使用Azure Runbook拉取运行Docker容器的问题排查
问题
我希望创建一个Runbook来自动化执行Azure中的Docker容器,已采用PowerShell Runbook并编写了如下代码:
# Install Azure CLI Invoke-Expression -Command "Invoke-WebRequest -Uri https://aka.ms/installazurecliwindows -OutFile installazurecli.ps1" .\installazurecli.ps1 # Log in to Azure using the Azure CLI az login --service-principal --username $appId --password $password --tenant $tenantId # Set the ACR details $acrName = "test" $acrResourceGroup = "test" $acrUsername = "test" $acrPassword = "000000000000000000000000000000000000" $aciName = "test" $imageName = "test.azurecr.io/test:test" $aciPort = 80 # Pull the Docker image from Azure Container Registry az acr login --name $acrName az acr repository login --name $acrName docker pull $imageName # Run the Docker container in Azure Container Instances az container create --name $aciName --resource-group $aciResourceGroup --image $imageName --ports $aciPort --registry-login-server $acrName # Get the container status az container show --name $aciName --resource-group $aciResourceGroup --query 'instanceView.currentState.state'
执行该代码后仅生成如下状态输出:
ActivityId : 174593042 ParentActivityId : -1 Activity : Web request status StatusDescription : Number of bytes processed: 7176192 CurrentOperation : PercentComplete : -1 SecondsRemaining : -1 RecordType : Processing
但未向我的Docker注册表发送任何请求,请求协助解决此问题。
解决方案
1. 移除冗余的Azure CLI安装步骤
Azure Automation Runbook环境默认已预装Azure CLI,无需手动安装。原代码中的安装脚本是交互式的,在Runbook中无法自动完成,会阻塞后续命令执行。
修复: 删除以下两行代码:
Invoke-Expression -Command "Invoke-WebRequest -Uri https://aka.ms/installazurecliwindows -OutFile installazurecli.ps1" .\installazurecli.ps1
2. 删除不必要的本地镜像拉取操作
创建Azure Container Instances(ACI)时,Azure会直接从指定的容器注册表拉取镜像,无需在Runbook环境中安装Docker客户端并执行docker pull,且冗余的az acr repository login命令也可移除。
修复: 删除以下代码块:
# Pull the Docker image from Azure Container Registry az acr login --name $acrName az acr repository login --name $acrName docker pull $imageName
3. 补充ACI创建的ACR认证信息
原az container create命令未传入ACR的用户名和密码,导致无法访问私有注册表,这是未向注册表发送请求的核心原因。
修复: 在az container create命令中添加--registry-username和--registry-password参数,传入ACR凭据。
4. 修正未定义的资源组变量
代码中使用了$aciResourceGroup但未定义,需确保该变量与ACR资源组一致或正确赋值。
修正后的完整代码
# Log in to Azure using the Azure CLI az login --service-principal --username $appId --password $password --tenant $tenantId # Set the ACR details $acrName = "test" $acrResourceGroup = "test" $acrUsername = "test" $acrPassword = "000000000000000000000000000000000000" $aciName = "test" $imageName = "test.azurecr.io/test:test" $aciPort = 80 $aciResourceGroup = $acrResourceGroup # 统一资源组变量 # Run the Docker container in Azure Container Instances az container create ` --name $aciName ` --resource-group $aciResourceGroup ` --image $imageName ` --ports $aciPort ` --registry-login-server $acrName ` --registry-username $acrUsername ` --registry-password $acrPassword # Get the container status az container show --name $aciName --resource-group $aciResourceGroup --query 'instanceView.currentState.state'
额外注意事项
- 确保使用的服务主体拥有ACR的
AcrPull权限和ACI的创建权限。 - 敏感信息(如
$appId、$password)应通过Azure Automation的凭据资产存储,避免硬编码。
内容的提问来源于stack exchange,提问作者ahm5
相关产品推荐
相关产品推荐

