使用Azure DevOps AzureFileCopy任务上传Blob时AzCopy认证失败如何解决
问题描述
我正在使用Azure file copy任务将构建产物上传到Blob容器,始终遇到如下报错:
0.0 %, 0 Done, 0 Failed, 1 Pending, 0 Skipped, 1 Total, INFO: Authentication failed, it is either not correct, or expired, or does not have the correct permission -> github.com/Azure/azure-storage-blob-go/azblob.newStorageError, /home/vsts/go/pkg/mod/github.com/!azure/azure-storage-blob-go@v0.10.1-0.20201022074806-8d8fc11be726/azblob/zc_storage_error.go:42 ===== RESPONSE ERROR (ServiceCode=AuthorizationPermissionMismatch) ===== Description=This request is not authorized to perform this operation using this permission. RequestId:ae545517-501e-00ce-0798-ea489e000000 Time:2021-12-06T11:54:25.0571292Z, Details: Code: AuthorizationPermissionMismatch PUT mybloburl?blockid=YjA4YjIzN2UtODJhMC1mMjQzLTUwOGYtNmYxNDcwOGJjZmY0&comp=block&timeout=901 Authorization: REDACTED Content-Length: [8388608] User-Agent: [TFS_useragent AzCopy/10.8.0 Azure-Storage/0.10 (go1.13; Windows_NT)] X-Ms-Client-Request-Id: [65465-83ea-4410-450e-dd5b722b6cb3] X-Ms-Version: [2019-12-12] -------------------------------------------------------------------------------- RESPONSE Status: 403 This request is not authorized to perform this operation using this permission.
任务对应的YAML配置如下:
steps: - task: AzureFileCopy@4 displayName: 'AzureBlob File Copy' inputs: SourcePath: '$(Build.ArtifactStagingDirectory)/myfile.zip' azureSubscription: 'my-azure-connection' Destination: AzureBlob storage: mystorage ContainerName: mycontainer
解决方案
这个报错核心原因是Azure DevOps服务连接绑定的服务主体,没有目标存储账户的Blob写入权限。AzureFileCopy@4版本默认基于服务主体的RBAC权限完成Blob操作,仅给服务主体订阅级别的读取权限不足以完成上传。
修复步骤
- 进入Azure DevOps项目的「服务连接」设置页,找到名为
my-azure-connection的连接,点击「管理服务主体」跳转至Azure门户,记录该服务主体的应用ID或名称。 - 打开目标存储账户
mystorage的「访问控制(IAM)」页,点击「添加角色分配」:- 角色选择「存储Blob数据贡献者」即可满足常规上传需求,若需要更高权限可选择「存储Blob数据所有者」
- 成员范围选择刚才记录的服务主体,完成分配
- 等待1-5分钟待权限生效后,重新运行流水线即可。
额外排查项
如果配置权限后仍报错,可依次检查以下内容:
- 存储账户是否开启了防火墙限制,若开启需将Azure DevOps的服务IP或
AzureDevOps服务标签加入存储账户白名单 - 重新验证
my-azure-connection服务连接的有效性,确认未过期 - 确认存储账户名
mystorage、容器名mycontainer拼写正确,且容器已提前创建
内容的提问来源于stack exchange,提问作者Sibeesh Venu
相关产品推荐
相关产品推荐

