在Azure自动化混合工作器中用Python获取Azure凭据的问题
问题
我有一个存储了大量凭据的Azure自动化账户,之前用PowerShell的Get-AutomationPSCredential命令获取凭据很顺畅,但现在需要在混合工作器运行的Python脚本中获取这些凭据。查资料得知应该用automationassets模块,但该模块似乎只在Azure环境内运行有效。
在混合工作器上运行以下脚本:
#!/usr/bin/env python3 import automationassets print("hello world") cred = automationassets.get_automation_credential("TestCredentials") print(cred["username"]) print(cred["password"]) print("---DONE---")
出现错误:
Traceback (most recent call last): File "C:\ProgramData\Microsoft\System Center\Orchestrator\7.2\SMA\Sandboxes\prccrwfo.uqy\Temp\u4krn2px.peo\2067bebf-6afe-4427-a1ba-ebe41539ff53", line 5, in <module> cred = automationassets.get_automation_credential("TestCredentials") File "C:\Python39\automationassets.py", line 126, in get_automation_credential credential = _get_asset(_KEY_CREDENTIAL, name) File "C:\Python39\automationassets.py", line 72, in _get_asset return_value = _get_asset_value(local_assets_file, asset_type, asset_name) File "C:\Python39\automationassets.py", line 55, in _get_asset_value for asset, asset_values in local_assets.iteritems(): AttributeError: 'dict' object has no attribute 'iteritems'
添加额外导入语句的脚本:
import automationassets from automationassets import AutomationAssetNotFound
抛出错误:
Traceback (most recent call last): File "C:\ProgramData\Microsoft\System Center\Orchestrator\7.2\SMA\Sandboxes\1v03pjym.qll\Temp\rv4yiqnf.c3v\4a5b24ae-bd26-40e6-82cc-86cf36915077", line 3, in <module> from automationassets import AutomationAssetNotFound ImportError: cannot import name 'AutomationAssetNotFound' from 'automationassets' (C:\Python39\automationassets.py)
请问是否可以在Azure自动化的混合工作器运行的Python脚本中获取Azure凭据?
解决方案
可以在混合工作器的Python脚本中获取Azure自动化凭据,你遇到的问题源于automationassets模块与Python 3.x版本不兼容,以下是具体解决办法:
修复iteritems()属性错误
你使用的是Python 3.x,而iteritems()是Python 2.x的字典遍历方法,Python 3.x中对应的方法是items()。直接修改本地的automationassets.py文件即可:
- 找到文件路径
C:\Python39\automationassets.py - 打开文件,定位到第55行的
for asset, asset_values in local_assets.iteritems(): - 将
iteritems()替换为items(),保存后重新运行脚本。
解决AutomationAssetNotFound导入错误
旧版本的automationassets模块未定义AutomationAssetNotFound异常类,因此无法导入。若需捕获凭据不存在的异常,可直接捕获通用Exception,或者升级模块至适配Python 3的版本。
替代方案:调用Azure REST API获取凭据
如果修改模块文件存在限制,可通过Azure自动化REST API获取凭据:
- 为混合工作器所在机器分配具有Azure自动化凭据读取权限的服务主体。
- 使用
azure-identity库获取身份令牌,再调用API获取凭据,示例代码如下:
from azure.identity import DefaultAzureCredential import requests # 获取身份令牌 credential = DefaultAzureCredential() token = credential.get_token("https://management.azure.com/.default") # 配置参数 subscription_id = "你的订阅ID" resource_group = "你的资源组名称" automation_account = "你的自动化账户名称" credential_name = "TestCredentials" # 构建API请求URL url = f"https://management.azure.com/subscriptions/{subscription_id}/resourceGroups/{resource_group}/providers/Microsoft.Automation/automationAccounts/{automation_account}/credentials/{credential_name}?api-version=2023-11-01" headers = { "Authorization": f"Bearer {token.token}" } # 发送请求并解析结果 response = requests.get(url, headers=headers) response.raise_for_status() cred_data = response.json() username = cred_data["properties"]["userName"] password = cred_data["properties"]["password"] print(f"用户名: {username}") print(f"密码: {password}")
内容的提问来源于stack exchange,提问作者Andrew Draper
相关产品推荐
相关产品推荐

