Azure / Azure/azure-powershell
New-AzureRmAutomationModule fails when Storage Account Firewall is enabled
- Dominant language
- C#
- Stars
- 4.8k
- Forks
- 4.3k
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 51
Description
### Description
If the "Firewall" is enabled on the storage account holding the content (zip file of module), I get the following error:
```
Error importing the module MyModule. Import failed with the following error: Orchestrator.Shared.AsyncModuleImport.ModuleImportException: No content was read from the supplied ContentLink. [ContentLink.Uri=https://mysa.blob.core.windows.net/mycontainer/MyModule.zip]
```
The "**Allow trusted Microsoft services to access this storage account**" option is ticked, but unfortunately this doesn't do what one would hope.
If I enter the URL provided in the error, into a browser, I can access the file and the content is as expected.
I have tried adding all IP ranges that you publish for UK South and UK South 2, but this doesn't help.
Initially, I thought this was a DevTest issue, but I have whittled it down to the SA firewall feature, as mentioned [here](https://social.msdn.microsoft.com/Forums/azure/en-US/8378e054-1342-4b29-a70c-1415e024c105/devtest-labs-newazurermautomationmodule-cmdlet-fails?forum=azureautomation).
### Script/Steps for Reproduction
```powershell
$ContentLink = "https://mysa.blob.core.windows.net/mycontainer/MyModule.zip"
New-AzureRmAutomationModule `
-ResourceGroupName "MyAARGName" `
-AutomationAccountName "MyAAName" `
-Name "MyModule" `
-ContentLink $ContentLink `
-Verbose
```
Please note, the error (above) comes from the portal. There is no way (that I can work out) to get the same error in PowerShell. All this PS cmdlet returns is "failed", same with `Get-AzureRmAutomationModule`
### Module Version
```powershell
PS R:\> Get-Module -Name AzureRM -ListAvailable
Directory: C:\Program Files\WindowsPowerShell\Modules
ModuleType Version Name ExportedCommands
---------- ------- ---- ----------------
Script 5.6.0 AzureRM
```
### Environment Data
```powershell
PS R:\> $PSVersionTable
Name Value
---- -----
PSVersion 5.1.14409.1012
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.14409.1012
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
```
### Debug Output
```
PS R:\> $ContentLink = "https://mysa.blob.core.windows.net/mycontainer/MyModule.zip"
New-AzureRmAutomationModule `
-ResourceGroupName "MyAARGName" `
-AutomationAccountName "MyAAName" `
-Name "MyModule" `
-ContentLink $ContentLink `
-Verbose `
-Debug
DEBUG: 19:34:36 - NewAzureAutomationModule begin processing with ParameterSet '__AllParameterSets'.
DEBUG: 19:34:39 - using account id 'myuser@arcotek.co.uk'...
DEBUG: [Common.Authentication]: Authenticating using Account: 'myuser@arcotek.co.uk', environment: 'AzureCloud', tenant: 'a123456-b789-c101-d012-e123456789fa'
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: - TokenCache: Serializing token cache with 2 items.
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: - TokenCache: Serializing token cache with 2 items.
DEBUG: [Common.Authentication]: Authenticating using configuration values: Domain: 'a123456-b789-c101-d012-e123456789fa', Endpoint: 'https://login.microsoftonline.com/', ClientId: '1950a258-227b-4e31-a9cf-717495945fc2', ClientRedirect: 'urn:ietf:wg:oauth:2.0:oob', ResourceClient
Uri: 'https://management.core.windows.net/', ValidateAuthrity: 'True'
DEBUG: [Common.Authentication]: Acquiring token using context with Authority 'https://login.microsoftonline.com/a123456-b789-c101-d012-e123456789fa/', CorrelationId: '00000000-0000-0000-0000-000000000000', ValidateAuthority: 'True'
DEBUG: [Common.Authentication]: Acquiring token using AdalConfiguration with Domain: 'a123456-b789-c101-d012-e123456789fa', AdEndpoint: 'https://login.microsoftonline.com/', ClientId: 'b234567-c789-d101-e012-f123456789ab', ClientRedirectUri: urn:ietf:wg:oauth:2.0:oob
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - AcquireTokenHandlerBase: === Token Acquisition started:
Authority: https://login.microsoftonline.com/a123456-b789-c101-d012-e123456789fa/
Resource: https://management.core.windows.net/
ClientId: b234567-c789-d101-e012-f123456789ab
CacheType: Microsoft.Azure.Commands.Common.Authentication.AuthenticationStoreTokenCache (2 items)
Authentication Target: User
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Verbose: 1 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: Looking up cache for a token...
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: An item matching the requested resource was found in the cache
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Verbose: 1 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: 47.1654683416667 minutes left until token in cache expires
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: A matching item (access token or refresh token or both) was found in the cache
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - AcquireTokenHandlerBase: === Token Acquisition finished successfully. An access token was retuned:
Access Token Hash: tRRT1LMjlzo1x2o5OGYU+YcsxfQbmJfurFQQJX3ZHR0=
Refresh Token Hash: zml3qMhS5jorwE2q01GH+pibOY9db+/67PFLAiZ6/v0=
Expiration Time: 04/06/2018 19:21:49 +00:00
User Hash: IYpW8WL02laukR6oQHMcrkRbPaqdrHxVxWI5uzyJLc=
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: - TokenCache: Serializing token cache with 2 items.
