You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Azure CLI本地及Cloud Shell执行Packer Build时出现azure-arm托管身份验证订阅ID获取错误的求助

解决Packer Azure ARM构建时的元数据服务认证错误

我之前也碰到过一模一样的问题,这个错误的核心原因是:Packer尝试从Azure VM元数据服务获取订阅ID时,收到的不是预期的JSON格式响应,而是HTML内容(错误提示里的<就是HTML标签的起始符,比如404或权限错误页面)。大概率是认证方式冲突或者配置参数出了问题,下面是具体的排查和解决步骤:

可能的成因

  • 认证方式冲突:你的配置里已经指定了服务主体的client_id和client_secret,但Packer仍尝试启用托管身份认证,导致请求本地/Cloud Shell环境中不存在的元数据服务,返回错误HTML。
  • 配置参数未正确填充:variables里的subscription_id、client_id或client_secret留空或无效,导致Packer fallback到错误的认证路径。
  • 权限不足:服务主体没有足够的权限访问目标订阅或资源组,请求元数据服务时被拒绝,返回错误页面。

可行的解决方法

1. 强制Packer使用服务主体认证,禁用元数据端点

在你的azure-arm builder配置块中,添加以下参数,明确告诉Packer使用你提供的服务主体信息,不要尝试访问元数据服务:

"use_azure_cli_auth": false,
"disable_metadata_endpoint": true

2. 验证并填充所有配置变量

确保variables中的client_id(服务主体应用ID)、client_secret(服务主体密钥)、subscription_id(目标订阅ID)都正确填充,没有留空。可以通过Azure CLI命令验证这些值的有效性:

# 验证服务主体是否能正常登录
az login --service-principal -u <client_id> -p <client_secret> --tenant <tenant_id>
# 验证订阅ID是否正确
az account show --subscription <subscription_id>

3. 确保服务主体拥有足够权限

给你的服务主体在目标资源组packer-rg上分配参与者角色(或更细粒度的必要权限),确保它能创建VM、托管磁盘和镜像资源:

az role assignment create --assignee <client_id> --role "Contributor" --resource-group packer-rg

修改后的完整配置示例

{
  "variables": {
    "client_id": "<你的服务主体应用ID>",
    "client_secret": "<你的服务主体密钥>",
    "subscription_id": "<你的订阅ID>",
    "tenant_id": "<你的租户ID>"
  },
  "builders": [{
    "type": "azure-arm",
    "client_id": "{{user `client_id`}}",
    "client_secret": "{{user `client_secret`}}",
    "subscription_id": "{{user `subscription_id`}}",
    "tenant_id": "{{user `tenant_id`}}",
    "os_type": "Linux",
    "image_publisher": "Canonical",
    "image_offer": "UbuntuServer",
    "image_sku": "18.04-LTS",
    "managed_image_resource_group_name": "packer-rg",
    "managed_image_name": "myPackerImage",
    "location": "East US",
    "vm_size": "Standard_A2",
    "use_azure_cli_auth": false,
    "disable_metadata_endpoint": true
  }],
  "provisioners": [{
    "inline": [
      "apt-get update",
      "apt-get upgrade -y"
    ],
    "inline_shebang": "/bin/sh -x",
    "type": "shell",
    "execute_command": "chmod +x {{ .Path }}; {{ .Vars }} sudo -E sh '{{ .Path }}'"
  }]
}

针对Cloud Shell的额外提示

在Cloud Shell中运行时,默认会优先使用Azure CLI的上下文认证,所以除了添加上述配置参数外,还可以先切换到正确的订阅上下文,避免冲突:

az account set --subscription <你的订阅ID>

内容的提问来源于stack exchange,提问作者Akano Benjamin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 17:23:11