部署Azure机器学习服务工作区ARM模板时遇MSI支持错误求助
Let's break down what's causing this error and how to resolve it quickly:
Root Cause
This error comes down to two critical compatibility issues:
- Outdated Az CLI Version: Your installed
azure-cli 2.0.78is extremely old (released in 2019). This version lacks support for the Managed Service Identity (MSI) functionality that Azure Machine Learning Workspaces rely on to access linked resources like Storage Accounts, Key Vaults, and App Insights—even for older API versions. - API Version & CLI Misalignment: While the
2018-11-19ML API version technically predates mandatory MSI requirements, the outdated CLI still has gaps that prevent successful deployment via ARM templates.
Step-by-Step Solutions
1. Upgrade Your Az CLI to the Latest Version
First, update your Azure CLI on Ubuntu to ensure it supports MSI for ML workspaces:
sudo apt update && sudo apt install --only-upgrade azure-cli # Verify the upgrade was successful az --version
You should see a version like 2.50.0 or newer (as of 2024).
2. Update the ARM Template's API Version
Using a newer, supported API version will make your deployment more reliable and align with Azure's current best practices. Update your ARM template's ML workspace apiVersion to 2019-11-01 or later (e.g., 2023-04-01-preview):
{ "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "storageAccountName": { "type": "string", "metadata": { "description": "The name of the storage account" } }, "appInsightsName" : { "type": "string", "metadata": { "description": "The name of the app insights account" } }, "keyVaultName": { "type": "string", "metadata": { "description": "The name of the keyvault resource" } }, "mlApiVersion": { "type": "string", "metadata": { "description": "The api version of the ML workspace" } }, "mlWorkspaceName": { "type": "string", "metadata": { "description": "The name of the Machine Learning Workspace" } }, "location": { "type": "string", "metadata": { "description": "Resource location" } } }, "resources": [ { "apiVersion": "[parameters('mlApiVersion')]", // Ensure you pass 2019-11-01 or newer here "type": "Microsoft.MachineLearningServices/workspaces", "name": "[parameters('mlWorkspaceName')]", "location": "[parameters('location')]", "sku": { "tier": "enterprise", "name": "enterprise" }, "properties": { "storageAccount": "[resourceId('Microsoft.Storage/storageAccounts',parameters('storageAccountName'))]", "applicationInsights": "[resourceId('Microsoft.Insights/components',parameters('appInsightsName'))]", "keyVault": "[resourceId('Microsoft.KeyVault/vaults',parameters('keyVaultName'))]" } } ] }
When running your deployment command, pass mlApiVersion=2019-11-01 instead of the 2018 version.
3. Verify Linked Resource Permissions
Ensure your Key Vault allows template deployments to access it:
- Navigate to your Key Vault in the Azure Portal
- Go to Access policies > Create
- Select the "Azure Resource Manager for template deployment" permission under "Secret permissions"
- Save the policy
This ensures the ML workspace can access the Key Vault via its MSI.
Re-Run the Deployment
After completing the above steps, re-execute your deployment command:
az group deployment create --name MachineLearning --resource-group data-science --template-file ML_ARM.json --parameters appInsightsName=machine-learning-dev storageAccountName=machinelearningdev keyVaultName=data-science-dev mlApiVersion=2019-11-01 mlWorkspaceName=machine-learning-dev location=uksouth
内容的提问来源于stack exchange,提问作者Matthew Darwin

