Azure环境下Maven release:perform无法完成git checkout问题
Azure DevOps中Maven release:perform执行git checkout失败的解决办法
问题场景
在Azure DevOps流水线中,已经通过MavenAuthenticate任务完成了release:prepare和git push --follow-tags操作,但执行release:perform目标时,SCM拉取环节报错,无法读取HTTPS凭证,错误日志如下:
[INFO] --- release:3.0.1:perform (default-cli) @ APPLICATION --- [INFO] starting perform goal, composed of 3 phases: verify-completed-prepare-phases, checkout-project-from-scm, run-perform-goals [INFO] 1/3 perform:verify-completed-prepare-phases [INFO] 2/3 perform:checkout-project-from-scm [INFO] Checking out the project to perform the release ... [INFO] Executing: /bin/sh -c cd '/azp/_work/1/s/target' && 'git' 'clone' '--depth' '1' '--branch' '1.1.1' 'https:********@dev.azure.com/APPLICATION-LOCATION-IN-REPO' 'checkout' [INFO] Working directory: /azp/_work/1/s/target [ERROR] The git-clone command failed. ... [ERROR] fatal: could not read Password for 'https:********@dev.azure.com': terminal prompts disabled
原因分析
MavenAuthenticate任务仅为Maven仓库的认证提供凭证,不会自动将凭证注入Git的SCM操作流程。release:perform默认会在target目录下重新克隆指定版本的代码,此时Git无可用凭证,且流水线环境禁用了终端交互提示,最终导致认证失败。
解决方法
方法1:配置Git自动使用流水线令牌认证
在release:perform任务前添加Bash任务,配置Git凭证助手,让它自动调用Azure DevOps流水线的系统访问令牌:
- bash: | git config --global credential.helper "!f() { echo username=; echo password=$(System.AccessToken); }; f" displayName: 'Configure Git credential helper for Azure DevOps'
System.AccessToken是Azure DevOps自动生成的内置变量,拥有当前仓库的读写权限,Git克隆时会自动用这个令牌完成认证。
方法2:直接给Maven命令传递凭证参数
修改release:perform的Maven任务,通过参数直接传递凭证信息:
- task: Maven@4 displayName: Release perf inputs: goals: 'release:perform -Dusername= -Dpassword=$(System.AccessToken)'
注:Azure DevOps的令牌认证不需要填写真实用户名,留空即可。
方法3:复用现有代码目录,跳过重新克隆
release:perform默认会重新克隆代码,我们可以指定直接使用流水线当前的代码目录,避免克隆操作:
- task: Maven@4 displayName: Release perf inputs: goals: 'release:perform -DcheckoutDirectory=$(Build.SourcesDirectory)'
$(Build.SourcesDirectory)是流水线的代码根目录,直接复用已拉取的代码,自然就不会遇到克隆时的凭证问题。
内容的提问来源于stack exchange,提问作者Polostor
相关产品推荐
相关产品推荐

