Azure / Azure/azure-powershell

New-AzureRmAutomationModule fails when Storage Account Firewall is enabled

Open
#5,885 15 comments 0 reactions 0 assignees View on GitHub
act-codegen-extensibility-squad Automation automation-modules Resolution - Investigation Service Attention
Dominant language
C#
Stars
4.8k
Forks
4.3k
Avg merge
2d 17h
Merged PRs (30d)
51

Description

### Description

If the "Firewall" is enabled on the storage account holding the content (zip file of module), I get the following error:
```
Error importing the module MyModule. Import failed with the following error: Orchestrator.Shared.AsyncModuleImport.ModuleImportException: No content was read from the supplied ContentLink. [ContentLink.Uri=https://mysa.blob.core.windows.net/mycontainer/MyModule.zip]
```
The "**Allow trusted Microsoft services to access this storage account**" option is ticked, but unfortunately this doesn't do what one would hope.

If I enter the URL provided in the error, into a browser, I can access the file and the content is as expected.

I have tried adding all IP ranges that you publish for UK South and UK South 2, but this doesn't help.

Initially, I thought this was a DevTest issue, but I have whittled it down to the SA firewall feature, as mentioned [here](https://social.msdn.microsoft.com/Forums/azure/en-US/8378e054-1342-4b29-a70c-1415e024c105/devtest-labs-newazurermautomationmodule-cmdlet-fails?forum=azureautomation).

### Script/Steps for Reproduction

```powershell

$ContentLink = "https://mysa.blob.core.windows.net/mycontainer/MyModule.zip"

New-AzureRmAutomationModule `
-ResourceGroupName "MyAARGName" `
-AutomationAccountName "MyAAName" `
-Name "MyModule" `
-ContentLink $ContentLink `
-Verbose
```
Please note, the error (above) comes from the portal. There is no way (that I can work out) to get the same error in PowerShell. All this PS cmdlet returns is "failed", same with `Get-AzureRmAutomationModule`
### Module Version

```powershell
PS R:\> Get-Module -Name AzureRM -ListAvailable

Directory: C:\Program Files\WindowsPowerShell\Modules

ModuleType Version Name ExportedCommands
---------- ------- ---- ----------------
Script 5.6.0 AzureRM
```

### Environment Data

```powershell
PS R:\> $PSVersionTable

Name Value
---- -----
PSVersion 5.1.14409.1012
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.14409.1012
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
```

