使用Terraform创建Azure AKS集群遇MFA认证错误求助
错误回顾
Error: building account: getting authenticated object ID: parsing json result from the Azure CLI: waiting for the Azure CLI: exit status 1: ERROR: AADSTS50076: Due to
a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access '00000003-0000-0000-c000-000000000000'.
│ Trace ID: 3391ac9b-4e8d-43a3-88f5-0cb1093a2d00
│ Correlation ID: fe984fa6-71ff-42d6-b487-7b988a7e1dd6
│ Timestamp: 2022-08-23 13:39:59Z
│ To re-authenticate, please run:
│ az login --scope https://graph.microsoft.com//.default
│
│ with provider["registry.terraform.io/hashicorp/azurerm"],
│ on tf1-provider.tf line 48, in provider "azurerm":
│ 48: provider "azurerm" {
问题根源
1. 目标资源是Microsoft Graph API
错误里的00000003-0000-0000-c000-000000000000是Microsoft Graph API的固定应用ID,Terraform的AzureRM Provider在初始化阶段,需要调用这个API获取当前认证用户的Object ID,以此构建账户上下文。
2. 普通az login的权限范围不覆盖Graph API
常规的az login默认获取的令牌仅包含Azure Resource Manager(ARM)的访问权限,未包含Microsoft Graph API的权限。当Provider尝试调用Graph API时,会触发权限校验失败。
3. 租户MFA策略强制拦截
你的Azure AD管理员已配置针对Microsoft Graph API的**强制多因素认证(MFA)**策略,任何未通过MFA验证的请求都会被拦截。之前的az login要么未完成MFA验证,要么会话中MFA状态已过期,导致请求被拒绝。
4. 指定Scope的登录是补全权限+MFA验证
错误提示的az login --scope https://graph.microsoft.com//.default命令,会强制获取针对Microsoft Graph API的全范围权限令牌,同时触发MFA验证流程。完成后,Azure CLI会话就拥有了访问Graph API的有效权限,Terraform Provider就能顺利获取用户Object ID,完成初始化。
总结
本质是Terraform AzureRM Provider依赖Microsoft Graph API获取用户信息,而你的租户要求访问该API必须通过MFA,且普通登录的权限范围不包含该API,因此必须通过指定Scope的登录完成MFA验证和权限授权。
内容的提问来源于stack exchange,提问作者VivekDev