DEBUG: [Common.Authentication]: Received token with LoginType 'LiveId', Tenant: 'a123456-b789-c101-d012-e123456789fa', UserId: 'myuser@arcotek.co.uk'
DEBUG: [Common.Authentication]: Renewing Token with Type: 'Bearer', Expiry: '04/06/2018 19:21:49 +00:00', MultipleResource? 'True', Tenant: 'a123456-b789-c101-d012-e123456789fa', UserId: 'myuser@arcotek.co.uk'
DEBUG: [Common.Authentication]: User info for token DisplayId: 'myuser@arcotek.co.uk', Name: My Name, IdProvider: 'https://sts.windows.net/a123456-b789-c101-d012-e123456789fa/', Uid: 'e987654-f789-a101-b012-c123456789de'
DEBUG: [Common.Authentication]: Checking token expiration, token expires '04/06/2018 19:21:49 +00:00' Comparing to '04/06/2018 18:34:39 +00:00' With threshold '00:05:00', calculated time until token expiry: '00:47:09.9261003'
DEBUG: ============================ HTTP REQUEST ============================
HTTP Method:
PUT
Absolute Uri:
https://management.azure.com/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule?api-version=2015-10-31
Headers:
Accept : application/json
x-ms-version : 2014-06-01
Body:
{
"properties": {
"contentLink": {
"uri": "https://mysa.blob.core.windows.net/mycontainer/MyModule.zip"
}
},
"name": "MyModule",
"tags": {}
}
DEBUG: ============================ HTTP RESPONSE ============================
Status Code:
OK
Headers:
Pragma : no-cache
x-ms-request-id : a2aa1fe8-13b2-4e75-8610-20551537c6dc
Strict-Transport-Security : max-age=31536000; includeSubDomains
x-ms-ratelimit-remaining-subscription-writes: 1199
x-ms-correlation-request-id : 26f96ec8-89d3-475c-a9ec-286eb237328a
x-ms-routing-request-id : UKSOUTH:20180406T183440Z:26f96ec8-89d3-475c-a9ec-286eb237328a
X-Content-Type-Options : nosniff
Cache-Control : no-cache
Date : Fri, 06 Apr 2018 18:34:40 GMT
Server : Microsoft-IIS/8.5
X-AspNet-Version : 4.0.30319
X-Powered-By : ASP.NET
Body:
{
"id": "/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule",
"name": "MyModule",
"type": "Microsoft.Automation/AutomationAccounts/Modules",
"location": "westeurope",
"tags": {},
"etag": null,
"properties": {
"isGlobal": false,
"version": null,
"sizeInBytes": 0,
"activityCount": 0,
"creationTime": "2018-04-06T01:26:17.95+01:00",
"lastModifiedTime": "2018-04-06T19:34:40.55+01:00",
"error": {
"code": null,
"message": null
},
"provisioningState": "Creating"
}
}
DEBUG: [Common.Authentication]: Renewing Token with Type: 'Bearer', Expiry: '04/06/2018 19:21:49 +00:00', MultipleResource? 'True', Tenant: 'a123456-b789-c101-d012-e123456789fa', UserId: 'myuser@arcotek.co.uk'
DEBUG: [Common.Authentication]: User info for token DisplayId: 'myuser@arcotek.co.uk', Name: My Name, IdProvider: 'https://sts.windows.net/a123456-b789-c101-d012-e123456789fa/', Uid: 'e987654-f789-a101-b012-c123456789de'
DEBUG: [Common.Authentication]: Checking token expiration, token expires '04/06/2018 19:21:49 +00:00' Comparing to '04/06/2018 18:34:40 +00:00' With threshold '00:05:00', calculated time until token expiry: '00:47:08.4209498'
DEBUG: ============================ HTTP REQUEST ============================
HTTP Method:
GET
Absolute Uri:
https://management.azure.com/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule?api-version=2015-10-31
Headers:
Accept : application/json
x-ms-version : 2014-06-01
Body:
DEBUG: ============================ HTTP RESPONSE ============================
Status Code:
OK
Headers:
Pragma : no-cache
x-ms-request-id : a2aa1fe8-13b2-4e75-8610-20551537c6dc
Strict-Transport-Security : max-age=31536000; includeSubDomains
x-ms-ratelimit-remaining-subscription-reads: 14999
x-ms-correlation-request-id : 0bc7b03a-bc3f-40fa-bccc-f6d810c0baf6
x-ms-routing-request-id : UKSOUTH:20180406T183441Z:0bc7b03a-bc3f-40fa-bccc-f6d810c0baf6
X-Content-Type-Options : nosniff
Cache-Control : no-cache
Date : Fri, 06 Apr 2018 18:34:40 GMT
Server : Microsoft-IIS/8.5
X-AspNet-Version : 4.0.30319
X-Powered-By : ASP.NET
Body:
{
"id": "/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule",
"name": "MyModule",
"type": "Microsoft.Automation/AutomationAccounts/Modules",
"location": "westeurope",
"tags": {},
"etag": null,
"properties": {
"isGlobal": false,
"version": "1.0.7.5",
"sizeInBytes": 123229,
"activityCount": 17,
"creationTime": "2018-04-06T01:26:17.95+01:00",
"lastModifiedTime": "2018-04-06T19:34:40.55+01:00",
"error": {
"code": null,
"message": ""
},
"provisioningState": "Creating"
}
}
ResourceGroupName : myAARGName
AutomationAccountName : myAAName
Name : MyModule
IsGlobal : False
Version : 1.0.7.5
SizeInBytes : 123229
ActivityCount : 17
CreationTime : 06/04/2018 01:26:17 +01:00
LastModifiedTime : 06/04/2018 19:34:40 +01:00
ProvisioningState : Creating
DEBUG: AzureQoSEvent: CommandName - New-AzureRmAutomationModule; IsSuccess - True; Duration - 00:00:04.6219875; Exception - ;
DEBUG: Finish sending metric.
DEBUG: 19:34:43 - NewAzureAutomationModule end processing.
DEBUG: 19:34:43 - NewAzureAutomationModule end processing.
```
Contributor guide
Assessment
This issue has not been assessed yet.