### Debug Output

```
PS R:\> $ContentLink = "https://mysa.blob.core.windows.net/mycontainer/MyModule.zip"

New-AzureRmAutomationModule `
-ResourceGroupName "MyAARGName" `
-AutomationAccountName "MyAAName" `
-Name "MyModule" `
-ContentLink $ContentLink `
-Verbose `
-Debug
DEBUG: 19:34:36 - NewAzureAutomationModule begin processing with ParameterSet '__AllParameterSets'.
DEBUG: 19:34:39 - using account id 'myuser@arcotek.co.uk'...
DEBUG: [Common.Authentication]: Authenticating using Account: 'myuser@arcotek.co.uk', environment: 'AzureCloud', tenant: 'a123456-b789-c101-d012-e123456789fa'
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: - TokenCache: Serializing token cache with 2 items.

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: - TokenCache: Serializing token cache with 2 items.

DEBUG: [Common.Authentication]: Authenticating using configuration values: Domain: 'a123456-b789-c101-d012-e123456789fa', Endpoint: 'https://login.microsoftonline.com/', ClientId: '1950a258-227b-4e31-a9cf-717495945fc2', ClientRedirect: 'urn:ietf:wg:oauth:2.0:oob', ResourceClient
Uri: 'https://management.core.windows.net/', ValidateAuthrity: 'True'
DEBUG: [Common.Authentication]: Acquiring token using context with Authority 'https://login.microsoftonline.com/a123456-b789-c101-d012-e123456789fa/', CorrelationId: '00000000-0000-0000-0000-000000000000', ValidateAuthority: 'True'
DEBUG: [Common.Authentication]: Acquiring token using AdalConfiguration with Domain: 'a123456-b789-c101-d012-e123456789fa', AdEndpoint: 'https://login.microsoftonline.com/', ClientId: 'b234567-c789-d101-e012-f123456789ab', ClientRedirectUri: urn:ietf:wg:oauth:2.0:oob
DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - AcquireTokenHandlerBase: === Token Acquisition started:
Authority: https://login.microsoftonline.com/a123456-b789-c101-d012-e123456789fa/
Resource: https://management.core.windows.net/
ClientId: b234567-c789-d101-e012-f123456789ab
CacheType: Microsoft.Azure.Commands.Common.Authentication.AuthenticationStoreTokenCache (2 items)
Authentication Target: User

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Verbose: 1 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: Looking up cache for a token...

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: An item matching the requested resource was found in the cache

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Verbose: 1 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: 47.1654683416667 minutes left until token in cache expires

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - TokenCache: A matching item (access token or refresh token or both) was found in the cache

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: c345678-d789-e101-f012-a123456789bc - AcquireTokenHandlerBase: === Token Acquisition finished successfully. An access token was retuned:
Access Token Hash: tRRT1LMjlzo1x2o5OGYU+YcsxfQbmJfurFQQJX3ZHR0=
Refresh Token Hash: zml3qMhS5jorwE2q01GH+pibOY9db+/67PFLAiZ6/v0=
Expiration Time: 04/06/2018 19:21:49 +00:00
User Hash: IYpW8WL02laukR6oQHMcrkRbPaqdrHxVxWI5uzyJLc=

DEBUG: Microsoft.IdentityModel.Clients.ActiveDirectory Information: 2 :
DEBUG: 04/06/2018 18:34:39: - TokenCache: Serializing token cache with 2 items.

DEBUG: [Common.Authentication]: Received token with LoginType 'LiveId', Tenant: 'a123456-b789-c101-d012-e123456789fa', UserId: 'myuser@arcotek.co.uk'
DEBUG: [Common.Authentication]: Renewing Token with Type: 'Bearer', Expiry: '04/06/2018 19:21:49 +00:00', MultipleResource? 'True', Tenant: 'a123456-b789-c101-d012-e123456789fa', UserId: 'myuser@arcotek.co.uk'
DEBUG: [Common.Authentication]: User info for token DisplayId: 'myuser@arcotek.co.uk', Name: My Name, IdProvider: 'https://sts.windows.net/a123456-b789-c101-d012-e123456789fa/', Uid: 'e987654-f789-a101-b012-c123456789de'
DEBUG: [Common.Authentication]: Checking token expiration, token expires '04/06/2018 19:21:49 +00:00' Comparing to '04/06/2018 18:34:39 +00:00' With threshold '00:05:00', calculated time until token expiry: '00:47:09.9261003'
DEBUG: ============================ HTTP REQUEST ============================

HTTP Method:
PUT

Absolute Uri:
