Azure Pipeline执行New-AzRoleDefinition返回Forbidden错误求助
Azure Pipeline创建AzRoleDefinition时出现Forbidden错误排查
问题描述
尝试通过Azure Pipeline的YAML脚本创建自定义Azure角色定义,执行New-AzRoleDefinition时返回"Forbidden"错误,导致任务失败。
Pipeline YAML脚本
name: 'Powershell' trigger: none pr: none pool: vmImage: ubuntu-latest jobs: - job: my_job timeoutInMinutes: 120 cancelTimeoutInMinutes: 3 pool: 'Azure Pipelines' steps: - task: AzurePowerShell@5 displayName: 'test' inputs: azureSubscription: 'azureinfo' azurePowerShellVersion: latestVersion ScriptType: 'InlineScript' workingDirectory: '$(System.DefaultWorkingDirectory)/powershell' Inline: | $myRoleImageCreationPath = ".\myRoleImageCreation.json" $subscriptionID = (Get-AzContext).Subscription.Id $imageResourceGroup = 'RG-WE-AVD-ACG' $imageRoleDefName="Custom Role AIB Pipe" $Content = Get-Content -Path $myRoleImageCreationPath -Raw $Content = $Content -replace '<subscriptionID>', $subscriptionID $Content = $Content -replace '<rgName>', $imageResourceGroup $Content = $Content -replace 'Azure Image Builder Service Image Creation Role', $imageRoleDefName $Content | Out-File -FilePath $myRoleImageCreationPath -Force New-AzRoleDefinition -InputFile $myRoleImageCreationPath
错误日志
2023-04-02T18:45:01.9886433Z ##[section]Starting: test 2023-04-02T18:45:01.9891615Z ============================================================================== 2023-04-02T18:45:01.9891784Z Task : Azure PowerShell 2023-04-02T18:45:01.9891873Z Description : Run a PowerShell script within an Azure environment 2023-04-02T18:45:01.9891977Z Version : 5.218.0 2023-04-02T18:45:01.9892040Z Author : Microsoft Corporation 2023-04-02T18:45:01.9892134Z Help : https://aka.ms/azurepowershelltroubleshooting 2023-04-02T18:45:01.9892229Z ============================================================================== 2023-04-02T18:45:02.3947087Z Generating script. 2023-04-02T18:45:02.3979550Z [command]/usr/bin/pwsh -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command . '/home/vsts/work/_temp/20a4d47f-6ea6-4006-ad79-4134328fd8dd.ps1' 2023-04-02T18:45:02.4042584Z Saved! 2023-04-02T18:45:03.9853492Z ##[command]Import-Module -Name /usr/share/az_9.3.0/Az.Accounts/2.12.1/Az.Accounts.psd1 -Global 2023-04-02T18:45:04.6779259Z ##[command]Clear-AzContext -Scope Process 2023-04-02T18:45:04.8075005Z ##[command]Clear-AzContext -Scope CurrentUser -Force -ErrorAction SilentlyContinue 2023-04-02T18:45:05.1564251Z ##[command]Connect-AzAccount -ServicePrincipal -Tenant 55a3fdf6-67a6-48d5-b825-1eaabecb27be -Credential System.Management.Automation.PSCredential -Environment AzureCloud @processScope 2023-04-02T18:45:05.9367076Z ##[command] Set-AzContext -SubscriptionId 6810f60a-9fbe-413a-bd28-e7e813507521 -TenantId 55a3fdf6-67a6-48d5-b825-1eaabecb27be 2023-04-02T18:45:09.0193054Z [31;1mNew-AzRoleDefinition: [0m/home/vsts/work/_temp/20a4d47f-6ea6-4006-ad79-4134328fd8dd.ps1:15 2023-04-02T18:45:09.0193738Z [36;1mLine | 2023-04-02T18:45:09.0194624Z [36;1m 15 | [0m [36;1mNew-AzRoleDefinition -InputFile $myRoleImageCreationPath[0m 2023-04-02T18:45:09.0195037Z [36;1m | [31;1m ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 2023-04-02T18:45:09.0195344Z [31;1m[36;1m | [31;1mOperation returned an invalid status code 'Forbidden' 2023-04-02T18:45:09.0195628Z [0m 2023-04-02T18:45:09.1158937Z ##[error]PowerShell exited with code '1'. 2023-04-02T18:45:09.1187370Z ##[section]Finishing: test
原因分析
错误提示"Forbidden",说明执行New-AzRoleDefinition的身份(即Pipeline使用的服务主体)没有足够权限创建角色定义。创建自定义Azure角色需要Microsoft.Authorization/roleDefinitions/write权限,该权限通常包含在以下内置角色中:
- 所有者
- 用户访问管理员
如果服务主体没有被分配以上角色,或者自定义角色未包含该权限,就会触发Forbidden错误。
解决步骤
确认服务主体权限
登录Azure门户,找到目标订阅,进入「访问控制(IAM)」页面,搜索Pipeline中azureSubscription对应的服务主体名称,查看其已分配的角色,确认是否包含所有者或用户访问管理员角色。添加必要权限
如果服务主体没有对应权限,在订阅级别(或角色定义的目标范围)添加角色分配:- 选择「添加」→「添加角色分配」
- 选择「所有者」或「用户访问管理员」角色,然后选中对应的服务主体完成分配。
或者创建一个自定义角色,包含Microsoft.Authorization/roleDefinitions/write权限,再分配给该服务主体。
验证权限生效
重新运行Pipeline,确认New-AzRoleDefinition命令可以正常执行。
内容的提问来源于stack exchange,提问作者themrt93
相关产品推荐
相关产品推荐

