使用Azure DevOps REST API实现环境审批自动化遇阻及用户Descriptor获取报错
Azure DevOps环境审批门自动化及用户Descriptor获取问题解决
一、修复用户Descriptor获取错误
你当前调用Graph API获取用户descriptor时出现错误,原因是误用了POST请求并传递了不符合要求的Body参数。正确的做法是使用GET请求调用用户查询接口,无需提交JSON Body。
修正后的PowerShell代码
Write-Host "Fetching user descriptor for $userName..." try { # 构造GET请求URI,直接通过searchValue参数传递用户名 $uri = "https://vssps.dev.azure.com/$organization/_apis/graph/users?searchValue=$userName&api-version=7.2-preview.1" $response = Invoke-RestMethod -Method GET -Headers $headers -Uri $uri $approverDescriptor = $response.value[0].descriptor if ([string]::IsNullOrWhiteSpace($approverDescriptor)) { Write-Error "Approver descriptor is empty." exit 1 } Write-Host "Approver Descriptor: $approverDescriptor" } catch { Write-Error "Failed to retrieve user descriptor: $_" exit 1 }
二、通过REST API自动化添加环境审批门
可以通过Azure DevOps REST API实现环境审批门的自动化配置,核心是调用流水线Checks配置接口。
实现步骤
获取环境ID:创建环境后,通过以下GET请求获取目标环境的ID:
GET https://dev.azure.com/{organization}/{project}/_apis/distributedtask/environments?api-version=7.2-preview.1调用Checks接口添加审批门:
- 端点:
POST https://dev.azure.com/{organization}/{project}/_apis/pipelines/checks/configurations?api-version=7.2-preview.1 - 请求Body需包含审批人信息、环境ID和审批门配置
- 端点:
PowerShell示例代码
# 替换为你的实际参数 $organization = "your-organization-name" $project = "your-project-name" $environmentId = "123" # 替换为目标环境的ID $approverDescriptor = "aad.NTlkNzE1Yz..." # 替换为之前获取的用户descriptor # 构造请求头(流水线中可使用系统AccessToken,本地测试用PAT) $headers = @{ "Authorization" = "Bearer $env:SYSTEM_ACCESSTOKEN" "Content-Type" = "application/json" } # 构造审批门配置Body $body = @{ type = @{ id = "fd2167ab-b0be-447a-8ec8-39368250530e" # 固定的人工审批类型ID } settings = @{ approvers = @( @{ descriptor = $approverDescriptor } ) executionOrder = "beforeGate" # 在部署前触发审批 isEnabled = $true notificationType = "noNotification" # 可根据需求调整为"email" requesterCannotBeApprover = $false timeout = 43200 # 超时时间(分钟),此处为30天 } resource = @{ type = "environment" id = $environmentId } } | ConvertTo-Json -Depth 10 try { $uri = "https://dev.azure.com/$organization/$project/_apis/pipelines/checks/configurations?api-version=7.2-preview.1" $response = Invoke-RestMethod -Method POST -Headers $headers -Body $body -Uri $uri Write-Host "Approval gate added successfully with ID: $($response.id)" } catch { Write-Error "Failed to add approval gate: $_" exit 1 }
注意事项
- 确保使用的令牌(PAT或系统AccessToken)拥有Environment Manage和Pipeline Edit权限
- 若需添加组作为审批人,只需将
approvers中的descriptor替换为组的descriptor(通过Graph API查询组信息获取) - 审批门类型ID
fd2167ab-b0be-447a-8ec8-39368250530e是Azure DevOps中固定的“人工审批”类型标识
内容的提问来源于stack exchange,提问作者Riyo
相关产品推荐
相关产品推荐