https://management.azure.com/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule?api-version=2015-10-31

Headers:
Accept : application/json
x-ms-version : 2014-06-01

Body:
{
"properties": {
"contentLink": {
"uri": "https://mysa.blob.core.windows.net/mycontainer/MyModule.zip"
}
},
"name": "MyModule",
"tags": {}
}

DEBUG: ============================ HTTP RESPONSE ============================

Status Code:
OK

Headers:
Pragma : no-cache
x-ms-request-id : a2aa1fe8-13b2-4e75-8610-20551537c6dc
Strict-Transport-Security : max-age=31536000; includeSubDomains
x-ms-ratelimit-remaining-subscription-writes: 1199
x-ms-correlation-request-id : 26f96ec8-89d3-475c-a9ec-286eb237328a
x-ms-routing-request-id : UKSOUTH:20180406T183440Z:26f96ec8-89d3-475c-a9ec-286eb237328a
X-Content-Type-Options : nosniff
Cache-Control : no-cache
Date : Fri, 06 Apr 2018 18:34:40 GMT
Server : Microsoft-IIS/8.5
X-AspNet-Version : 4.0.30319
X-Powered-By : ASP.NET

Body:
{
"id": "/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule",
"name": "MyModule",
"type": "Microsoft.Automation/AutomationAccounts/Modules",
"location": "westeurope",
"tags": {},
"etag": null,
"properties": {
"isGlobal": false,
"version": null,
"sizeInBytes": 0,
"activityCount": 0,
"creationTime": "2018-04-06T01:26:17.95+01:00",
"lastModifiedTime": "2018-04-06T19:34:40.55+01:00",
"error": {
"code": null,
"message": null
},
"provisioningState": "Creating"
}
}

DEBUG: [Common.Authentication]: Renewing Token with Type: 'Bearer', Expiry: '04/06/2018 19:21:49 +00:00', MultipleResource? 'True', Tenant: 'a123456-b789-c101-d012-e123456789fa', UserId: 'myuser@arcotek.co.uk'
DEBUG: [Common.Authentication]: User info for token DisplayId: 'myuser@arcotek.co.uk', Name: My Name, IdProvider: 'https://sts.windows.net/a123456-b789-c101-d012-e123456789fa/', Uid: 'e987654-f789-a101-b012-c123456789de'
DEBUG: [Common.Authentication]: Checking token expiration, token expires '04/06/2018 19:21:49 +00:00' Comparing to '04/06/2018 18:34:40 +00:00' With threshold '00:05:00', calculated time until token expiry: '00:47:08.4209498'
DEBUG: ============================ HTTP REQUEST ============================

HTTP Method:
GET

Absolute Uri:
https://management.azure.com/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule?api-version=2015-10-31

Headers:
Accept : application/json
x-ms-version : 2014-06-01

Body:

DEBUG: ============================ HTTP RESPONSE ============================

Status Code:
OK

Headers:
Pragma : no-cache
x-ms-request-id : a2aa1fe8-13b2-4e75-8610-20551537c6dc
Strict-Transport-Security : max-age=31536000; includeSubDomains
x-ms-ratelimit-remaining-subscription-reads: 14999
x-ms-correlation-request-id : 0bc7b03a-bc3f-40fa-bccc-f6d810c0baf6
x-ms-routing-request-id : UKSOUTH:20180406T183441Z:0bc7b03a-bc3f-40fa-bccc-f6d810c0baf6
X-Content-Type-Options : nosniff
Cache-Control : no-cache
Date : Fri, 06 Apr 2018 18:34:40 GMT
Server : Microsoft-IIS/8.5
X-AspNet-Version : 4.0.30319
X-Powered-By : ASP.NET

Body:
{
"id": "/subscriptions/d456789-e789-f101-a012-b123456789cd/resourceGroups/myAARGName/providers/Microsoft.Automation/automationAccounts/myAAName/modules/MyModule",
"name": "MyModule",
"type": "Microsoft.Automation/AutomationAccounts/Modules",
"location": "westeurope",
"tags": {},
"etag": null,
"properties": {
"isGlobal": false,
"version": "1.0.7.5",
"sizeInBytes": 123229,
"activityCount": 17,
"creationTime": "2018-04-06T01:26:17.95+01:00",
"lastModifiedTime": "2018-04-06T19:34:40.55+01:00",
"error": {
"code": null,
"message": ""
},
"provisioningState": "Creating"
}
}

ResourceGroupName : myAARGName
AutomationAccountName : myAAName
Name : MyModule
IsGlobal : False
Version : 1.0.7.5
SizeInBytes : 123229
ActivityCount : 17
CreationTime : 06/04/2018 01:26:17 +01:00
LastModifiedTime : 06/04/2018 19:34:40 +01:00
ProvisioningState : Creating

DEBUG: AzureQoSEvent: CommandName - New-AzureRmAutomationModule; IsSuccess - True; Duration - 00:00:04.6219875; Exception - ;
DEBUG: Finish sending metric.
DEBUG: 19:34:43 - NewAzureAutomationModule end processing.
DEBUG: 19:34:43 - NewAzureAutomationModule end processing.

```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.