Azure Functions通过GitHub Actions部署失败:发布配置文件REDACTED
Azure Functions GitHub Actions部署401未授权问题
构建与发布阶段日志
Run pushd './.' pushd './.' dotnet build --configuration Release dotnet publish --configuration Release --output ./publish popd shell: C:\Program Files\PowerShell\7\pwsh.EXE -command ". '{0}'" env: AZURE_FUNCTIONAPP_NAME: function-core-api AZURE_FUNCTIONAPP_PACKAGE_PATH: . DOTNET_VERSION: 8.0.x CONFIGURATION: Release DOTNET_CORE_VERSION: 8.0.x WORKING_DIRECTORY: . DOTNET_ROOT: C:\Program Files\dotnet Determining projects to restore... All projects are up-to-date for restore. Warning: C:\a\functions\functions\Services\VideoService.cs(379,29): warning CS8602: Dereference of a possibly null reference. [C:\a\functions\functions\functions.csproj] Determining projects to restore... Restored C:\a\functions\functions\obj\Release\net8.0\WorkerExtensions\WorkerExtensions.csproj (in 7.75 sec). WorkerExtensions -> C:\a\functions\functions\obj\Release\net8.0\WorkerExtensions\buildout\Microsoft.Azure.Functions.Worker.Extensions.dll functions -> C:\a\functions\functions\bin\Release\net8.0\functions.dll Build succeeded. Warning: C:\a\functions\functions\Services\VideoService.cs(379,29): warning CS8602: Dereference of a possibly null reference. [C:\a\functions\functions\functions.csproj] 1 Warning(s) 0 Error(s) Time Elapsed 00:01:10.18 Determining projects to restore... All projects are up-to-date for restore. Warning: C:\Program Files\dotnet\sdk\9.0.300\Current\SolutionFile\ImportAfter\Microsoft.NET.Sdk.Solution.targets(36,5): warning NETSDK1194: The "--output" option isn't supported when building a solution. Specifying a solution-level output path results in all projects copying outputs to the same directory, which can lead to inconsistent builds. [C:\a\functions\functions\functions.sln] Determining projects to restore... All projects are up-to-date for restore. WorkerExtensions -> C:\a\functions\functions\obj\Release\net8.0\WorkerExtensions\buildout\Microsoft.Azure.Functions.Worker.Extensions.dll functions -> C:\a\functions\functions\bin\Release\net8.0\functions.dll functions -> C:\a\functions\functions\publish\
部署阶段错误日志
Run Azure/functions-action@v1 with: app-name: core-api package: ./publish publish-profile: *** respect-funcignore: true scm-do-build-during-deployment: false enable-oryx-build: false respect-pom-xml: false remote-build: false env: AZURE_FUNCTIONAPP_NAME: core-api AZURE_FUNCTIONAPP_PACKAGE_PATH: . DOTNET_VERSION: 8.0.x CONFIGURATION: Release DOTNET_CORE_VERSION: 8.0.x WORKING_DIRECTORY: . DOTNET_ROOT: C:\Program Files\dotnet Successfully parsed SCM credential from publish-profile format. Using SCM credential for authentication, GitHub Action will not perform resource validation. Error: Execution Exception (state: ValidateAzureResource) (step: Invocation) Error: When request Azure resource at ValidateAzureResource, Get Function App Settings : Failed to acquire app settings from https://<scmsite>/api/settings with publish-profile Error: Failed to fetch Kudu App Settings. Unauthorized (CODE: 401) Error: Error: Failed to fetch Kudu App Settings. Unauthorized (CODE: 401) at Kudu.<anonymous> (C:\a_actions\Azure\functions-action\v1\lib\appservice-rest\Kudu\azure-app-kudu-service.js:72:23) at Generator.next (<anonymous>) at fulfilled (C:\a_actions\Azure\functions-action\v1\lib\appservice-rest\Kudu\azure-app-kudu-service.js:5:58) at process.processTicksAndRejections (node:internal/process/task_queues:95:5) Error: Deployment Failed!
用户疑问
复制的发布配置文件中所有凭证均显示为REDACTED而非真实凭证,导致部署出现401未授权错误。请问这种情况是否正常?是否需要手动补全配置文件?
获取的发布配置文件内容:
<publishData><publishProfile profileName="core-api - Web Deploy" publishMethod="MSDeploy" publishUrl="core-api.scm.azurewebsites.net:443" msdeploySite="core-api" userName="REDACTED" userPWD="REDACTED" destinationAppUrl="https://core-api.azurewebsites.net" SQLServerDBConnectionString="REDACTED" mySQLDBConnectionString="" hostingProviderForumLink="" controlPanelLink="https://portal.azure.com" webSystem="WebSites"><databases /></publishProfile><publishProfile profileName="core-api - FTP" publishMethod="FTP" publishUrl="ftps://waws-prod-bn1-285.ftp.azurewebsites.windows.net/site/wwwroot" ftpPassiveMode="True" userName="REDACTED" userPWD="REDACTED" destinationAppUrl="https://core-api.azurewebsites.net" SQLServerDBConnectionString="REDACTED" mySQLDBConnectionString="" hostingProviderForumLink="" controlPanelLink="https://portal.azure.com" webSystem="WebSites"><databases /></publishProfile><publishProfile profileName="core-api - Zip Deploy" publishMethod="ZipDeploy" publishUrl="core-api.scm.azurewebsites.net:443" userName="REDACTED" userPWD="REDACTED" destinationAppUrl="https://core-api.azurewebsites.net" SQLServerDBConnectionString="REDACTED" mySQLDBConnectionString="" hostingProviderForumLink="" controlPanelLink="https://portal.azure.com" webSystem="WebSites"><databases /></publishProfile></publishData>
问题解答
原因说明
REDACTED是Azure门户显示发布配置文件时的脱敏处理,属于正常现象,但你复制的是脱敏后的内容,不包含真实的身份凭证,这才是导致401未授权的根本原因。不要手动补全配置文件,手动补全无法获取有效凭证。
解决步骤
重新下载完整发布配置文件
- 登录Azure门户,定位到你的Function App
- 在「概述」或「部署中心」页面,点击「获取发布配置文件」按钮
- 下载的XML文件中会包含真实的
userName和userPWD值,不会显示为REDACTED
配置GitHub Actions秘密变量
- 打开GitHub仓库,进入「Settings」→「Secrets and variables」→「Actions」
- 点击「New repository secret」,创建名为
AZURE_FUNCTIONAPP_PUBLISH_PROFILE的秘密变量 - 将下载的完整发布配置文件内容粘贴到变量值中,保存
更新GitHub Actions工作流
修改工作流中部署步骤的publish-profile参数,引用刚才创建的秘密变量:- name: Deploy to Azure Functions uses: Azure/functions-action@v1 with: app-name: core-api package: ./publish publish-profile: ${{ secrets.AZURE_FUNCTIONAPP_PUBLISH_PROFILE }} # 其他保持不变
额外提示
构建阶段的两个警告不影响部署,但如果需要优化:
- CS8602警告:在
VideoService.cs第379行添加空值检查(如if (xxx != null))或使用!运算符明确标记非空 - NETSDK1194警告:修改
dotnet publish命令,指定具体项目文件而非解决方案,例如:dotnet publish ./functions.csproj --configuration Release --output ./publish
内容的提问来源于stack exchange,提问作者Ricker Silva
相关产品推荐
相关产品推荐

