You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Function配置用户分配身份访问KeyVault异常排查求助

Azure Function App 无法使用用户分配身份访问KeyVault问题排查

问题描述

使用Pulumi的azure_native provider构建Azure基础设施时,Function App始终尝试通过系统分配托管身份访问KeyVault,而非配置的用户分配身份。已完成以下配置但仍无法解析KeyVault密钥:

  • 在Pulumi中为Function App设置keyVaultReferenceIdentity为用户分配身份的Principal/Object Id
  • 在KeyVault访问策略中为该用户分配身份赋予对应权限

原配置代码

return new web.WebApp("xxxx", {
    ...resourceGroupArgs,
    serverFarmId: aspId,
    name: rndFAppName.hex.apply((v) => `fa${v}`),
    kind: "functionapp,linux",
    siteConfig: {
        appSettings: [
            {name: "MICROSOFT_PROVIDER_AUTHENTICATION_SECRET", value: "MICROSOFT_PROVIDER_AUTHENTICATION_SECRET"},
            {name: "SCM_DO_BUILD_DURING_DEPLOYMENT", value: "false"},
            {name: "WEBSITE_ENABLE_APP_SERVICE_STORAGE", value: "true"},
            {name: "APPLICATIONINSIGHTS_CONNECTION_STRING", value: appInsightsConnectionString},
            {name: "APPINSIGHTS_INSTRUMENTATIONKEY", value:appInsightsInstrumentkey},
            {name: "FUNCTIONS_EXTENSION_VERSION", value: "~4"},
            {name: "AzureWebJobsStorage__accountName", value: storageAccount.name},
            {
                name: "AzureWebJobsStorage",
                value: pulumi.interpolate`DefaultEndpointsProtocol=https;AccountName=${storageAccount.name};AccountKey=${storageKeys.keys[0].value};EndpointSuffix=core.windows.net`
            },
            {name: "FUNCTIONS_WORKER_RUNTIME", value: "dotnet"},
        ],
        cors: {
            allowedOrigins: ["https://preview.portal.azure.com"],
        },
        ftpsState: "Disabled",
        remoteDebuggingVersion: "VS2019",
        linuxFxVersion: "dotnet|6.0",
        minTlsVersion: "1.2",
        use32BitWorkerProcess: false,
        keyVaultReferenceIdentity: userAssignedIdentity.principalId,
    },
    identity: {
        type: "UserAssigned",
        userAssignedIdentities: userAssignedIdentity.id.apply(id => getId(id))
    }
}, {dependsOn: [userAssignedIdentity, appInsights, storageAccount, kvVault, container]});

配置遗漏点及修正方案

1. 修正keyVaultReferenceIdentity取值类型

Azure要求Key Vault引用身份必须使用用户分配身份的Client ID,而非Principal/Object ID。原代码中使用principalId是错误的,需替换为clientId。

2. 规范userAssignedIdentities格式

Pulumi中该字段需要以用户分配身份ID为键、空对象为值的字典格式。原代码中getId(id)方法若未返回正确格式,会导致身份关联失效,Function App会 fallback到系统身份。

3. 添加Linux环境必需的应用设置

Linux版Function App需要WEBSITE_LOAD_USER_PROFILE = 1才能正确加载用户分配身份,原配置中缺少该设置。

4. 验证KeyVault访问策略权限

确保给用户分配身份赋予了对应资源的Get和List权限(如密钥/机密/证书,根据实际使用场景),且权限范围覆盖目标资源。

修正后的代码示例

return new web.WebApp("xxxx", {
    ...resourceGroupArgs,
    serverFarmId: aspId,
    name: rndFAppName.hex.apply((v) => `fa${v}`),
    kind: "functionapp,linux",
    siteConfig: {
        appSettings: [
            {name: "MICROSOFT_PROVIDER_AUTHENTICATION_SECRET", value: "MICROSOFT_PROVIDER_AUTHENTICATION_SECRET"},
            {name: "SCM_DO_BUILD_DURING_DEPLOYMENT", value: "false"},
            {name: "WEBSITE_ENABLE_APP_SERVICE_STORAGE", value: "true"},
            {name: "APPLICATIONINSIGHTS_CONNECTION_STRING", value: appInsightsConnectionString},
            {name: "APPINSIGHTS_INSTRUMENTATIONKEY", value:appInsightsInstrumentkey},
            {name: "FUNCTIONS_EXTENSION_VERSION", value: "~4"},
            {name: "AzureWebJobsStorage__accountName", value: storageAccount.name},
            {
                name: "AzureWebJobsStorage",
                value: pulumi.interpolate`DefaultEndpointsProtocol=https;AccountName=${storageAccount.name};AccountKey=${storageKeys.keys[0].value};EndpointSuffix=core.windows.net`
            },
            {name: "FUNCTIONS_WORKER_RUNTIME", value: "dotnet"},
            // 添加Linux环境必需配置
            {name: "WEBSITE_LOAD_USER_PROFILE", value: "1"},
        ],
        cors: {
            allowedOrigins: ["https://preview.portal.azure.com"],
        },
        ftpsState: "Disabled",
        remoteDebuggingVersion: "VS2019",
        linuxFxVersion: "dotnet|6.0",
        minTlsVersion: "1.2",
        use32BitWorkerProcess: false,
        // 替换为用户分配身份的Client ID
        keyVaultReferenceIdentity: userAssignedIdentity.clientId,
    },
    identity: {
        type: "UserAssigned",
        // 使用正确的字典格式关联用户分配身份
        userAssignedIdentities: {
            [userAssignedIdentity.id]: {}
        }
    }
}, {dependsOn: [userAssignedIdentity, appInsights, storageAccount, kvVault, container]});

内容的提问来源于stack exchange,提问作者TheDentist

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 17:44:52