You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipeline中TerraformTaskV4无法获取服务主体凭证报错

Azure Pipelines Terraform Init 报错:Identity not found 问题解决

问题场景

将Terraform IaC代码托管在GitHub,使用Azure Pipelines搭建流水线,配置了以下任务:

- task: ms-devlabs.custom-terraform-tasks.custom-terraform-installer-task.TerraformInstaller@0
  inputs:
    terraformVersion: '1.3.7'

- task: TerraformTaskV4@4
  inputs:
    provider: 'azurerm'
    command: 'init'
    backendServiceArm: 'Svc Conn Name'
    backendAzureRmResourceGroupName: 'terraform-statefile'
    backendAzureRmStorageAccountName: 'XXX'
    backendAzureRmContainerName: 'devtfstatecontainer'
    backendAzureRmKey: 'tfstate'

执行时触发错误:

Starting: TerraformTaskV4
==============================================================================
Task         : Terraform
Description  : Execute terraform commands to manage resources on AzureRM, Amazon Web Services(AWS) and Google Cloud Platform(GCP)
Version      : 4.218.21
Author       : Microsoft Corporation
Help         : [Learn more about this task](https://aka.ms/AAf0uqr)
==============================================================================
/opt/hostedtoolcache/terraform/1.3.7/x64/terraform init -backend-config=storage_account_name=XXX -backend-config=container_name=XXX -backend-config=key=tfstate -backend-config=resource_group_name=XXX -backend-config=subscription_id=XXX -backend-config=tenant_id=XXX -backend-config=use_msi=true


Initializing the backend...
╷
│ Error: Failed to get existing workspaces: Error retrieving keys for Storage Account "tfstate": azure.BearerAuthorizer#WithAuthorization: Failed to refresh the Token for request to https://management.azure.com/subscriptions/XXXX/resourceGroups/XXX/providers/Microsoft.Storage/storageAccounts/XXX/listKeys?api-version=2021-01-01: StatusCode=400 -- Original Error: adal: Refresh request failed. Status Code = '400'. Response body: {"error":"invalid_request","error_description":"Identity not found"} Endpoint http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https%3A%2F%2Fmanagement.azure.com%2F
│ 
│ 
╵

##[error]Error: The process '/opt/hostedtoolcache/terraform/1.3.7/x64/terraform' failed with exit code 1

已确认流水线拥有服务连接的使用权限,但任务无法从手动创建的Service Principal类型服务连接中获取凭证。

问题原因

从执行命令可以看到,TerraformTaskV4自动添加了-backend-config=use_msi=true参数,强制尝试使用托管身份(MSI)进行认证,但当前使用的是手动配置的Service Principal服务连接,两者冲突,导致流水线尝试访问MSI元数据端点时找不到对应身份,触发报错。

解决方案

  1. 修改TerraformTaskV4配置,禁用MSI
    在任务输入中添加useBackendMSI: false参数,明确告诉任务使用Service Principal凭证而非MSI:
    - task: TerraformTaskV4@4
      inputs:
        provider: 'azurerm'
        command: 'init'
        backendServiceArm: 'Svc Conn Name'
        backendAzureRmResourceGroupName: 'terraform-statefile'
        backendAzureRmStorageAccountName: 'XXX'
        backendAzureRmContainerName: 'devtfstatecontainer'
        backendAzureRmKey: 'tfstate'
        useBackendMSI: false  # 添加此参数禁用MSI认证
    
  2. 验证Service Principal权限
    确保服务连接对应的Service Principal拥有目标存储账户的权限,至少需要Storage Account Contributor角色,或包含Microsoft.Storage/storageAccounts/listKeys/action权限的自定义角色。
  3. 确认服务连接配置正确性
    检查手动创建的Service Principal服务连接,确保订阅ID、租户ID、客户端ID、客户端密钥均配置正确,且客户端密钥未过期。

内容的提问来源于stack exchange,提问作者Anwar Husain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 14:52:34