You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure CLI/VS Code插件部署Function App遇401未授权求助

Azure CLI执行func azure functionapp list-functions返回401未授权的解决方法

问题背景

部署Azure Python Timer Trigger Function App后,执行func azure functionapp list-functions命令始终返回401未授权错误,已尝试重登Azure CLI、轮换存储密钥、重新部署函数应用等操作无效。

涉及配置

function.json

{
  "scriptFile": "__init__.py",
  "bindings": [
    {
      "name": "mytimer",
      "type": "timerTrigger",
      "direction": "in",
      "schedule": "0 */5 * * * *"
    }
  ]
}

Terraform部署代码

resource "azurerm_linux_function_app" "data-extract-fa" {
  name                = "${var.prefix}-function-app"
  resource_group_name = var.rg
  location            = var.location

  storage_account_name       = azurerm_storage_account.data-extract-sa.name
  storage_account_access_key = azurerm_storage_account.data-extract-sa.primary_access_key
  service_plan_id            = azurerm_service_plan.data-extract-sp.id
  identity {
    type = "SystemAssigned"
  }
  app_settings = {
    AzureWebJobsDisableHomepage    = true
    APPINSIGHTS_INSTRUMENTATIONKEY = azurerm_application_insights.data-extract-ai.instrumentation_key
    SCM_DO_BUILD_DURING_DEPLOYMENT = true
  }

  site_config {
    application_stack {
      python_version = "3.9"
    }
  }

  dynamic "connection_string" {
    for_each = { for tuple in regexall("(.*)=(.*)", file("../functions/.env")) : tuple[0] => tuple[1] }
    content {
        name = connection_string.key
        type = "Custom"
        value = connection_string.value
    }
  }
}

解决步骤

  1. 确认订阅与权限

    • 执行az account show验证当前CLI登录的订阅是否为函数应用所在订阅,若不是则切换:az account set --subscription <订阅ID/名称>
    • 检查当前账户是否拥有Function App Contributor或更高权限,权限不足会导致401。
  2. 修复存储连接字符串
    Timer Trigger依赖AzureWebJobsStorage连接字符串访问存储账户维护触发器状态,Terraform部署时可能未正确生成该配置。在Terraform的app_settings中显式添加:

    app_settings = {
      AzureWebJobsDisableHomepage    = true
      APPINSIGHTS_INSTRUMENTATIONKEY = azurerm_application_insights.data-extract-ai.instrumentation_key
      SCM_DO_BUILD_DURING_DEPLOYMENT = true
      AzureWebJobsStorage            = "DefaultEndpointsProtocol=https;AccountName=${azurerm_storage_account.data-extract-sa.name};AccountKey=${azurerm_storage_account.data-extract-sa.primary_access_key};EndpointSuffix=core.windows.net"
    }
    

    重新部署后,执行func azure functionapp publish <函数名> --show-config确认连接字符串正确。

  3. 配置系统身份权限
    函数应用启用了系统分配身份,需为该身份授予存储账户的Storage Blob Data Contributor权限:

    # 获取函数应用系统身份对象ID
    az functionapp identity show --name <函数名> --resource-group <资源组名> --query principalId -o tsv
    # 分配权限
    az role assignment create --assignee <身份对象ID> --role "Storage Blob Data Contributor" --scope <存储账户资源ID>
    
  4. 清除本地凭据缓存
    本地CLI缓存的失效凭据可能导致401,执行以下命令重置:

    az cache purge
    func azure logout
    func azure login
    
  5. 重置SCM部署凭据
    若使用VS Code插件或Git部署,SCM凭据过期也会引发授权问题。在Azure门户的函数应用>部署中心>FTPS凭据中重置凭据,重新登录VS Code即可。

内容的提问来源于stack exchange,提问作者Alex Dembo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 03:23:31