Azure DevOps执行Terraform Init时出现403错误如何解决?
错误信息
Error: Failed to get existing workspaces: containers.Client#ListBlobs: Failure responding to request: StatusCode=403 -- Original Error: autorest returned/azure: Service an error. Status=403 Code="AuthenticationFailed" Message="The server failed to authenticate the request. Ensure that the authorization header value is properly formed, including the signature.
核心原因
Terraform使用的身份凭证要么未关联目标Azure租户,要么没有权限访问目标租户中存储Terraform状态文件的Blob容器。
修复步骤
显式指定目标租户ID到Terraform后端配置
检查backend "azurerm"块,添加或修改tenant_id字段为目标租户的UUID,避免默认使用Azure DevOps所在租户的ID。示例配置:backend "azurerm" { resource_group_name = "tf-state-resource-group" storage_account_name = "tfstatestorageaccount" container_name = "tfstate-container" key = "terraform.tfstate" tenant_id = "xxxx-xxxx-xxxx-xxxx" # 替换为目标租户ID }配置跨租户认证凭证
- 若使用Azure DevOps管道:创建跨租户服务连接,选择目标Azure租户的订阅完成授权,管道任务中使用该服务连接设置Azure环境,替代默认租户凭证。
- 若本地执行:运行
az login --tenant 目标租户ID切换到目标租户,确保当前CLI会话的身份有权访问后端存储。
验证存储容器权限
确保认证身份(服务主体/托管身份)在目标租户的存储Blob容器上拥有Storage Blob Data Contributor权限,仅订阅级贡献者权限无法访问Blob内容。清除旧认证缓存(本地执行场景)
执行以下命令清除Azure CLI缓存的旧租户凭证,再重新登录目标租户:az account clear
内容的提问来源于stack exchange,提问作者dna

