Azure Function连接Cosmos DB Table API用托管身份遇授权格式错误
Azure Cosmos DB Table API 托管身份支持问题及解决
问题描述
在Azure Function中尝试通过托管身份连接Cosmos DB Table API,编写代码如下:
Uri tableEndpoint = new Uri("https://mycosmos.table.cosmos.azure.com:443/"); var tableServiceClient = new TableServiceClient(tableEndpoint, new DefaultAzureCredential()); var tableClient = tableServiceClient.GetTableClient(tableName);
运行后触发错误:
Authorization header doesn't confirm to the required format
此前了解到两年前Cosmos DB Table API尚不支持托管身份,现确认该功能是否已实现。
解答
Cosmos DB Table API目前已支持托管身份认证,代码报错是因为缺少必要的配置步骤,而非功能未上线。需完成以下操作:
- 在Azure门户的Cosmos DB账户「访问控制(IAM)」页面,添加角色分配:选择「Cosmos DB内置数据角色」中的合适角色(如
Cosmos DB Table Contributor),将其分配给Azure Function对应的托管身份(系统分配或用户分配均可)。 - 确保项目使用的
Azure.Data.TablesSDK版本不低于12.8.0,该版本开始正式支持Cosmos DB Table API的托管身份认证。 - 确认Azure Function已正确配置托管身份:系统分配身份需启用,用户分配身份需完成关联。
完成上述配置后,原代码即可正常运行。早期版本的SDK确实不支持该功能,但后续更新已补足此能力。
内容的提问来源于stack exchange,提问作者Rob Bowman
相关产品推荐
相关产品推荐

