Azure DevOps发布管道访问KeyVault无密钥列表权限求助
Azure DevOps发布管道Key Vault RBAC权限问题求助
我的DevOps发布管道一直失败,报错提示在密钥保管库上无密钥列表权限,试了各种方法都没解决,求帮忙。
错误信息
2023-06-07T07:12:53.7594988Z ##[error]Get secrets failed. Error: The user, group or application 'appid=***;oid=b5a[REDACTED];iss=https://sts.windows.net/292[REDACTED]/' does not have secrets list permission on key vault 'kv-d-chatgeni;location=australiasoutheast'. For help resolving this issue, please see https://go.microsoft.com/fwlink/?linkid=2125287. The specified Azure service connection needs to have Get, List secret management permissions on the selected key vault. To set these permissions, download the ProvisionKeyVaultPermissions.ps1 script from build/release logs and execute it, or set them from the Azure portal..
相关信息
DevOps使用的服务主体信息如下:
| 对象 | 值 |
|---|---|
| Application (client) ID | 14e[REDACTED] |
| Object ID | a7e[REDACTED] |
| Tenant ID | 292[REDACTED] |
我注意到报错里的Object ID是b5a[REDACTED],但Application (client) ID和服务主体的一致。
我针对报错中的Object ID执行了以下命令:
az role assignment create --role "Key Vault Secrets User" --assignee b5a[REDACTED] --scope /subscriptions/ade[REDACTED]
也尝试用服务主体的Application ID执行命令:
az role assignment create --role "Key Vault Secrets User" --assignee 14e[REDACTED] --scope /subscriptions/143[REDACTED]
任务配置
steps: - task: AzureKeyVault@2 displayName: 'Azure Key Vault: kv-d-[REDACTED]' inputs: azureSubscription: 'app-[REDACTED]' KeyVaultName: 'kv-d-[REDACTED]' RunAsPreJob: true
其他环境情况
- 已为b5a[REDACTED]分配订阅级Contributor角色
- 生产环境KeyVault采用RBAC权限模式,不能改用访问策略
- 我建了一个用访问策略的测试KeyVault,分配List、Get权限后管道能正常运行
查了很多资料,但大部分都是讲访问策略的,RBAC相关的内容很模糊,实在找不到解决办法了。
内容的提问来源于stack exchange,提问作者Brett Maytom PST
相关产品推荐
相关产品推荐

