You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kubernetes YAML中使用Azure Vault密钥配置镜像仓库认证及报错解决

解决Azure私有镜像仓库部署YAML的凭证配置错误

错误原因

你遇到的InvalidRequestContent错误,核心是ImageRegistryCredential类型不支持secret这个配置字段,你用了不符合Azure规范的YAML结构。

修正方案

要通过Key Vault引用ACR凭证,需在imageRegistryCredentials中直接指定username和password的密钥引用,而非嵌套的secret节点。具体操作如下:

  1. 确认Key Vault中的凭证:确保你的Key Vault(示例中为bbb)已存储ACR的用户名和密码两个独立机密(可从Azure门户ACR的「访问密钥」中获取)。
  2. 修正YAML配置:替换错误的imageRegistryCredentials部分,示例如下:
properties:
  containers:
  - name: app
    properties:
      image: myreg.azurecr.io/my-app:latest
      # 保留你的其他容器配置...
      volumeMounts:
      - name: secrets
        mountPath: /mnt/secrets
  volumes:
  - name: secrets
    secret:
      secretName: aaa
      vaultName: bbb
      objectType: ccc
  imageRegistryCredentials:
    - server: myreg.azurecr.io
      username:
        secretRef:
          name: acr-username-secret  # 替换为Key Vault中存储ACR用户名的机密名称
          vaultName: bbb             # 你的Key Vault名称
      password:
        secretRef:
          name: acr-password-secret  # 替换为Key Vault中存储ACR密码的机密名称
          vaultName: bbb             # 你的Key Vault名称
  1. 配置权限:确保部署资源(如Container Apps、AKS)的托管标识拥有Key Vault的「机密读取」权限,否则无法拉取凭证。

更优方案(可选)

如果使用Azure Container Apps,可直接通过托管标识访问ACR,无需存储凭证:

  • 给Container Apps的系统分配标识添加ACR的AcrPull角色
  • YAML中仅保留imageRegistryCredentials的server字段,省略用户名和密码配置:
imageRegistryCredentials:
  - server: myreg.azurecr.io

内容的提问来源于stack exchange,提问作者Siamak Ferdos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 16:58:32