Device Update Agent作为身份模块适配Identity Service的连接问题排查
问题排查与缺失步骤梳理
1. 修正Identity Service的config.toml配置
当使用设备连接字符串作为manual源时,必须明确指定Device Update Agent对应的模块ID(通常为deviceUpdateAgent),否则Identity Service无法识别要为哪个模块获取连接信息。正确配置示例:
[service] name = "aziot-identityd" [identity] source = "manual" connection_string = "<你的设备连接字符串>" # 新增模块ID配置,对应IoT Hub中创建的Agent模块身份ID module_id = "deviceUpdateAgent"
保存配置后重启Identity Service:
sudo systemctl restart aziot-identityd
2. 验证du-config.json的配置准确性
确保配置中无残留模块连接字符串,且连接类型字段拼写准确(大小写敏感):
{ "schemaVersion": "1.0", "aduShellTrustedUsers": [], "logLevel": "info", "connectionType": "AIS", "manufacturer": "<你的设备厂商>", "model": "<你的设备型号>" }
3. 修复Agent进程的权限问题
日志中connect failure 13是权限错误(EPERM),需将Agent用户加入Identity Service的用户组:
# 将adu用户添加到aziot组 sudo usermod -aG aziot adu # 重启Device Update Agent服务 sudo systemctl restart adu-agent
4. 确认IoT Hub中的模块身份存在
登录Azure门户进入目标IoT Hub,找到对应设备的模块身份页面,确认已创建ID为deviceUpdateAgent的模块身份,若缺失需手动创建。
5. 排查Identity Service运行状态
检查服务是否正常运行,并查看日志定位连接问题:
# 查看服务状态 sudo systemctl status aziot-identityd # 查看最近10分钟的服务日志 journalctl -u aziot-identityd --since "10 minutes ago"
若日志显示模块认证失败,需验证设备连接字符串有效性、设备是否在IoT Hub启用,以及网络IP是否在IoT Hub允许范围内。
内容的提问来源于stack exchange,提问作者Gustavo Nóbrega
相关产品推荐
相关产品推荐

