You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure File Copy任务无法完成,403权限错误排查求助

问题描述

在Azure DevOps中使用Azure File Copy任务,将Git中的制品复制到订阅下的Blob存储时,任务始终无法完成并一直处于运行状态,查看执行日志后出现403(AuthorizationFailure)错误,怀疑是订阅缺少Blob存储的写入权限,需确认是否存在配置错误。

任务配置

steps:
- task: AzureFileCopy@5
  displayName: 'AzureBlob File Copy'
  inputs:
    SourcePath: '$(System.DefaultWorkingDirectory)/_ADF-MRSG-Tide-Continuous-Integration-Build/ArmTemplates'
    azureSubscription: 'BDAP-PRD-PIPELINE-CONN (xxxxxxxx)'
    Destination: AzureBlob
    storage: mrsgtideprdwedev
    ContainerName: 'azure-artifacts'

执行日志

2023-01-12T17:01:15.4423974Z ##[section]Starting: AzureBlob File Copy
2023-01-12T17:01:15.4550000Z ==============================================================================
2023-01-12T17:01:15.4550253Z Task         : Azure file copy
2023-01-12T17:01:15.4550388Z Description  : Copy files to Azure Blob Storage or virtual machines
2023-01-12T17:01:15.4550590Z Version      : 5.210.1
2023-01-12T17:01:15.4550713Z Author       : Microsoft Corporation
2023-01-12T17:01:15.4550863Z Help         : https://docs.microsoft.com/azure/devops/pipelines/tasks/deploy/azure-file-copy
2023-01-12T17:01:15.4551268Z ==============================================================================
2023-01-12T17:01:20.7123632Z ##[command]Import-Module -Name C:\Modules\az_9.0.1\Az.Accounts\2.10.4\Az.Accounts.psd1 -Global
2023-01-12T17:01:22.8437792Z ##[warning]Both Az and AzureRM modules were detected on this machine. Az and AzureRM modules cannot be imported in the same session or used in the same script or runbook. If you are running PowerShell in an environment you control you can use the 'Uninstall-AzureRm' cmdlet to remove all AzureRm modules from your machine. If you are running in Azure Automation, take care that none of your runbooks import both Az and AzureRM modules. More information can be found here: https://aka.ms/azps-migration-guide
2023-01-12T17:01:31.6898708Z ##[command]Clear-AzContext -Scope CurrentUser -Force -ErrorAction SilentlyContinue
2023-01-12T17:01:32.5179394Z ##[command]Clear-AzContext -Scope Process
2023-01-12T17:01:32.5180271Z ##[command]Connect-AzAccount -ServicePrincipal -Tenant xxx -Credential System.Management.Automation.PSCredential -Environment AzureCloud @processScope
2023-01-12T17:01:35.1239900Z ##[command] Set-AzContext -SubscriptionId xxx -TenantId xxx
2023-01-12T17:01:36.0411697Z ##[command]Import-Module -Name C:\Modules\az_9.0.1\Az.Resources\6.3.1\Az.Resources.psd1 -Global
2023-01-12T17:01:39.1422423Z ##[command]Import-Module -Name C:\Modules\az_9.0.1\Az.Storage\5.0.0\Az.Storage.psd1 -Global
2023-01-12T17:01:41.0099745Z ##[command]Import-Module -Name C:\Modules\az_9.0.1\Az.Compute\5.0.0\Az.Compute.psd1 -Global
2023-01-12T17:01:44.7529810Z ##[command]Import-Module -Name C:\Modules\az_9.0.1\Az.Network\5.0.0\Az.Network.psd1 -Global
2023-01-12T17:01:45.5713749Z ##[warning]The names of some imported commands from the module 'Microsoft.Azure.PowerShell.Cmdlets.Network' include unapproved verbs that might make them less discoverable. To find the commands with unapproved verbs, run the Import-Module command again with the Verbose parameter. For a list of approved verbs, type Get-Verb.
2023-01-12T17:01:45.8587032Z ##[warning]The names of some imported commands from the module 'Az.Network' include unapproved verbs that might make them less discoverable. To find the commands with unapproved verbs, run the Import-Module command again with the Verbose parameter. For a list of approved verbs, type Get-Verb.
2023-01-12T17:11:24.8085548Z ##[command]Disconnect-AzAccount -Scope Process -ErrorAction Stop
2023-01-12T17:11:24.8364623Z ##[command]Clear-AzContext -Scope Process -ErrorAction Stop
2023-01-12T17:11:24.9976554Z ##[error]This request is not authorized to perform this operation.
RequestId:0e6ffe85-601e-0047-3da8-2639da000000
Time:2023-01-12T17:11:24.5146395Z
Status: 403 (This request is not authorized to perform this operation.)
ErrorCode: AuthorizationFailure

Content:
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationFailure</Code><Message>This request is not authorized to perform this operation.
RequestId:0e6ffe85-601e-0047-3da8-2639da000000
Time:2023-01-12T17:11:24.5146395Z</Message></Error>

Headers:
x-ms-request-id: 0e6ffe85-601e-0047-3da8-2639da000000
x-ms-client-request-id: 069ac45e-6638-4d55-9ece-39522ed6f5c5
x-ms-error-code: AuthorizationFailure
Content-Length: 246
Content-Type: application/xml
Date: Thu, 12 Jan 2023 17:11:24 GMT
Server: Microsoft-HTTPAPI/2.0

2023-01-12T17:11:25.0733282Z ##[section]Finishing: AzureBlob File Copy
排查与解决方案
  • 检查服务主体权限:Azure DevOps中配置的服务连接BDAP-PRD-PIPELINE-CONN对应的服务主体,需要在目标存储账户mrsgtideprdwedev上拥有足够的写入权限,推荐添加存储Blob数据参与者或存储账户参与者角色。操作路径:Azure门户→目标存储账户→访问控制(IAM)→添加角色分配,选择对应角色并指定该服务主体。
  • 验证服务连接有效性:确认Azure DevOps中的服务连接已正确关联目标订阅,且服务主体的凭据(客户端ID、密钥)未过期。可在Azure DevOps项目设置→服务连接中,对该连接执行测试操作,验证连通性。
  • 检查存储账户网络限制:若存储账户配置了防火墙或虚拟网络规则,需确保Azure DevOps代理的IP地址被允许访问,或者开启“允许受信任的Microsoft服务访问此存储账户”选项,避免代理被拦截。
  • 清理模块冲突:日志提示代理机器同时存在Az和AzureRM模块,虽不是403错误的直接原因,但可能引发潜在问题,建议卸载AzureRM模块,避免模块冲突影响任务执行。

内容的提问来源于stack exchange,提问作者Brian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 20:55:59