You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure DevOps REST API实现环境审批自动化遇阻及用户Descriptor获取报错

Azure DevOps环境审批门自动化及用户Descriptor获取问题解决

一、修复用户Descriptor获取错误

你当前调用Graph API获取用户descriptor时出现错误,原因是误用了POST请求并传递了不符合要求的Body参数。正确的做法是使用GET请求调用用户查询接口,无需提交JSON Body。

修正后的PowerShell代码

Write-Host "Fetching user descriptor for $userName..."
try {
    # 构造GET请求URI,直接通过searchValue参数传递用户名
    $uri = "https://vssps.dev.azure.com/$organization/_apis/graph/users?searchValue=$userName&api-version=7.2-preview.1"
    $response = Invoke-RestMethod -Method GET -Headers $headers -Uri $uri
    
    $approverDescriptor = $response.value[0].descriptor
    if ([string]::IsNullOrWhiteSpace($approverDescriptor)) {
        Write-Error "Approver descriptor is empty."
        exit 1
    }

    Write-Host "Approver Descriptor: $approverDescriptor"
}
catch {
    Write-Error "Failed to retrieve user descriptor: $_"
    exit 1
}

二、通过REST API自动化添加环境审批门

可以通过Azure DevOps REST API实现环境审批门的自动化配置,核心是调用流水线Checks配置接口。

实现步骤

  1. 获取环境ID:创建环境后,通过以下GET请求获取目标环境的ID:

    GET https://dev.azure.com/{organization}/{project}/_apis/distributedtask/environments?api-version=7.2-preview.1
    
  2. 调用Checks接口添加审批门:

    • 端点:POST https://dev.azure.com/{organization}/{project}/_apis/pipelines/checks/configurations?api-version=7.2-preview.1
    • 请求Body需包含审批人信息、环境ID和审批门配置

PowerShell示例代码

# 替换为你的实际参数
$organization = "your-organization-name"
$project = "your-project-name"
$environmentId = "123" # 替换为目标环境的ID
$approverDescriptor = "aad.NTlkNzE1Yz..." # 替换为之前获取的用户descriptor

# 构造请求头(流水线中可使用系统AccessToken,本地测试用PAT)
$headers = @{
    "Authorization" = "Bearer $env:SYSTEM_ACCESSTOKEN"
    "Content-Type" = "application/json"
}

# 构造审批门配置Body
$body = @{
    type = @{
        id = "fd2167ab-b0be-447a-8ec8-39368250530e" # 固定的人工审批类型ID
    }
    settings = @{
        approvers = @(
            @{
                descriptor = $approverDescriptor
            }
        )
        executionOrder = "beforeGate" # 在部署前触发审批
        isEnabled = $true
        notificationType = "noNotification" # 可根据需求调整为"email"
        requesterCannotBeApprover = $false
        timeout = 43200 # 超时时间(分钟),此处为30天
    }
    resource = @{
        type = "environment"
        id = $environmentId
    }
} | ConvertTo-Json -Depth 10

try {
    $uri = "https://dev.azure.com/$organization/$project/_apis/pipelines/checks/configurations?api-version=7.2-preview.1"
    $response = Invoke-RestMethod -Method POST -Headers $headers -Body $body -Uri $uri
    Write-Host "Approval gate added successfully with ID: $($response.id)"
}
catch {
    Write-Error "Failed to add approval gate: $_"
    exit 1
}

注意事项

  • 确保使用的令牌(PAT或系统AccessToken)拥有Environment Manage和Pipeline Edit权限
  • 若需添加组作为审批人,只需将approvers中的descriptor替换为组的descriptor(通过Graph API查询组信息获取)
  • 审批门类型ID fd2167ab-b0be-447a-8ec8-39368250530e 是Azure DevOps中固定的“人工审批”类型标识

内容的提问来源于stack exchange,提问作者Riyo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 10:04:56