Azure Python SDK:“ ServicePrincipalCredentials”对象没有属性“ get_token”

问题描述

因此,我具有以下python3脚本来列出所有虚拟机。

import os,json
from azure.mgmt.compute import ComputeManagementClient
from azure.mgmt.network import NetworkManagementClient
from azure.mgmt.resource import ResourceManagementClient,SubscriptionClient
from azure.common.credentials import ServicePrincipalCredentials

credentials = ServicePrincipalCredentials(
        client_id="xxx",secret="xxx",tenant="xxx"
        )

resource_client = ResourceManagementClient(credentials,"my-subscription")
compute_client = ComputeManagementClient(credentials,"my-subscription")
network_client = NetworkManagementClient(credentials,"my-subscription")

for vm in compute_client.virtual_machines.list_all():
    print("\tVM: {}".format(vm.name))

但是由于某些原因,出现以下错误

Traceback (most recent call last):
  File "/Users/me/a/azure-test.py",line 17,in <module>
    for vm in compute_client.virtual_machines.list_all():
...
  File "/usr/local/lib/python3.8/site-packages/azure/core/pipeline/policies/_authentication.py",line 93,in on_request
    self._token = self._credential.get_token(*self._scopes)
AttributeError: 'ServicePrincipalCredentials' object has no attribute 'get_token'

我做错什么了吗?

解决方法

Python的Azure库当前正在更新,以共享常见的云模式,例如身份验证协议,日志记录,跟踪,传输协议,缓冲的响应和重试。

这也会稍微改变身份验证机制。在旧版本中,ServicePrincipalCredentials中的azure.common用于向Azure进行身份验证并创建服务客户端。

在较新的版本中,身份验证机制已经过重新设计,并被azure-identity库代替,以便为所有Azure SDK提供基于Azure身份的统一身份验证。运行pip install azure-identity来获取软件包。

就代码而言,然后是:

from azure.common.credentials import ServicePrincipalCredentials
from azure.mgmt.compute import ComputeManagementClient

credentials = ServicePrincipalCredentials(
    client_id='xxxxx',secret='xxxxx',tenant='xxxxx'
)

compute_client = ComputeManagementClient(
    credentials=credentials,subscription_id=SUBSCRIPTION_ID
)

现在是:

from azure.identity import ClientSecretCredential
from azure.mgmt.compute import ComputeManagementClient

credential = ClientSecretCredential(
    tenant_id='xxxxx',client_id='xxxxx',client_secret='xxxxx'
)

compute_client = ComputeManagementClient(
    credential=credential,subscription_id=SUBSCRIPTION_ID
)

然后您可以将list_all的{​​{1}}方法与往常一样列出所有VM:

compute_client

参考:

,

如果是 Azure 主权云(AZURE_PUBLIC_CLOUDAZURE_CHINA_CLOUDAZURE_US_GOV_CLOUDAZURE_GERMAN_CLOUD),接受的答案将扩展到下面的代码片段。

from azure.identity import ClientSecretCredential
from azure.mgmt.compute import ComputeManagementClient
from msrestazure.azure_cloud import AZURE_US_GOV_CLOUD as cloud_env

credential = ClientSecretCredential(
    tenant_id='xxxxx',client_secret='xxxxx',authority=cloud_env.endpoints.active_directory
)

compute_client = ComputeManagementClient(
    credential=credential,subscription_id=SUBSCRIPTION_ID
    base_url=cloud_env.endpoints.resource_manager,credential_scopes=[cloud_env.endpoints.resource_manager + ".default"]
)