r\n
    x-ms-error-code: AuthenticationFailed\r\n
    Date: Thu, 28 Dec 2023 16:53:13 GMT\r\n",

"Data":null,
"InnerException":null,
"HelpURL":null,
"StackTraceString":"   
    at Azure.Core.HttpPipelineExtensions.ProcessMessageAsync(HttpPipeline pipeline, HttpMessage message, RequestContext requestContext, CancellationToken cancellationToken)\r\n   
    at Azure.Storage.Blobs.BlobRestClient.GetPropertiesAsync(String snapshot, String versionId, Nullable`1 timeout, String leaseId, String encryptionKey, String encryptionKeySha256, String encryptionAlgorithm, String ifTags, RequestConditions requestConditions, RequestContext context)\r\n   
    at Azure.Storage.Blobs.Specialized.BlobBaseClient.GetPropertiesInternal(BlobRequestConditions conditions, Boolean async, RequestContext context, String operationName)\r\n   
    at Azure.Storage.Blobs.Specialized.BlobBaseClient.ExistsInternal(Boolean async, CancellationToken cancellationToken)\r\n   
    at Azure.Storage.Blobs.Specialized.BlobBaseClient.ExistsAsync(CancellationToken cancellationToken)\r\n   
    at MyDaycareApi.Services.FileManagerService.LoadTemplateAsync(String path) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\FileManagerService.cs:line 138\r\n   
    at MyDaycareApi.Services.ViewRenderService.BuildAndReplaceAsync(String templateName, Dictionary`2 data) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\ViewRenderService.cs:line 19\r\n   
    at MyDaycareApi.Builders.EmailBuilder.BuildNotification(Int32 daycareId, String daycareName, IEnumerable`1 guardians, String title, String message, String btnText, String btnUrl) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Builders\\EmailBuilder.cs:line 132\r\n   
    at MyDaycareApi.Services.AppNotificationService.SendEmailNotificationAsync(Guardian systemUser, Guardian accountHolder, AppNotificationCreateDto dto) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\AppNotificationService.cs:line 61\r\n   
    at MyDaycareApi.Services.AppNotificationService.SendNotificationAsync(AppNotificationCreateDto dto, List`1 accountHoldersToNotify) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\AppNotificationService.cs:line 130\r\n   
    at MyDaycareApi.Services.AppNotificationService.SendAsync(String email, AppNotificationCreateDto dto) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\AppNotificationService.cs:line 158\r\n   
    at MyDaycareApi.Services.MessageService.SendMessageAsync(IIdentity from, IIdentity to, String msg, UploadImageDto image, Boolean doNotSendEmail) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\MessageService.cs:line 320\r\n   
    at MyDaycareApi.Services.MessageService.SendMessage(ILoggedInUser loggedInUser, NewMessageDto model) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Services\\MessageService.cs:line 354\r\n   
    at MyDaycareApi.Controllers.MessagesController.CreateV2Async(NewMessageDto model) in D:\\Repository\\Repository\\MyDaycare-Api\\MyDaycareApi\\Controllers\\MessagesController.cs:line 107",
"RemoteStackTraceString":null,
"RemoteStackIndex":0,
"ExceptionMethod":null,
"HResult":-2146233088,
"Source":"Azure.Storage.Blobs",
"WatsonBuckets":null

内容的提问来源于stack exchange,提问作者OverMars

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 10:53:13