Azure函数应用System Assigned Managed Identity配置问题求助
问题背景
我有一个函数应用,需要为其授予写入Blob/Table存储的权限。已开启System Assigned Managed Identity,并为其配置了以下权限(作用域为目标存储账户):
Storage Account Contributor Storage Blob Data Owner Storage Table Data Contributor Storage Queue Data Contributor
问题出现与尝试过程
移除AZURE_CLIENT_ID、AZURE_CLIENT_SECRET和AZURE_TENANT_ID环境变量后,通过API Management触发函数时收到环境配置错误:
Executed 'Create' (Failed, Duration=1406ms)EnvironmentCredential authentication unavailable. Environment variables are not fully configured. See the troubleshooting guide for more information. https://aka.ms/azsdk/net/identity/environmentcredential/troubleshoot
相关文档提示需重新添加这些变量,但根据之前的建议本应无需配置。我困惑的是:明明已经通过角色分配给托管标识授予了权限,为何还要额外创建应用注册这类资源来实现相同权限?Azure要求必须包含的三个变量为:
AZURE_CLIENT_IDAZURE_CLIENT_SECRETAZURE_TENANT_ID
尝试创建应用注册并配置如下,但未达预期:
App Registration: API permissions -> Microsoft.Graph User.Read Authentication -> https://<mydomain>.onmicrosoft.com/.auth/login/aad/callback -> ID Tokens -> Accounts in this organization Secrets -> 生成新密钥用于AZURE_CLIENT_SECRET Roles & Admissions -> Cloud application administrator
将AZURE_CLIENT_ID设为应用注册ID、AZURE_CLIENT_SECRET设为应用密钥、AZURE_TENANT_ID设为租户ID后,代码中执行:
var tableUri = new Uri(string.Format("https://{0}.table.core.windows.net/", storageAccountName)); var credential = new DefaultAzureCredential(options); services.AddScoped(x => new TableServiceClient(tableUri, credential));
此时访问表存储出现401认证错误:
Executed 'Create' (Failed, Id=<id>, Duration=2108ms)Server failed to authenticate the request. Please refer to the information in the www-authenticate header.RequestId:<id>Time:2022-10-21T12:15:21.6998519ZStatus: 401 (Server failed to authenticate the request. Please refer to the information in the www-authenticate header.)ErrorCode: InvalidAuthenticationInfoContent:{"odata.error":{"code":"InvalidAuthenticationInfo","message":{"lang":"en-US","value":"Server failed to authenticate the request. Please refer to the information in the www-authenticate header.\nRequestId:<id>\nTime:2022-10-21T12:15:21.6998519Z"}}}Headers:Server: Microsoft-HTTPAPI/2.0x-ms-request-id: <id>x-ms-error-code: REDACTEDWWW-Authenticate: Bearer authorization_uri=https://login.microsoftonline.com/<tenant_id>/oauth2/authorize resource_id=https://storage.azure.comDate: Fri, 21 Oct 2022 12:15:21 GMTContent-Length: 279Content-Type: application/json
将认证重定向URL改为https://storage.azure.com后,又出现403权限不匹配错误:
Executed 'Create' (Failed, Id=<id>, Duration=2349ms)This request is not authorized to perform this operation using this permission.RequestId:<request>Time:2022-10-21T13:14:29.0955823ZStatus: 403 (Forbidden)ErrorCode: AuthorizationPermissionMismatchContent:{"odata.error":{"code":"AuthorizationPermissionMismatch","message":{"lang":"en-US","value":"This request is not authorized to perform this operation using this permission.\nRequestId:<id>\nTime:2022-10-21T13:14:29.0955823Z"}}}Headers:Cache-Control: no-cacheTransfer-Encoding: chunkedServer: Windows-Azure-Table/1.0,Microsoft-HTTPAPI/2.0x-ms-request-id: <id>x-ms-client-request-id: <id>x-ms-version: REDACTEDX-Content-Type-Options: REDACTEDDate: Fri, 21 Oct 2022 13:14:28 GMTContent-Type: application/json; odata=minimalmetadata; streaming=true; charset=utf-8
问题解决
经排查,核心问题出在代码实现上:开发团队虽强调使用DefaultAzureCredential,但实际代码中明确调用了new EnvironmentCredential(),该类强制要求设置AZURE_CLIENT_ID;即使使用DefaultAzureCredential,它会按优先级尝试认证方式,当检测到AZURE_CLIENT_ID已设置时,会跳过托管标识认证,导致已配置的托管标识权限无法生效。
内容的提问来源于stack exchange,提问作者Jake Boomgaarden

