Azure虚拟机托管身份获取访问令牌时遇404错误求助
Hey there, let's break down the most likely reasons you're getting that 404 response when calling the Azure Instance Metadata Service (IMDS) from your VM:
Managed identity might not be fully activated on the VM
Even if you assigned the user-assigned managed identity (UAMI) through the portal, VMs sometimes need a quick restart to recognize the new identity. Reboot your VM, wait a minute or two, then try the curl command again. Also, double-check the VM's Identity > User assigned tab in the Azure portal to confirm the UAMI is listed as successfully assigned (no pending status).You might be using the wrong ID in the
client_idparameter
It's super easy to mix up the UAMI's Client ID with its Object ID or Resource ID. Head back to your managed identity's overview page in the portal and make sure you're copying the Client ID field—this is the value the IMDS needs to locate your identity. A single typo here will trigger a 404.Network rules are blocking access to the IMDS endpoint
The IMDS uses the local, non-routable IP169.254.169.254, which should be accessible from within the VM by default. But if you've set up custom Network Security Group (NSG) rules or a VM-level firewall, double-check that outbound traffic to this IP isn't blocked. Even a restrictive default deny rule could be causing the issue.Typos in the curl command parameters
Let's take a look at your command syntax. Theresourceparameter has a trailing slash (https%3A%2F%2Fmanagement.azure.com/)—while this isn't always a problem, try removing it so the encoded resource ishttps%3A%2F%2Fmanagement.azure.com. You can also try a newerapi-version(like2021-02-01) instead of2018-02-01—both are valid, but newer versions sometimes resolve minor edge cases.
Here's a cleaned-up version of the command to test:
curl -H Metadata:true "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2021-02-01&resource=https%3A%2F%2Fmanagement.azure.com&client_id=<UAMI CLIENT ID>"
If none of these steps work, check the VM's diagnostic logs (under VM > Logs in the portal) for entries related to managed identity setup—they might have specific details about why the IMDS can't locate your identity.
内容的提问来源于stack exchange,提问作者vikramaditya234

