ARM模板配置Key Vault权限报错:accessPolicies值无效及ObjectID异常
Let's break down and fix the issues you're facing step by step:
1. Correct the Managed Identity Resource ID Construction
Your identityResourceId variable has a small syntax error in the resourceId function - you added an extra trailing slash in the resource type. This leads to an invalid resource ID, which breaks the reference call later.
Fixed variable definition:
"variables": { "identityResourceId": "[concat(resourceId('Microsoft.Web/sites', variables('functionAppName')), '/providers/Microsoft.ManagedIdentity/Identities/default')]" }
2. Update the Reference API Version
The 2015-08-31-PREVIEW API version is outdated for managed identities. Using a newer, stable version ensures you can reliably fetch the principalId.
Fixed outputs section:
"outputs": { "AppObjectId": { "type": "string", "value": "[reference(variables('identityResourceId'), '2018-11-30').principalId]" } }
(You can also use newer versions like 2023-01-31 if preferred - just ensure it's compatible with your Azure resource provider version.)
3. Verify System-Assigned Identity is Enabled
Make sure your Function App has system-managed identity turned on in its resource definition. Without this, the managed identity resource won't exist, and you'll never get a valid principalId:
"resources": [ { "type": "Microsoft.Web/sites", "name": "[variables('functionAppName')]", "apiVersion": "2022-09-01", "identity": { "type": "SystemAssigned" // This line enables the managed identity }, // Rest of your Function App configuration... } ]
4. Ensure Deployment Order & Dependencies
To avoid race conditions where Key Vault tries to fetch the identity before the Function App is created, add a dependsOn clause in your Key Vault resource:
{ "type": "Microsoft.KeyVault/vaults", "name": "[variables('keyVaultName')]", "apiVersion": "2023-02-01", "dependsOn": [ "[resourceId('Microsoft.Web/sites', variables('functionAppName'))]" // Wait for Function App to deploy ], "properties": { "accessPolicies": [ { "tenantId": "[subscription().tenantId]", "objectId": "[reference(variables('identityResourceId'), '2018-11-30').principalId]", "permissions": { "secrets": ["Get", "List"], // Adjust permissions to your needs "keys": [], "certificates": [] } } ], // Rest of your Key Vault configuration... } }
After applying these fixes, you should be able to retrieve the correct principalId and resolve the "invalid accessPolicies" error, since the Key Vault will now reference a valid identity object ID.
内容的提问来源于stack exchange,提问作者ssashok10

