Azure Spring Apps部署报错、容器日志无法访问及deny assignment权限问题求助
操作场景
使用Azure CLI将Azure Container Registry(ACR)中的Docker镜像部署到Azure Spring Apps,执行命令如下:
az spring app deploy -n <application-name> -s <service-name> -g <resource-group-name> --container-image processorregistry.azurecr.io/test-app:myapp-2 --container-registry processorregistry.azurecr.io --registry-username <registry-username> --registry-password <registry-password>
遇到的问题
- 执行部署命令时,终端返回
InternalServerError - 尝试访问容器日志时,提示
Unauthorized - 修改容器配置时,收到错误提示:
however, the access is denied because of the deny assignment with name '86a4e140-7a5c-4130-9b7a-b79af99c6413' and Id '86a4e1407a5c41309b7ab79af99c6413' at scope '/subscriptions/9c270d7c-042e-48e9-b1ee-61eea44726f7/resourceGroups/demo-app-environment_SpringApps_0dedeb44-a86f-4530-b61f-03765a500d8f'.
但检查订阅级别的deny assignments列表,结果为空。
排查步骤
验证Azure Spring Apps系统身份权限
Azure Spring Apps依赖系统分配托管身份访问资源,需确认该身份权限:- 在Azure门户进入目标Spring Apps服务的身份选项卡,复制系统分配身份的对象ID
- 到ACR实例的**访问控制(IAM)**页面,给该身份分配
AcrPull角色 - 到目标资源组的**访问控制(IAM)**页面,给该身份分配
Spring Apps Contributor或Contributor角色
查询资源组级别的Deny Assignments
订阅级列表为空不代表资源组无相关配置,用CLI查询目标资源组的Deny Assignments:az role assignment list --deny --resource-group demo-app-environment_SpringApps_0dedeb44-a86f-4530-b61f-03765a500d8f --subscription 9c270d7c-042e-48e9-b1ee-61eea44726f7若找到提示中的Deny Assignment,检查其拒绝的权限范围,确认是否影响Spring Apps操作。
确认CLI登录上下文权限
- 执行
az account show验证当前登录的订阅ID与目标一致 - 执行
az role assignment list --assignee <你的用户主体名称> --resource-group <资源组名称>,确认账号在资源组拥有Contributor及以上权限
- 执行
检查Spring Apps服务状态
在Azure门户查看Spring Apps服务的概述页面,确认服务无维护、异常状态。重新生成ACR访问凭据
重新生成ACR的访问密钥,替换部署命令中的--registry-username和--registry-password,排除凭据过期或无效问题。
内容的提问来源于stack exchange,提问作者christopher420

