无法将DAG导入Azure Data Factory中的托管Airflow
问题:ADF托管Airflow导入Blob存储DAG时授权失败
环境信息
- ADF系统托管标识已配置访问Blob存储,ADF内可正常浏览该存储
- 使用公共集成运行时,存储Blob连接测试正常
- Airflow版本:2.4.3
- 认证方式:AAD
错误详情
尝试将Blob存储中的DAG Python文件附加到Airflow时触发以下异常:
Microsoft.WindowsAzure.Storage.StorageException: This request is not authorized to perform this operation. at Microsoft.WindowsAzure.Storage.Core.Executor.Executor.ExecuteAsyncInternal[T](RESTCommand`1 cmd, IRetryPolicy policy, OperationContext operationContext, CancellationToken token) at Microsoft.WindowsAzure.Storage.Blob.CloudBlobContainer.ListBlobsSegmentedAsync(String prefix, Boolean useFlatBlobListing, BlobListingDetails blobListingDetails, Nullable`1 maxResults, BlobContinuationToken currentToken, BlobRequestOptions options, OperationContext operationContext, CancellationToken cancellationToken) at Microsoft.ADF.PipelineManager.AirflowHandler.ListDAGsAsync(String integrationRuntimeName, String linkedServiceName, String containerName, String folderPath, Boolean copyFolderStructure, SystemProperties systemProperties, CancellationToken cancellationToken) in C:\__w\1\s\PipelineManager\src\PipelineManager.Core\JobHandlers\AirflowHandlers\AirflowHandler.cs:line 165 at Microsoft.ADF.PipelineManager.AirflowController.ListAirflowDAGsAsync(String factoryName, String integrationRuntimeName, ListAirflowDagsRequest request, CancellationToken cancellationToken) in C:\__w\1\s\PipelineManager\src\PipelineManager.Core.FX\AirflowControllers\AirflowController.cs:line 163 Request Information RequestID:2dd561ad-a01e-0064-643a-bcdb21000000 RequestDate:Sat, 22 Jul 2023 01:18:05 GMT StatusMessage:This request is not authorized to perform this operation. ErrorCode:AuthorizationFailure ErrorMessage:This request is not authorized to perform this operation. RequestId:2dd561ad-a01e-0064-643a-bcdb21000000 Time:2023-07-22T01:18:05.0775853Z
排查与解决方案
- 检查托管标识的Blob数据权限
确保ADF系统托管标识对目标Blob容器拥有Storage Blob Data Reader或Storage Blob Data Contributor角色,注意仅通用的Reader角色无法操作Blob数据,必须使用针对Blob数据的内置角色。 - 验证存储账户网络设置
若存储账户开启了防火墙,需确认是否允许公共集成运行时访问:要么添加ADF服务IP段,要么勾选"允许受信任的Microsoft服务访问此存储账户"选项。 - 核对链接服务配置
确认Blob存储链接服务采用系统托管标识认证,同时检查容器名称、文件夹路径的拼写是否完全正确,无大小写或路径层级错误。 - 检查Blob文件ACL(若启用分层命名空间)
若存储账户使用ADLS Gen2分层命名空间,需确认DAG文件夹及文件的ACL权限未限制托管标识的读取、列出操作。
内容的提问来源于stack exchange,提问作者zezzar
相关产品推荐
相关产品推荐

