You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps发布管道访问KeyVault无密钥列表权限求助

Azure DevOps发布管道Key Vault RBAC权限问题求助

我的DevOps发布管道一直失败,报错提示在密钥保管库上无密钥列表权限,试了各种方法都没解决,求帮忙。

错误信息

2023-06-07T07:12:53.7594988Z ##[error]Get secrets failed. Error: The user, group or application 'appid=***;oid=b5a[REDACTED];iss=https://sts.windows.net/292[REDACTED]/' does not have secrets list permission on key vault 'kv-d-chatgeni;location=australiasoutheast'. For help resolving this issue, please see https://go.microsoft.com/fwlink/?linkid=2125287. The specified Azure service connection needs to have Get, List secret management permissions on the selected key vault. To set these permissions, download the ProvisionKeyVaultPermissions.ps1 script from build/release logs and execute it, or set them from the Azure portal..

相关信息

DevOps使用的服务主体信息如下:

对象值
Application (client) ID14e[REDACTED]
Object IDa7e[REDACTED]
Tenant ID292[REDACTED]

我注意到报错里的Object ID是b5a[REDACTED],但Application (client) ID和服务主体的一致。

我针对报错中的Object ID执行了以下命令:

az role assignment create --role "Key Vault Secrets User" --assignee  b5a[REDACTED] --scope /subscriptions/ade[REDACTED]

也尝试用服务主体的Application ID执行命令:

az role assignment create --role "Key Vault Secrets User" --assignee  14e[REDACTED] --scope /subscriptions/143[REDACTED]

任务配置

steps:
- task: AzureKeyVault@2
  displayName: 'Azure Key Vault: kv-d-[REDACTED]'
  inputs:
    azureSubscription: 'app-[REDACTED]'
    KeyVaultName: 'kv-d-[REDACTED]'
    RunAsPreJob: true

其他环境情况

  • 已为b5a[REDACTED]分配订阅级Contributor角色
  • 生产环境KeyVault采用RBAC权限模式,不能改用访问策略
  • 我建了一个用访问策略的测试KeyVault,分配List、Get权限后管道能正常运行

查了很多资料,但大部分都是讲访问策略的,RBAC相关的内容很模糊,实在找不到解决办法了。

内容的提问来源于stack exchange,提问作者Brett Maytom PST

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 19:38:25