You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps执行Terraform Init时出现403错误如何解决?

跨Azure租户Terraform部署的403认证失败解决方法

错误信息

Error: Failed to get existing workspaces: containers.Client#ListBlobs: Failure responding to request: StatusCode=403 -- Original Error: autorest returned/azure: Service an error. Status=403 Code="AuthenticationFailed" Message="The server failed to authenticate the request. Ensure that the authorization header value is properly formed, including the signature.

核心原因

Terraform使用的身份凭证要么未关联目标Azure租户,要么没有权限访问目标租户中存储Terraform状态文件的Blob容器。

修复步骤

  • 显式指定目标租户ID到Terraform后端配置
    检查backend "azurerm"块,添加或修改tenant_id字段为目标租户的UUID,避免默认使用Azure DevOps所在租户的ID。示例配置:

    backend "azurerm" {
      resource_group_name  = "tf-state-resource-group"
      storage_account_name = "tfstatestorageaccount"
      container_name       = "tfstate-container"
      key                  = "terraform.tfstate"
      tenant_id            = "xxxx-xxxx-xxxx-xxxx" # 替换为目标租户ID
    }
    
  • 配置跨租户认证凭证

    • 若使用Azure DevOps管道:创建跨租户服务连接,选择目标Azure租户的订阅完成授权,管道任务中使用该服务连接设置Azure环境,替代默认租户凭证。
    • 若本地执行:运行az login --tenant 目标租户ID切换到目标租户,确保当前CLI会话的身份有权访问后端存储。
  • 验证存储容器权限
    确保认证身份(服务主体/托管身份)在目标租户的存储Blob容器上拥有Storage Blob Data Contributor权限,仅订阅级贡献者权限无法访问Blob内容。

  • 清除旧认证缓存(本地执行场景)
    执行以下命令清除Azure CLI缓存的旧租户凭证,再重新登录目标租户:

    az account clear
    

内容的提问来源于stack exchange,提问作者dna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 08:52:35