You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure VM规模集Terraform自定义脚本托管身份下载Blob失败

问题

尝试在Azure虚拟机规模集(VM Scale Set)的自定义脚本中,使用托管身份(Managed Identity)从私有存储容器下载Blob,对应的Terraform代码如下:

# https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/custom-script-linux#property-values
resource "azurerm_virtual_machine_scale_set_extension" "res-extension" {
  depends_on = [
        azurerm_storage_blob.example
    ]

  name                         = "nn-extension"
  virtual_machine_scale_set_id = module.vmss.vmss.id
  publisher                    = "Microsoft.Azure.Extensions"
  type                         = "CustomScript"
  type_handler_version         = "2.1"

  protected_settings = jsonencode({
      "fileUris" = ["${azurerm_storage_blob.example.url}"],
      "commandToExecute" = "sh createfile.sh ; ls -al",
      "managedIdentity" : { "objectId": module.vmss.vmss.identity.0.principal_id }
    }
  )
}

执行失败,报错信息如下:

"Error message: \"Enable failed: processing file downloads failed: failed to download file[0]: failed to download response and write to file: /var/lib/waagent/custom-script/download/1/createfile: failed to create http request: Unable to get managed identity with object id 2c8.....8. Please make sure that the user assigned managed identity is added to the VM"

已在Azure门户确认VM规模集已配置状态正常的托管身份,且Principal ID与代码中一致;改用clientId配置时也会出现类似错误。请问是否可以使用托管身份下载Blob?是否需要为规模集中的单个VM实例分配用户分配托管身份?

回答

  • 可以使用托管身份下载Blob
    自定义脚本扩展(CustomScript Extension)支持通过托管身份访问私有存储Blob,核心是确保配置细节和权限设置正确。

  • 无需单独为单个VM实例分配用户分配托管身份
    虚拟机规模集层面配置的用户分配托管身份会自动同步到所有实例,无需逐个实例手动配置。

  • 关键排查与修正点

    1. 权限配置验证:确认该用户分配托管身份已被授予目标存储容器的存储Blob数据读取者权限,且权限作用范围是目标容器(而非仅存储账户层面)。
    2. 扩展参数修正:对于CustomScript Extension 2.x版本,使用用户分配托管身份时,需在managedIdentity中配置clientId而非objectId,修正后的配置示例:
      protected_settings = jsonencode({
          "fileUris" = ["${azurerm_storage_blob.example.url}"],
          "commandToExecute" = "sh createfile.sh ; ls -al",
          "managedIdentity" : { "clientId": module.vmss.vmss.identity.0.client_id }
        }
      )
      
    3. 身份状态确认:通过Azure CLI执行az vmss identity show --resource-group <资源组名> --name <VMSS名称>,确认输出中包含目标托管身份的clientId和principalId,且状态正常。
    4. 依赖顺序调整:添加对存储容器角色分配资源的depends_on依赖,确保扩展部署前权限已生效,避免因权限未同步导致的下载失败。

内容的提问来源于stack exchange,提问作者Jay05

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 02:15:22