You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure自动化Runbook混合Worker调用Get-VICredentialStoreItem登录vCenter失败

问题:Azure自动化混合Worker执行PowerCLI脚本时无法访问共享路径的凭据文件

我们通过Azure自动化Runbook结合混合Worker,从本地vCenter环境收集信息。脚本在混合Worker服务器本地运行正常,但通过Runbook执行时,调用Get-VICredentialStoreItem读取共享路径\\mgmtserver.domain.local\Credentials\pwd.xml的凭据失败,报错找不到指定路径,同时提示无法进行用户交互请求凭据。

相关脚本:

$date = get-date -format dd-MM-yyyy

#Load Module and connect to vCenter

Get-Module -Name VMware.PowerCLI.VCenter* -ListAvailable | Import-Module
Get-Module -Name VMware.Sdk* -ListAvailable | Import-Module 
Get-Module -Name VMware.VimAutomation.Core | Import-Module

Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -Confirm:$false

Set-PowerCLIConfiguration -Scope User -ParticipateInCEIP $false -Confirm:$false
 
$Credentials = Get-VICredentialStoreItem -Host "server1.domain.local" -File "\\mgmtserver.domain.local\Credentials\pwd.xml"

Connect-viserver -server "server1.domain.local" -User $Credentials.User -Password $Credentials.Password

$datastore = "\\mgmtserver.domain.local\myshare2\VMware-Corp-Datastores.csv"

#add VMtools details 
New-VIProperty -Name ToolsVersion -ObjectType VirtualMachine -ValueFromExtensionProperty 'Config.tools.ToolsVersion' -Force 
New-VIProperty -Name ToolsVersionStatus -ObjectType VirtualMachine -ValueFromExtensionProperty 'Guest.ToolsVersionStatus' -Force

#export datastore list
get-datastore | Select Name, Datacenter, CapacityGB, FreeSpaceGB | export-csv $datastore -NoTypeInformation -UseCulture

disconnect-viserver -Server * -confirm:$false

原因及解决方案

1. 混合Worker运行账户权限不足

Azure自动化混合Worker默认以Local System账户运行,该账户没有访问域内共享文件夹的权限。而本地运行脚本时使用的是有权限的域账户,因此能正常访问共享文件。

解决步骤:

  • 打开混合Worker所在服务器的「服务」控制台,找到Microsoft Azure Automation Hybrid Worker服务
  • 右键点击服务 → 属性 → 切换到「登录」选项卡
  • 选择「此账户」,输入拥有共享文件夹访问权限的域账户及密码
  • 重启该服务后,重新执行Runbook

2. UNC路径访问问题

  • 确认混合Worker服务器能正常解析共享服务器的域名,可尝试用IP地址替换域名测试(如\\192.168.x.x\Credentials\pwd.xml),排除DNS解析故障
  • 检查共享文件夹的NTFS权限和共享权限,确保指定的域账户拥有读取权限

3. 避免交互式凭据请求

当Get-VICredentialStoreItem找不到指定文件时,会尝试弹出交互式窗口请求凭据,但混合Worker运行在后台无交互桌面,因此报错。可在脚本中提前校验文件是否存在:

$credFilePath = "\\mgmtserver.domain.local\Credentials\pwd.xml"
if (-not (Test-Path -Path $credFilePath -PathType Leaf)) {
    throw "无法找到凭据文件:$credFilePath,请检查路径或权限"
}
$Credentials = Get-VICredentialStoreItem -Host "server1.domain.local" -File $credFilePath

4. 更安全的替代方案:使用Azure自动化凭据资产

不要通过共享文件存储敏感凭据,直接在Azure自动化账户中创建「凭据资产」,存储vCenter的用户名和密码,然后在Runbook中调用:

# 从Azure自动化凭据资产中获取凭据
$vCenterCred = Get-AutomationPSCredential -Name "VCenterAdminCredential"

# 连接vCenter
Connect-VIServer -Server "server1.domain.local" -Credential $vCenterCred

这种方式无需依赖共享路径,且Azure会加密存储凭据,安全性更高。

内容的提问来源于stack exchange,提问作者A A

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 22:30:48