本地Docker容器中Azure托管标识Python应用访问Key Vault问题排查
问题:本地Docker容器中Azure托管身份访问Key Vault失败
背景
我开发了一个Python函数应用,通过Azure托管身份从Azure Key Vault读取证书,核心代码如下:
credential = DefaultAzureCredential() certificate_client = CertificateClient(key_vault_url, credential) certificate = certificate_client.get_certificate(key_vault_certificate_name)
这段代码在VS Code本地运行、部署到Azure平台时均正常,但部署到本地Docker容器后出现错误:
Exception: ServiceRequestError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1007)
我怀疑该错误具有误导性,问题可能出在Docker无法访问Azure托管身份,或是公司代理配置导致的。我已在Dockerfile中安装必要证书,但未解决问题;同时为推送到Azure的容器应用配置了与函数应用相同的Key Vault全权限,仍然报错。
想请教:有没有方法确认问题到底是证书错误还是身份验证错误?
更新1
给三个构造函数添加connection_verify=False后,出现新错误,确认同时存在证书错误和默认身份验证错误:
ClientAuthenticationError: DefaultAzureCredential failed to retrieve a token from the included credentials.
具体错误详情:
Attempted credentials: EnvironmentCredential: EnvironmentCredential authentication unavailable. Environment variables are not fully configured. ManagedIdentityCredential: ManagedIdentityCredential authentication unavailable, no response from the IMDS endpoint. SharedTokenCacheCredential: SharedTokenCacheCredential authentication unavailable. No accounts were found in the cache. AzureCliCredential: Azure CLI not found on path AzurePowerShellCredential: PowerShell is not installed AzureDeveloperCliCredential: Azure Developer CLI could not be found.
我的Dockerfile内容如下:
FROM mcr.microsoft.com/azure-functions/python:4-python3.10-appservice ENV AzureWebJobsScriptRoot=/home/site/wwwroot \ AzureFunctionsJobHost__Logging__Console__IsEnabled=true COPY Certificates/*.crt /usr/local/share/ca-certificates/ RUN update-ca-certificates --verbose --fresh COPY requirements.txt / RUN pip install --trusted-host pypi.org --trusted-host \ pypi.python.org --trusted-host=files.pythonhosted.org --no-cache-dir -r /requirements.txt COPY . /home/site/wwwroot
内容的提问来源于stack exchange,提问作者Ali
相关产品推荐
相关产品推荐

