跨订阅迁移ACR镜像时出现资源找不到错误的技术求助
ACR跨订阅镜像导入报错排查与解决
场景说明
我有3个ACR实例,分别属于不同订阅、不同资源组,但区域相同,需要将ACR1或ACR2的镜像仓库导入至ACR3。使用了以下两组PowerShell命令:
单镜像导入命令
az acr import \ --name <destinationRegistry> \ --source <sourceRegistry>.azurecr.io/<Image:Tag> \ --username <SourceRegistryUsername> \ --password <SourceRegistryPassword>
批量导入脚本
$SourceAcrName="" $DestinationAcrName="" $Repos= az acr repository list --name $SourceAcrName | ConvertFrom-Json foreach ($repo in $Repos) { $Tags = az acr repository show-tags -n $SourceAcrName --repository $repo | ConvertFrom-Json foreach ($tag in $Tags) { az acr import -r $SourceAcrName -n $DestinationAcrName --source "${repo}:${tag}" --no-wait } }
执行后遇到错误:
"The resource with name '<>' and type 'Microsoft.ContainerRegistry/registries' could not be found in subscription '<>' (<---**-******)'."
问题根源
错误核心是当前Azure CLI会话的默认订阅与目标ACR所在订阅不匹配,导致CLI无法定位到指定的ACR资源。
排查与修复方案
1. 切换CLI上下文到对应订阅
操作前先切换到目标ACR或源ACR所在的订阅:
# 切换到源ACR所在订阅 az account set --subscription <源ACR订阅ID/名称> # 切换到目标ACR3所在订阅 az account set --subscription <目标ACR3订阅ID/名称>
2. 命令中明确指定订阅/资源组(推荐)
无需切换上下文,直接在命令中指定ACR所属的订阅和资源组,避免默认订阅不匹配问题:
修正后的单镜像导入命令
az acr import ` --name <destinationRegistry> ` --source <sourceRegistry>.azurecr.io/<Image:Tag> ` --username <SourceRegistryUsername> ` --password <SourceRegistryPassword> ` --subscription <目标ACR3订阅ID/名称> ` --resource-group <目标ACR3资源组名称>
修正后的批量导入脚本
$SourceAcrName = "源ACR名称" $SourceSubId = "源ACR订阅ID" $SourceRG = "源ACR资源组" $DestinationAcrName = "目标ACR3名称" $DestSubId = "目标ACR3订阅ID" $DestRG = "目标ACR3资源组" # 获取源ACR仓库列表(指定源订阅和资源组) $Repos = az acr repository list --name $SourceAcrName --subscription $SourceSubId --resource-group $SourceRG | ConvertFrom-Json foreach ($repo in $Repos) { # 获取仓库标签(指定源订阅和资源组) $Tags = az acr repository show-tags -n $SourceAcrName --repository $repo --subscription $SourceSubId --resource-group $SourceRG | ConvertFrom-Json foreach ($tag in $Tags) { # 导入镜像到目标ACR(指定目标订阅、资源组,源镜像需带完整ACR域名) az acr import ` --name $DestinationAcrName ` --subscription $DestSubId ` --resource-group $DestRG ` --source "${SourceAcrName}.azurecr.io/${repo}:${tag}" ` --no-wait } }
3. 验证权限配置
确保执行命令的账号拥有:
- 源ACR的
AcrPull权限(用于读取镜像) - 目标ACR的
AcrPush权限(用于写入镜像)
4. 核对资源信息准确性
检查命令中填写的ACR名称、订阅ID、资源组名称是否完全正确,避免拼写错误。
内容的提问来源于stack exchange,提问作者Dinesh
相关产品推荐
相关产品推荐

