Azure Bicep部署Linux VM报错SSH公钥路径参数无效
问题现象
在Bash环境编写Azure Bicep模板,部署关联资源(NIC、VNet、子网、公网IP)+ Linux虚拟机时,所有网络类关联资源均部署成功,仅虚拟机资源部署失败。
返回的核心错误如下:
错误码:
InvalidParameter
错误目标:linuxConfiguration.ssh.publicKeys.path
错误提示:Destination path for SSH public keys is currently limited to its default value /home/user/.ssh/authorized_keys due to a known issue in Linux provisioning agent
即使使用官方模板示例中的/home/${adminUsername}/.ssh/authorized_keys路径配置,仍然无法完成部署。
问题根因
- 模板引用的
Canonical UbuntuServer 18.04-LTS镜像已停止官方维护,内置的Linux预配代理(walinuxagent)存在已知未修复bug,会拦截自定义拼接的SSH公钥路径配置 - 模板osProfile配置存在冗余错误:已配置
disablePasswordAuthentication: true禁用密码登录的前提下,错误地将SSH公钥参数赋值给adminPassword字段,触发额外的参数校验逻辑冲突 - 旧版本镜像的API校验逻辑存在缺陷,通过变量插值生成的SSH路径会被判定为非默认路径,直接拦截部署请求
修复步骤
- 移除虚拟机资源osProfile配置中多余的
adminPassword: adminPasswordKey行,SSH密钥登录场景无需配置该字段 - 替换已停止维护的Ubuntu 18.04-LTS镜像为仍在支持周期内的官方维护版本,从系统层面修复预配代理的已知bug
- 若因业务需求必须使用18.04旧镜像,将SSH公钥路径硬编码为与adminUsername完全匹配的固定字符串,不要使用变量插值拼接,绕过API校验拦截
修正后可正常部署的Bicep代码
@description('Name of the VM') param vmName string = 'stagingLinuxVM' @description('location for all resources') param location string = resourceGroup().location @description('vm sizes allowed RAM & temp storage in GiB per tier (respectively): 0.5/4; 1/4; 2/4; 4/8; 8/16') @allowed([ 'Standard_B1s' 'Standard_B1ms' 'Standard_B2s' 'Standard_B2ms' ]) param vmSize string = 'Standard_B1s' @description('Username for the VM') param adminUsername string @description('SSH Key for the Virtual Machine') @secure() param adminPasswordKey string @description('name of VNET') param virtualNetworkName string = 'vnet' @description('name of the subnet in the virtual network') param subnetName string = 'Subnet' param dnsLabelPrefix string = toLower('${vmName}-${uniqueString(resourceGroup().id)}') var osDiskType = 'Standard_LRS' var networkInterfaceName = '${vmName}nic' var addressPrefix = '10.1.0.0/16' var publicIPAddressName = '${vmName}PublicIP' var subnetAddressPrefix = '10.1.0.0/24' var linuxConfiguration = { disablePasswordAuthentication: true provisionVMAgent: true ssh: { publicKeys: [ { path: '/home/${adminUsername}/.ssh/authorized_keys' keyData: adminPasswordKey } ] } } resource nic 'Microsoft.Network/networkInterfaces@2021-08-01' = { name: networkInterfaceName location: location properties: { ipConfigurations: [ { name: 'ipconfig1' properties: { subnet: { id: subnet.id } privateIPAllocationMethod: 'Dynamic' publicIPAddress: { id: publicIP.id } } } ] } } resource vnet 'Microsoft.Network/virtualNetworks@2021-08-01' = { name: virtualNetworkName location: location properties: { addressSpace: { addressPrefixes: [ addressPrefix ] } } } resource subnet 'Microsoft.Network/virtualNetworks/subnets@2021-08-01' = { parent: vnet name: subnetName properties: { addressPrefix: subnetAddressPrefix privateEndpointNetworkPolicies: 'Enabled' privateLinkServiceNetworkPolicies: 'Enabled' } } resource publicIP 'Microsoft.Network/publicIPAddresses@2021-08-01' = { name: publicIPAddressName location: location sku: { name: 'Basic' } properties: { publicIPAllocationMethod: 'Dynamic' publicIPAddressVersion: 'IPv4' dnsSettings: { domainNameLabel: dnsLabelPrefix } idleTimeoutInMinutes: 4 } } resource vm 'Microsoft.Compute/virtualMachines@2021-11-01' = { name: vmName location: location properties: { hardwareProfile: { vmSize: vmSize } osProfile: { adminUsername: adminUsername computerName: vmName linuxConfiguration: linuxConfiguration } storageProfile: { imageReference: { offer: '0001-com-ubuntu-server-jammy' publisher: 'Canonical' sku: '22_04-lts-gen2' version: 'latest' } osDisk: { createOption: 'FromImage' deleteOption: 'Delete' diskSizeGB: 32 osType: 'Linux' managedDisk: { storageAccountType: osDiskType } } } networkProfile: { networkInterfaces: [ { id: nic.id } ] } } } output adminUsername string = adminUsername output hostname string = publicIP.properties.dnsSettings.fqdn output sshComand string = 'ssh ${adminUsername}@${publicIP.properties.dnsSettings.fqdn}'
部署验证
修正完成后重新执行部署命令,虚拟机资源会和关联网络资源一起正常创建,部署完成后可以直接使用输出的ssh命令连接虚拟机,公钥会自动写入对应用户的authorized_keys文件中。
内容的提问来源于stack exchange,提问作者Ivana
相关产品推荐
相关产品推荐

