You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure门户中ARM模板自动化App Registration部署失败求助

Azure ARM模板结合DeploymentScript创建应用注册失败(ResourceDeploymentFailure)

问题描述

我想在Azure门户内不依赖本地工具,通过ARM模板结合Azure CLI部署脚本自动创建Azure应用注册,并提取appId作为输出,但部署始终失败,报错ResourceDeploymentFailure,提示资源进入终端预配状态“failed”。

使用的ARM模板

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "deploymentTag": {
      "type": "string",
      "defaultValue": "[format('{0}', deployment().name)]"
    }
  },
  "resources": [
    {
      "type": "Microsoft.Resources/deploymentScripts",
      "apiVersion": "2020-10-``your text``01",
      "name": "AppRegistrationScript",
      "location": "[resourceGroup().location]",
      "kind": "AzureCLI",
      "properties": {
        "scriptType": "AzureCLI",
        "azCliVersion": "2.40.0",
        "timeout": "PT300M",
        "cleanupPreference": "OnSuccess",
        "retentionInterval": "P1D",
        "scriptContent": "az ad app create --display-name 'MyApp' --sign-in-audience 'AzureADMyOrg' --query appId --output tsv > $AZ_SCRIPTS_OUTPUT_PATH",
        "forceUpdateTag": "[parameters('deploymentTag')]"
      }
    }
  ],
  "outputs": {
    "appId": {
      "type": "string",
      "value": "[reference('AppRegistrationScript').outputs['appId']]"
    }
  }
}

已尝试的操作

  • ✅ 手动执行命令az ad app create --display-name "MyApp"可成功创建应用注册
  • ✅ 验证$AZ_SCRIPTS_OUTPUT_PATH可正确捕获输出
  • ✅ 确认模板中appId输出引用正确
  • ✅ 将超时时间增加至PT300M
  • ✅ 在Azure门户中查看部署日志获取错误详情

错误详情

Error: The resource write operation failed to complete successfully, because it reached terminal provisioning state 'failed'.
(Code: ResourceDeploymentFailure)

原始错误JSON:

{
  "code": "DeploymentFailed",
  "target": "/subscriptions/xxxxxxxxxxxxxxxxxxxxx/resourceGroups/scratch/providers/Microsoft.Resources/deployments/Microsoft.Template-2025052312xx36",
  "message": "At least one resource deployment operation failed. Please list deployment operations for details. Please see https://aka.ms/arm-deployment-operations for usage details.",
  "details": [
    {
      "code": "ResourceDeploymentFailure",
      "target": "/subscriptions/xxxxxxxxxxxxxxxxxxxxxxxxxxxxx/resourceGroups/scratch/providers/Microsoft.Resources/deploymentScripts/AppRegistrationScript",
      "message": "The resource write operation failed to complete successfully, because it reached terminal provisioning state 'failed'."
    }
  ]
}

解决方案

1. 修正API版本的语法错误

模板中apiVersion字段存在输入错误:"2020-10-``your text``01",这会导致模板解析失败。将其修正为正确的API版本:

"apiVersion": "2020-10-01"

2. 为DeploymentScript托管标识分配权限

DeploymentScript默认使用系统分配的托管标识,该标识默认没有创建Azure AD应用注册的权限,需要为其授予Application Developer角色:

  • 手动分配:部署模板后(即使失败),找到AppRegistrationScript资源,进入“标识”页复制系统分配的对象ID;在Azure AD的“角色和管理员”中找到Application Developer角色,添加该对象ID作为成员。
  • 自动分配:在ARM模板的resources数组中添加角色分配资源,自动授予权限(需部署账号有租户级角色分配权限):
    {
      "type": "Microsoft.Authorization/roleAssignments",
      "apiVersion": "2022-04-01",
      "name": "[guid(tenant().id, 'AppDevRoleAssignment')]",
      "dependsOn": [
        "AppRegistrationScript"
      ],
      "properties": {
        "roleDefinitionId": "/providers/Microsoft.Authorization/roleDefinitions/1b4f816e-5eaf-48b9-8613-7923830595ad",
        "principalId": "[reference('AppRegistrationScript').identity.principalId]",
        "scope": "[tenant().id]"
      }
    }
    

3. 优化脚本输出格式

确保脚本输出为标准JSON格式,ARM模板才能正确解析outputs。修改scriptContent为:

appId=$(az ad app create --display-name 'MyApp' --sign-in-audience 'AzureADMyOrg' --query appId --output tsv)
echo "{\"appId\": \"$appId\"}" > $AZ_SCRIPTS_OUTPUT_PATH

4. 完整修正后的模板

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "deploymentTag": {
      "type": "string",
      "defaultValue": "[format('{0}', deployment().name)]"
    },
    "appDisplayName": {
      "type": "string",
      "defaultValue": "MyApp"
    }
  },
  "resources": [
    {
      "type": "Microsoft.Resources/deploymentScripts",
      "apiVersion": "2020-10-01",
      "name": "AppRegistrationScript",
      "location": "[resourceGroup().location]",
      "kind": "AzureCLI",
      "identity": {
        "type": "SystemAssigned"
      },
      "properties": {
        "scriptType": "AzureCLI",
        "azCliVersion": "2.40.0",
        "timeout": "PT30M",
        "cleanupPreference": "OnSuccess",
        "retentionInterval": "P1D",
        "scriptContent": "[format('appId=$(az ad app create --display-name ''{0}'' --sign-in-audience ''AzureADMyOrg'' --query appId --output tsv) && echo ''{{\"appId\": \"$appId\"}}'' > $AZ_SCRIPTS_OUTPUT_PATH', parameters('appDisplayName'))]",
        "forceUpdateTag": "[parameters('deploymentTag')]"
      }
    },
    {
      "type": "Microsoft.Authorization/roleAssignments",
      "apiVersion": "2022-04-01",
      "name": "[guid(tenant().id, 'AppDevRoleAssignment')]",
      "dependsOn": [
        "AppRegistrationScript"
      ],
      "properties": {
        "roleDefinitionId": "/providers/Microsoft.Authorization/roleDefinitions/1b4f816e-5eaf-48b9-8613-7923830595ad",
        "principalId": "[reference('AppRegistrationScript').identity.principalId]",
        "scope": "[tenant().id]"
      }
    }
  ],
  "outputs": {
    "appId": {
      "type": "string",
      "value": "[reference('AppRegistrationScript').outputs.appId]"
    }
  }
}

5. 排查详细错误

如果问题仍存在,进入AppRegistrationScript资源的“日志”页,查看execution.log,里面会包含Azure CLI命令的具体执行错误(如权限不足、参数冲突等),这是定位问题的核心依据。

内容的提问来源于stack exchange,提问作者Sanjith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 01:59:52