You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Function访问Azure Key Vault遇防火墙授权错误求助

排查Azure Function通过系统分配身份访问Key Vault的防火墙拒绝问题

问题场景

已为启用系统分配标识的Azure Function应用授予Azure Key Vault密钥的Get权限,但调用函数时触发防火墙拒绝错误:

{
"error": "(Forbidden) Client address is not authorized and caller is not a trusted service.\r\nClient address: 51.xx.xx.46\r\nCaller:....Code: Forbidden\nMessage: Client address is not authorized and caller is not a trusted service.\r\nClient address: 51.xx.xx.46\r\nCaller: ..Inner error: {\n "code": "ForbiddenByFirewall"\n}"
}

函数代码:

import logging
import json
import azure.functions as func
from azure.identity import DefaultAzureCredential
from azure.keyvault.secrets import SecretClient

app = func.FunctionApp(http_auth_level=func.AuthLevel.FUNCTION)

@app.route(route="http_trigger")
def http_trigger(req: func.HttpRequest) -> func.HttpResponse:
    logging.info('Python HTTP trigger function processed a request.')

    # Get a credential object using Managed Identity
    credential = DefaultAzureCredential()

    # Create a SecretClient using the Key Vault URL and credential
    vault_url = "https://xxxx.vault.azure.net/"
    secret_client = SecretClient(vault_url=vault_url, credential=credential)

    # Retrieve the secret from Key Vault
    try:
        secret_value = secret_client.get_secret("xxxx").value
        response_message = {"message": f"Secret retrieved from Key Vault: {secret_value}"}
        return func.HttpResponse(json.dumps(response_message), mimetype="application/json")
    except Exception as e:
        response_message = {"error": str(e)}
        return func.HttpResponse(json.dumps(response_message), status_code=500, mimetype="application/json")

Key Vault防火墙当前配置:

  • 仅允许指定IP范围/虚拟网络访问
  • 未开启"允许受信任的Microsoft服务绕过此防火墙"选项

解决方案

方案1:启用受信任服务绕过防火墙

在Key Vault的网络 > 防火墙和虚拟网络设置中:

  • 勾选允许受信任的Microsoft服务绕过此防火墙选项
  • 保存配置后重新测试函数调用

此方式适用于无需严格IP限制的场景,Azure Functions属于微软受信任服务,开启后可直接通过身份验证访问Key Vault。

方案2:添加Function出站IP到防火墙允许列表

若需严格控制IP访问:

  1. 进入Azure Function应用的网络设置,复制所有出站IP地址(消耗计划会列出多个IP,需全部添加)
  2. 在Key Vault的防火墙和虚拟网络设置中,将这些IP添加到允许的IP地址范围列表
  3. 保存配置后测试访问

方案3:虚拟网络集成访问

将Function和Key Vault部署到同一虚拟网络:

  1. 为Function应用配置虚拟网络集成(进入函数应用网络设置,关联目标虚拟网络)
  2. 在Key Vault的防火墙和虚拟网络设置中,添加该虚拟网络到允许的虚拟网络列表
  3. 保存配置后测试访问

额外验证步骤

  • 确认Key Vault访问策略中,已为Function的系统分配标识授予Secret Get权限
  • 检查Function应用的标识设置,确认系统分配标识状态为"开启"

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 13:05:23