容器化Azure Python Durable Function连接存储账户证书链错误求助
问题:容器化Azure Python Durable Function连接存储账户时SSL证书链错误
环境与配置信息
所用Dockerfile
FROM mcr.microsoft.com/azure-functions/python:4-python3.10 ENV AzureWebJobsScriptRoot=/home/site/wwwroot \ AzureFunctionsJobHost__Logging__Console__IsEnabled=true ENV AzureWebJobsStorage="<connection-string>" COPY requirements.txt / RUN pip install -r /requirements.txt COPY . /home/site/wwwroot
容器报错日志
---> DurableTask.AzureStorage.Storage.DurableTaskStorageException: The SSL connection could not be established, see inner exception. ---> Microsoft.WindowsAzure.Storage.StorageException: The SSL connection could not be established, see inner exception. ---> System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception. ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid because of errors in the certificate chain: UntrustedRoot
镜像底层操作系统信息
PRETTY_NAME="Debian GNU/Linux 11 (bullseye)" NAME="Debian GNU/Linux" VERSION_ID="11" VERSION="11 (bullseye)" VERSION_CODENAME=bullseye ID=debian HOME_URL="https://www.debian.org/" SUPPORT_URL="https://www.debian.org/support" BUG_REPORT_URL="https://bugs.debian.org/"
证书安装状态确认
已确认容器内已安装最新版ca-certificates:
$ apt-get install ca-certificates Reading package lists... Done Building dependency tree... Done Reading state information... Done ca-certificates is already the newest version (20210119). 0 upgraded, 0 newly installed, 0 to remove and 1 not upgraded.
存储账户配置
业务要求已在存储账户的「设置>配置」中禁用了Allow Blob public access。
问题
我推测Azure Durable Function需要在存储账户中自动创建操作相关容器,但当前因镜像内SSL证书链不被信任导致访问被拒。试过升级证书但没有效果,请问有哪些替代方案可以让Docker容器正常连接到该存储账户?
内容的提问来源于stack exchange,提问作者Sherwin Fernandes
相关产品推荐
相关产品推荐

