将应用部署至Azure Kubernetes Service失败:全局管理员权限不足
我正在学习Git课程,当前处于将应用推送至Azure Kubernetes Service(AKS)的步骤,联系PluralSight支持未收到回复,只能自行排查。预期成功部署至AKS,但我的全局管理员(Global Admin)账号却触发了权限报错。
已核查账号权限,确认拥有全局管理员权限,该账号应能执行错误信息中描述的范围下的凭据列出操作。通过对象ID(GUID)在Azure门户中查询,也确认该账号确实已分配全局管理员角色,按常理此角色应拥有全部权限。
环境变量和密钥在第一个任务build-deploy-image中均能正常使用,该任务执行无问题。
完整错误信息(已隐去账号GUID和订阅GUID)
Error: "error":"code":"AuthorizationFailed","message":"The client '' with object id '' does not have authorization to perform action 'Microsoft.ContainerService/managedClusters/accessProfiles/listCredential/action' over scope '/subscriptions//resourceGroups//providers/Microsoft.ContainerService/managedClusters//accessProfiles/clusterAdmin' or the scope is invalid. If access was recently granted, please refresh your credentials."
工作流第二个任务的YAML代码
deploy-to-aks: runs-on: ubuntu-latest if: github.ref == 'refs/heads/master' needs: build-deploy-image #env: #NAMESPACE: dummy steps: - uses: actions/checkout@main # Set the target Azure Kubernetes Service (AKS) cluster. - uses: azure/aks-set-context@v1 with: creds: '${{ secrets.AZURE_CREDENTIALS_DEMO }}' cluster-name: ${{ secrets.AKS_NAME_DEMO }} resource-group: ${{ secrets.AKS_RESOURCE_GROUP }} # Create namespace if doesn't exist # - run: | # kubectl create namespace ${{ env.NAMESPACE }} --dry-run -o json | kubectl apply -f - # Create image pull secret for ACR - uses: azure/k8s-create-secret@v1 with: container-registry-url: ${{ env.ACR_LOGON_SERVER }} container-registry-username: ${{ secrets.SERVICE_PRINCIPAL_ID_DEMO }} container-registry-password: ${{ secrets.SERVICE_PRINCIPAL_PASSWORD_DEMO }} secret-name: ${{ secrets.AKS_SECRET }} # namespace: ${{ env.NAMESPACE }} # Deploy app to AKS - uses: azure/k8s-deploy@v1 with: manifests: | manifests/deployment.yml manifests/service.yml images: | ${{ env.IMAGE_NAME }} imagepullsecrets: | ${{ secrets.AKS_SECRET }} #namespace: ${{ env.NAMESPACE }}
内容的提问来源于stack exchange,提问作者user1585204

