在非区域对中部署Azure CVO HA失败、并显示错误"此请求无权执行此操作"
适用场景
- Azure CVO HA部署
- 非区域对中的Azure CVO和Connector
- 存储帐户的Azure专用链接已禁用或不起作用
- Azure存储帐户创建
- 蓝色XP 3.9.25及更高版本
问题描述
- 如果Azure CVO和CM不在 Azure区域对中 、并且 存储帐户的Azure专用链接已禁用或不起作用、则Azure CVO HA部署将失败、并显示以下错误。
- BlueXP时间间隔、错误
This request is not authorized to perform this operation
为ONCreate Container task
Create Container (6) Failed { "storageAccountName": "rootsaxxxx", "containerName": "blobcontainer", "requestContext": "Create Azure Ha Working Environment", "useProxy": true, "_failure": "This request is not authorized to perform this operation.", "_resourceGroup": "CVO-RG" } Update Storage Account Network Rules Failed { "storageAccount": "rootsaxxxxx", "defaultAction": "Deny", "networkRules": [ { "action": "Allow", "id": "/subscriptions/79f9c07a-xxxxx-yyyy-a761-84c910955d4a/resourceGroups/CVO-RG/providers/Microsoft.Network/virtualNetworks/CVO-vNET/subnets/CVO-SUBNET" }, { "action": "Allow", "id": "/subscriptions/3efcd6c9-zzzz-uuuu-a431-0971b4fd6c2c/resourceGroups/CM-RG/providers/Microsoft.Network/virtualNetworks/CM-VNET/subnets/CM-SUBNET" } ], "_failure": "Validation of network acls failure: ResourceBeingAcledHasWrongLocation:Microsoft.Storage resources in System.Linq.Enumerable+<ExceptIterator>d__73`1[System.String] cannot be ACL-ed to virtual network /subscriptions/79f9c07a-xxxxx-yyyy-a761-84c910955d4a/resourceGroups/CVO-RG/providers/Microsoft.Network/virtualNetworks/CVO-vNET in uksouth. Only resources in uksouth, ukwest can be ACL-ed to virtual networks in uksouth.. Code: NetworkAclsValidationFailure ", "_resourceGroup": "RNB-P-NetAppCvo-NA20-RGRP2" }