在Python Runbook中通过托管标识获取Azure Automation凭据密码的问题
问题:使用托管标识获取Azure自动化账户凭据的实际密码
我正尝试在Python 3.8 Runbook中使用托管标识(Managed Identity)获取Azure自动化账户(Automation Account)的凭据。当前代码能够获取凭据对象,但无法获取所需的实际密码,已查阅官方文档但尚未找到解决方法,请问如何处理?
当前代码
from azure.identity import ManagedIdentityCredential from azure.mgmt.automation import AutomationClient from azure.mgmt.automation.operations import CredentialOperations def get_credential(credential): subscription_id = "xxxxxxxxxxxx" automation_account = "xxxxxxxxxxxx" # Create Managed Identity object auth_client = ManagedIdentityCredential() # Create Automation Client client = AutomationClient(auth_client, subscription_id) # Create Credential Operations Client credential_client = CredentialOperations(client._client, client._config, client._serialize, client._deserialize) # Get Credential cred = credential_client.get(subscription_id, automation_account, credential) return cred
解决方案
Azure自动化账户的凭据密码属于敏感信息,通过Azure Management API的CredentialOperations.get()方法仅会返回凭据的元数据(如用户名、创建时间等),不会返回明文密码。要在Python Runbook中获取实际密码,需要使用Azure自动化Runbook内置的专用工具方法:
- 使用Azure自动化Runbook环境内置的
azure.automation.core模块中的get_automation_ps_credential函数,该函数可以直接返回包含明文密码的凭据对象。 - 确保你的托管标识已被授予访问目标自动化账户凭据的权限(例如
Automation Contributor角色,或更细粒度的自定义权限)。
修改后的代码示例:
from azure.automation.core.automation_account import get_automation_ps_credential def get_credential(credential_name): # 直接通过内置方法获取包含密码的凭据 cred = get_automation_ps_credential(credential_name) # 提取用户名和密码 username = cred.username password = cred.password return {"username": username, "password": password}
说明
get_automation_ps_credential是Azure自动化Runbook Python环境特有的内置函数,无需额外安装依赖,专门用于安全获取凭据的敏感信息。- 该方法会自动使用Runbook的托管标识进行身份验证,无需手动创建
ManagedIdentityCredential实例。
内容的提问来源于stack exchange,提问作者ChristofferL
相关产品推荐
相关产品推荐

