You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service部署Spring Boot应用时Spring Cloud Vault UAMI连接超时

解决Azure App Service中Spring Cloud Vault Config使用UAMI连接超时问题

问题原因

Spring Cloud Vault的azure_msi认证模式默认会尝试访问Azure虚拟机的实例元数据服务(IMDS)端点http://169.254.169.254获取身份令牌,但Azure App Service的托管身份并不通过这个端点提供服务,而是通过环境变量IDENTITY_ENDPOINT和IDENTITY_HEADER暴露身份服务地址和验证头部,这就是导致连接超时的根本原因。

解决方案

修改application.yaml配置,显式指定Spring Cloud Vault使用App Service提供的环境变量来获取身份令牌,配置如下:

spring.cloud.vault:
  scheme: https
  uri: <vault url>
  authentication: azure_msi
  connection_timeout: 5000
  azure_msi:
    role: MY_UAMI
    # 读取App Service环境变量中的身份端点和头部
    endpoint: ${IDENTITY_ENDPOINT}
    header: ${IDENTITY_HEADER}
spring:
  config:
    import: vault://secret-path

额外验证步骤

  • 确认UAMI权限:确保你配置的用户分配托管身份(MY_UAMI)已被授予Azure Vault的访问权限,比如关联了允许读取secret-path路径的Vault Policy。
  • 检查环境变量:在Azure App Service的「配置」→「应用程序设置」中,确认IDENTITY_ENDPOINT和IDENTITY_HEADER这两个系统变量已自动生成(启用托管身份后会自动添加)。
  • 本地测试(可选):如果需要本地模拟,可以手动设置这两个环境变量(值可从App Service控制台复制),验证配置是否能正常获取令牌。

关键说明

  • Spring Cloud Vault 4.x版本支持通过azure_msi.endpoint和azure_msi.header参数自定义身份服务地址,正好适配Azure App Service的托管身份机制。
  • 切换到token认证正常,说明Vault本身的网络连接没有问题,问题仅出在MSI身份令牌的获取路径上。

内容的提问来源于stack exchange,提问作者nsharma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 08:57:07