Azure Pipeline中TerraformTaskV4无法获取服务主体凭证报错
Azure Pipelines Terraform Init 报错:Identity not found 问题解决
问题场景
将Terraform IaC代码托管在GitHub,使用Azure Pipelines搭建流水线,配置了以下任务:
- task: ms-devlabs.custom-terraform-tasks.custom-terraform-installer-task.TerraformInstaller@0 inputs: terraformVersion: '1.3.7' - task: TerraformTaskV4@4 inputs: provider: 'azurerm' command: 'init' backendServiceArm: 'Svc Conn Name' backendAzureRmResourceGroupName: 'terraform-statefile' backendAzureRmStorageAccountName: 'XXX' backendAzureRmContainerName: 'devtfstatecontainer' backendAzureRmKey: 'tfstate'
执行时触发错误:
Starting: TerraformTaskV4 ============================================================================== Task : Terraform Description : Execute terraform commands to manage resources on AzureRM, Amazon Web Services(AWS) and Google Cloud Platform(GCP) Version : 4.218.21 Author : Microsoft Corporation Help : [Learn more about this task](https://aka.ms/AAf0uqr) ============================================================================== /opt/hostedtoolcache/terraform/1.3.7/x64/terraform init -backend-config=storage_account_name=XXX -backend-config=container_name=XXX -backend-config=key=tfstate -backend-config=resource_group_name=XXX -backend-config=subscription_id=XXX -backend-config=tenant_id=XXX -backend-config=use_msi=true Initializing the backend... ╷ │ Error: Failed to get existing workspaces: Error retrieving keys for Storage Account "tfstate": azure.BearerAuthorizer#WithAuthorization: Failed to refresh the Token for request to https://management.azure.com/subscriptions/XXXX/resourceGroups/XXX/providers/Microsoft.Storage/storageAccounts/XXX/listKeys?api-version=2021-01-01: StatusCode=400 -- Original Error: adal: Refresh request failed. Status Code = '400'. Response body: {"error":"invalid_request","error_description":"Identity not found"} Endpoint http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https%3A%2F%2Fmanagement.azure.com%2F │ │ ╵ ##[error]Error: The process '/opt/hostedtoolcache/terraform/1.3.7/x64/terraform' failed with exit code 1
已确认流水线拥有服务连接的使用权限,但任务无法从手动创建的Service Principal类型服务连接中获取凭证。
问题原因
从执行命令可以看到,TerraformTaskV4自动添加了-backend-config=use_msi=true参数,强制尝试使用托管身份(MSI)进行认证,但当前使用的是手动配置的Service Principal服务连接,两者冲突,导致流水线尝试访问MSI元数据端点时找不到对应身份,触发报错。
解决方案
- 修改TerraformTaskV4配置,禁用MSI
在任务输入中添加useBackendMSI: false参数,明确告诉任务使用Service Principal凭证而非MSI:- task: TerraformTaskV4@4 inputs: provider: 'azurerm' command: 'init' backendServiceArm: 'Svc Conn Name' backendAzureRmResourceGroupName: 'terraform-statefile' backendAzureRmStorageAccountName: 'XXX' backendAzureRmContainerName: 'devtfstatecontainer' backendAzureRmKey: 'tfstate' useBackendMSI: false # 添加此参数禁用MSI认证 - 验证Service Principal权限
确保服务连接对应的Service Principal拥有目标存储账户的权限,至少需要Storage Account Contributor角色,或包含Microsoft.Storage/storageAccounts/listKeys/action权限的自定义角色。 - 确认服务连接配置正确性
检查手动创建的Service Principal服务连接,确保订阅ID、租户ID、客户端ID、客户端密钥均配置正确,且客户端密钥未过期。
内容的提问来源于stack exchange,提问作者Anwar Husain
相关产品推荐
相关产品推荐

