You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell创建Service Fabric集群失败求助

Troubleshooting Failed Service Fabric Cluster Creation via PowerShell Script

Hey, sorry to hear your Service Fabric Linux cluster creation script is failing—let’s break down the most likely issues and how to fix them, starting with what you’ve shared:

First, Fix Script Parameter Incompleteness

Looking at your script snippet, the $Location parameter is cut off. Make sure it’s fully defined with either a default value or marked as mandatory. For example:

[Parameter(HelpMessage="Where is the azure location?")]
[String]$Location="eastus" # Add a default region, or use [Parameter(Mandatory=$true)] if you want it required

An incomplete parameter definition will cause the script to throw a syntax error before it even starts running.

Verify Azure Authentication & Permissions

Your script uses username/password auth for Azure—let’s make sure this is set up correctly:

  • Install the latest modules: Ensure you have the most recent versions of Az and Az.ServiceFabric installed. Run Update-Module Az.ServiceFabric -Force to update.
  • Properly authenticate before cluster creation: Your script is missing the step to log into Azure with the provided credentials. Add this at the start of your script:
    $securePassword = ConvertTo-SecureString $azPassword -AsPlainText -Force
    $credential = New-Object System.Management.Automation.PSCredential($azUserName, $securePassword)
    Connect-AzAccount -Credential $credential -ErrorAction Stop
    
  • Check user permissions: The Azure account you’re using needs:
    • Contributor access to the cluster resource group (sfLinuxClusterRg)
    • Key Vault Contributor access to the key vault resource group (KeyVaultRg)
      Without these, the script will hit permission-denied errors when trying to create resources or access the key vault.

Validate Key Vault Requirements

Service Fabric clusters have strict key vault requirements—double-check these:

  • Soft Delete & Purge Protection must be enabled: This is mandatory for storing cluster certificates. You can verify this with:
    $keyVault = Get-AzKeyVault -ResourceGroupName $KeyVaultResourceGroupName -VaultName "YOUR_KEYVAULT_NAME"
    if (-not $keyVault.EnableSoftDelete -or -not $keyVault.EnablePurgeProtection) {
        Write-Error "Key vault must have Soft Delete and Purge Protection enabled"
        exit 1
    }
    
  • Certificate availability: Ensure the cluster’s SSL certificate is already stored in the key vault, or your script includes logic to generate/upload it. Without a valid certificate, the cluster creation will fail immediately—Service Fabric requires certificates for node-to-node encryption and identity verification.

Check Cluster Creation Command Configuration

Since you only shared the parameter section, make sure your New-AzServiceFabricCluster command has all the required Linux-specific settings:

  • Specify -OsType Linux explicitly
  • Use a Linux-compatible VM size (e.g., Standard_D2s_v3)
  • Correctly reference the key vault certificate with -CertificateUrl and -CertificateThumbprint

Capture & Analyze Exact Error Details

The most critical step is getting the full error message. Run your script with -ErrorAction Stop to halt on failures, then check the detailed error output with:

$Error[0].Exception | Format-List -Force

Common errors you might see:

  • "Insufficient privileges to perform action": Fix permissions as noted above
  • "Key vault does not have soft delete enabled": Enable soft delete/purge protection on the vault
  • "Certificate not found in key vault": Ensure the certificate exists in the vault and your script references it correctly

内容的提问来源于stack exchange,提问作者ossentoo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:05:06