You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipeline执行New-AzRoleDefinition返回Forbidden错误求助

Azure Pipeline创建AzRoleDefinition时出现Forbidden错误排查

问题描述

尝试通过Azure Pipeline的YAML脚本创建自定义Azure角色定义,执行New-AzRoleDefinition时返回"Forbidden"错误,导致任务失败。

Pipeline YAML脚本

name: 'Powershell'
trigger: none
pr: none

pool:
  vmImage: ubuntu-latest

jobs:
  - job: my_job
    timeoutInMinutes: 120
    cancelTimeoutInMinutes: 3
    pool: 'Azure Pipelines'
    steps:

    - task: AzurePowerShell@5
      displayName: 'test'
      inputs:
        azureSubscription: 'azureinfo'
        azurePowerShellVersion: latestVersion
        ScriptType: 'InlineScript'
        workingDirectory: '$(System.DefaultWorkingDirectory)/powershell'
        Inline: |
          $myRoleImageCreationPath = ".\myRoleImageCreation.json"
          $subscriptionID = (Get-AzContext).Subscription.Id
          $imageResourceGroup = 'RG-WE-AVD-ACG'
          $imageRoleDefName="Custom Role AIB Pipe"

          $Content = Get-Content -Path $myRoleImageCreationPath -Raw
          $Content = $Content -replace '<subscriptionID>', $subscriptionID
          $Content = $Content -replace '<rgName>', $imageResourceGroup
          $Content = $Content -replace 'Azure Image Builder Service Image Creation Role', $imageRoleDefName
          $Content | Out-File -FilePath $myRoleImageCreationPath -Force
        
          New-AzRoleDefinition -InputFile $myRoleImageCreationPath

错误日志

2023-04-02T18:45:01.9886433Z ##[section]Starting: test
2023-04-02T18:45:01.9891615Z ==============================================================================
2023-04-02T18:45:01.9891784Z Task         : Azure PowerShell
2023-04-02T18:45:01.9891873Z Description  : Run a PowerShell script within an Azure environment
2023-04-02T18:45:01.9891977Z Version      : 5.218.0
2023-04-02T18:45:01.9892040Z Author       : Microsoft Corporation
2023-04-02T18:45:01.9892134Z Help         : https://aka.ms/azurepowershelltroubleshooting
2023-04-02T18:45:01.9892229Z ==============================================================================
2023-04-02T18:45:02.3947087Z Generating script.
2023-04-02T18:45:02.3979550Z [command]/usr/bin/pwsh -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command . '/home/vsts/work/_temp/20a4d47f-6ea6-4006-ad79-4134328fd8dd.ps1'
2023-04-02T18:45:02.4042584Z Saved!
2023-04-02T18:45:03.9853492Z ##[command]Import-Module -Name /usr/share/az_9.3.0/Az.Accounts/2.12.1/Az.Accounts.psd1 -Global
2023-04-02T18:45:04.6779259Z ##[command]Clear-AzContext -Scope Process
2023-04-02T18:45:04.8075005Z ##[command]Clear-AzContext -Scope CurrentUser -Force -ErrorAction SilentlyContinue
2023-04-02T18:45:05.1564251Z ##[command]Connect-AzAccount -ServicePrincipal -Tenant 55a3fdf6-67a6-48d5-b825-1eaabecb27be -Credential System.Management.Automation.PSCredential -Environment AzureCloud @processScope
2023-04-02T18:45:05.9367076Z ##[command] Set-AzContext -SubscriptionId 6810f60a-9fbe-413a-bd28-e7e813507521 -TenantId 55a3fdf6-67a6-48d5-b825-1eaabecb27be
2023-04-02T18:45:09.0193054Z [31;1mNew-AzRoleDefinition: [0m/home/vsts/work/_temp/20a4d47f-6ea6-4006-ad79-4134328fd8dd.ps1:15
2023-04-02T18:45:09.0193738Z [36;1mLine |
2023-04-02T18:45:09.0194624Z [36;1m  15 | [0m [36;1mNew-AzRoleDefinition -InputFile $myRoleImageCreationPath[0m
2023-04-02T18:45:09.0195037Z [36;1m     | [31;1m ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2023-04-02T18:45:09.0195344Z [31;1m[36;1m     | [31;1mOperation returned an invalid status code 'Forbidden'
2023-04-02T18:45:09.0195628Z [0m
2023-04-02T18:45:09.1158937Z ##[error]PowerShell exited with code '1'.
2023-04-02T18:45:09.1187370Z ##[section]Finishing: test

原因分析

错误提示"Forbidden",说明执行New-AzRoleDefinition的身份(即Pipeline使用的服务主体)没有足够权限创建角色定义。创建自定义Azure角色需要Microsoft.Authorization/roleDefinitions/write权限,该权限通常包含在以下内置角色中:

  • 所有者
  • 用户访问管理员
    如果服务主体没有被分配以上角色,或者自定义角色未包含该权限,就会触发Forbidden错误。

解决步骤

  1. 确认服务主体权限
    登录Azure门户,找到目标订阅,进入「访问控制(IAM)」页面,搜索Pipeline中azureSubscription对应的服务主体名称,查看其已分配的角色,确认是否包含所有者或用户访问管理员角色。

  2. 添加必要权限
    如果服务主体没有对应权限,在订阅级别(或角色定义的目标范围)添加角色分配:

    • 选择「添加」→「添加角色分配」
    • 选择「所有者」或「用户访问管理员」角色,然后选中对应的服务主体完成分配。
      或者创建一个自定义角色,包含Microsoft.Authorization/roleDefinitions/write权限,再分配给该服务主体。
  3. 验证权限生效
    重新运行Pipeline,确认New-AzRoleDefinition命令可以正常执行。


内容的提问来源于stack exchange,提问作者themrt93

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 21:07:04