You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Bicep部署Linux VM报错SSH公钥路径参数无效

问题现象

在Bash环境编写Azure Bicep模板,部署关联资源(NIC、VNet、子网、公网IP)+ Linux虚拟机时,所有网络类关联资源均部署成功,仅虚拟机资源部署失败。
返回的核心错误如下:

错误码:InvalidParameter
错误目标:linuxConfiguration.ssh.publicKeys.path
错误提示:Destination path for SSH public keys is currently limited to its default value /home/user/.ssh/authorized_keys due to a known issue in Linux provisioning agent
即使使用官方模板示例中的/home/${adminUsername}/.ssh/authorized_keys路径配置,仍然无法完成部署。

问题根因
  • 模板引用的Canonical UbuntuServer 18.04-LTS镜像已停止官方维护,内置的Linux预配代理(walinuxagent)存在已知未修复bug,会拦截自定义拼接的SSH公钥路径配置
  • 模板osProfile配置存在冗余错误:已配置disablePasswordAuthentication: true禁用密码登录的前提下,错误地将SSH公钥参数赋值给adminPassword字段,触发额外的参数校验逻辑冲突
  • 旧版本镜像的API校验逻辑存在缺陷,通过变量插值生成的SSH路径会被判定为非默认路径,直接拦截部署请求
修复步骤
  • 移除虚拟机资源osProfile配置中多余的adminPassword: adminPasswordKey行,SSH密钥登录场景无需配置该字段
  • 替换已停止维护的Ubuntu 18.04-LTS镜像为仍在支持周期内的官方维护版本,从系统层面修复预配代理的已知bug
  • 若因业务需求必须使用18.04旧镜像,将SSH公钥路径硬编码为与adminUsername完全匹配的固定字符串,不要使用变量插值拼接,绕过API校验拦截
修正后可正常部署的Bicep代码
@description('Name of the VM')
param vmName string = 'stagingLinuxVM'

@description('location for all resources')
param location string = resourceGroup().location

@description('vm sizes allowed RAM & temp storage in GiB per tier (respectively): 0.5/4; 1/4; 2/4; 4/8; 8/16')
@allowed([
  'Standard_B1s'
  'Standard_B1ms'
  'Standard_B2s'
  'Standard_B2ms'
])
param vmSize string = 'Standard_B1s'

@description('Username for the VM')
param adminUsername string

@description('SSH Key for the Virtual Machine')
@secure()
param adminPasswordKey string

@description('name of VNET')
param virtualNetworkName string = 'vnet'

@description('name of the subnet in the virtual network')
param subnetName string = 'Subnet'

param dnsLabelPrefix string = toLower('${vmName}-${uniqueString(resourceGroup().id)}')

var osDiskType = 'Standard_LRS'
var networkInterfaceName = '${vmName}nic'
var addressPrefix = '10.1.0.0/16'
var publicIPAddressName = '${vmName}PublicIP'
var subnetAddressPrefix = '10.1.0.0/24'
var linuxConfiguration = {
  disablePasswordAuthentication: true
  provisionVMAgent: true
  ssh: {
    publicKeys: [
      {
        path: '/home/${adminUsername}/.ssh/authorized_keys'
        keyData: adminPasswordKey
      }
    ]
  }
}

resource nic 'Microsoft.Network/networkInterfaces@2021-08-01' = {
  name: networkInterfaceName
  location: location
  properties: {
    ipConfigurations: [
      {
        name: 'ipconfig1'
        properties: {
          subnet: {
            id: subnet.id
          }
          privateIPAllocationMethod: 'Dynamic'
          publicIPAddress: {
            id: publicIP.id
          }
        }
      }
    ]
  }
}

resource vnet 'Microsoft.Network/virtualNetworks@2021-08-01' = {
  name: virtualNetworkName
  location: location
  properties: {
    addressSpace: {
      addressPrefixes: [
        addressPrefix
      ]
    }
  }
}

resource subnet 'Microsoft.Network/virtualNetworks/subnets@2021-08-01' = {
  parent: vnet
  name: subnetName
  properties: {
    addressPrefix: subnetAddressPrefix
    privateEndpointNetworkPolicies: 'Enabled'
    privateLinkServiceNetworkPolicies: 'Enabled'
  }
}

resource publicIP 'Microsoft.Network/publicIPAddresses@2021-08-01' = {
  name: publicIPAddressName
  location: location
  sku: {
    name: 'Basic'
  }
  properties: {
    publicIPAllocationMethod: 'Dynamic'
    publicIPAddressVersion: 'IPv4'
    dnsSettings: {
      domainNameLabel: dnsLabelPrefix
    }
    idleTimeoutInMinutes: 4
  }
}

resource vm 'Microsoft.Compute/virtualMachines@2021-11-01' = {
  name: vmName
  location: location
  properties: {
    hardwareProfile: {
      vmSize: vmSize
    }
    osProfile: {
      adminUsername: adminUsername
      computerName: vmName
      linuxConfiguration: linuxConfiguration
    }
    storageProfile: {
      imageReference: {
        offer: '0001-com-ubuntu-server-jammy'
        publisher: 'Canonical'
        sku: '22_04-lts-gen2'
        version: 'latest'
      }
      osDisk: {
        createOption: 'FromImage'
        deleteOption: 'Delete'
        diskSizeGB: 32
        osType: 'Linux'
        managedDisk: {
          storageAccountType: osDiskType
        }
      }
    }
    networkProfile: {
      networkInterfaces: [
        {
          id: nic.id
        }
      ]
    }
  }
}

output adminUsername string = adminUsername
output hostname string = publicIP.properties.dnsSettings.fqdn
output sshComand string = 'ssh ${adminUsername}@${publicIP.properties.dnsSettings.fqdn}'
部署验证

修正完成后重新执行部署命令,虚拟机资源会和关联网络资源一起正常创建,部署完成后可以直接使用输出的ssh命令连接虚拟机,公钥会自动写入对应用户的authorized_keys文件中。

内容的提问来源于stack exchange,提问作者Ivana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.02 23:09:31