You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法将DAG导入Azure Data Factory中的托管Airflow

问题:ADF托管Airflow导入Blob存储DAG时授权失败

环境信息

  • ADF系统托管标识已配置访问Blob存储,ADF内可正常浏览该存储
  • 使用公共集成运行时,存储Blob连接测试正常
  • Airflow版本:2.4.3
  • 认证方式:AAD

错误详情

尝试将Blob存储中的DAG Python文件附加到Airflow时触发以下异常:

Microsoft.WindowsAzure.Storage.StorageException: This request is not authorized to perform this operation.
at Microsoft.WindowsAzure.Storage.Core.Executor.Executor.ExecuteAsyncInternal[T](RESTCommand`1 cmd, IRetryPolicy policy, OperationContext operationContext, CancellationToken token)
at Microsoft.WindowsAzure.Storage.Blob.CloudBlobContainer.ListBlobsSegmentedAsync(String prefix, Boolean useFlatBlobListing, BlobListingDetails blobListingDetails, Nullable`1 maxResults, BlobContinuationToken currentToken, BlobRequestOptions options, OperationContext operationContext, CancellationToken cancellationToken)
at Microsoft.ADF.PipelineManager.AirflowHandler.ListDAGsAsync(String integrationRuntimeName, String linkedServiceName, String containerName, String folderPath, Boolean copyFolderStructure, SystemProperties systemProperties, CancellationToken cancellationToken) in C:\__w\1\s\PipelineManager\src\PipelineManager.Core\JobHandlers\AirflowHandlers\AirflowHandler.cs:line 165
at Microsoft.ADF.PipelineManager.AirflowController.ListAirflowDAGsAsync(String factoryName, String integrationRuntimeName, ListAirflowDagsRequest request, CancellationToken cancellationToken) in C:\__w\1\s\PipelineManager\src\PipelineManager.Core.FX\AirflowControllers\AirflowController.cs:line 163
Request Information
RequestID:2dd561ad-a01e-0064-643a-bcdb21000000
RequestDate:Sat, 22 Jul 2023 01:18:05 GMT
StatusMessage:This request is not authorized to perform this operation.
ErrorCode:AuthorizationFailure
ErrorMessage:This request is not authorized to perform this operation.
RequestId:2dd561ad-a01e-0064-643a-bcdb21000000
Time:2023-07-22T01:18:05.0775853Z

排查与解决方案

  • 检查托管标识的Blob数据权限
    确保ADF系统托管标识对目标Blob容器拥有Storage Blob Data Reader或Storage Blob Data Contributor角色,注意仅通用的Reader角色无法操作Blob数据,必须使用针对Blob数据的内置角色。
  • 验证存储账户网络设置
    若存储账户开启了防火墙,需确认是否允许公共集成运行时访问:要么添加ADF服务IP段,要么勾选"允许受信任的Microsoft服务访问此存储账户"选项。
  • 核对链接服务配置
    确认Blob存储链接服务采用系统托管标识认证,同时检查容器名称、文件夹路径的拼写是否完全正确,无大小写或路径层级错误。
  • 检查Blob文件ACL(若启用分层命名空间)
    若存储账户使用ADLS Gen2分层命名空间,需确认DAG文件夹及文件的ACL权限未限制托管标识的读取、列出操作。

内容的提问来源于stack exchange,提问作者zezzar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 20:23:19