You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure DevOps AzureFileCopy任务上传Blob时AzCopy认证失败如何解决

问题描述

我正在使用Azure file copy任务将构建产物上传到Blob容器,始终遇到如下报错:

0.0 %, 0 Done, 0 Failed, 1 Pending, 0 Skipped, 1 Total, 
INFO: Authentication failed, it is either not correct, or expired, or does not have the correct permission -> github.com/Azure/azure-storage-blob-go/azblob.newStorageError, /home/vsts/go/pkg/mod/github.com/!azure/azure-storage-blob-go@v0.10.1-0.20201022074806-8d8fc11be726/azblob/zc_storage_error.go:42
===== RESPONSE ERROR (ServiceCode=AuthorizationPermissionMismatch) =====
Description=This request is not authorized to perform this operation using this permission.
RequestId:ae545517-501e-00ce-0798-ea489e000000
Time:2021-12-06T11:54:25.0571292Z, Details: 
   Code: AuthorizationPermissionMismatch
   PUT mybloburl?blockid=YjA4YjIzN2UtODJhMC1mMjQzLTUwOGYtNmYxNDcwOGJjZmY0&comp=block&timeout=901
   Authorization: REDACTED
   Content-Length: [8388608]
   User-Agent: [TFS_useragent AzCopy/10.8.0 Azure-Storage/0.10 (go1.13; Windows_NT)]
   X-Ms-Client-Request-Id: [65465-83ea-4410-450e-dd5b722b6cb3]
   X-Ms-Version: [2019-12-12]
   --------------------------------------------------------------------------------
   RESPONSE Status: 403 This request is not authorized to perform this operation using this permission.

任务对应的YAML配置如下:

steps:
- task: AzureFileCopy@4
  displayName: 'AzureBlob File Copy'
  inputs:
    SourcePath: '$(Build.ArtifactStagingDirectory)/myfile.zip'
    azureSubscription: 'my-azure-connection'
    Destination: AzureBlob
    storage: mystorage
    ContainerName: mycontainer
解决方案

这个报错核心原因是Azure DevOps服务连接绑定的服务主体,没有目标存储账户的Blob写入权限。AzureFileCopy@4版本默认基于服务主体的RBAC权限完成Blob操作,仅给服务主体订阅级别的读取权限不足以完成上传。

修复步骤

  • 进入Azure DevOps项目的「服务连接」设置页,找到名为my-azure-connection的连接,点击「管理服务主体」跳转至Azure门户,记录该服务主体的应用ID或名称。
  • 打开目标存储账户mystorage的「访问控制(IAM)」页,点击「添加角色分配」:
    • 角色选择「存储Blob数据贡献者」即可满足常规上传需求,若需要更高权限可选择「存储Blob数据所有者」
    • 成员范围选择刚才记录的服务主体,完成分配
  • 等待1-5分钟待权限生效后,重新运行流水线即可。

额外排查项

如果配置权限后仍报错,可依次检查以下内容:

  • 存储账户是否开启了防火墙限制,若开启需将Azure DevOps的服务IP或AzureDevOps服务标签加入存储账户白名单
  • 重新验证my-azure-connection服务连接的有效性,确认未过期
  • 确认存储账户名mystorage、容器名mycontainer拼写正确,且容器已提前创建

内容的提问来源于stack exchange,提问作者Sibeesh Venu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 17:54:00