You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipeline Git Submodule更新认证失败排查求助

Azure DevOps Pipeline子模块拉取认证失败问题

错误输出

......
git submodule sync
Synchronizing submodule url for 'submodule01'
Synchronizing submodule url for 'submodule02'
Synchronizing submodule url for 'submodule03'
Synchronizing submodule url for 'submodule04'
Synchronizing submodule url for 'submodule05'
git --config-env=http.https://myorg@dev.azure.com.extraheader=env_var_http.https://myorg@dev.azure.com.extraheader submodule update --init --force --depth=1
fatal: Cannot prompt because terminal prompts have been disabled.
fatal: Cannot prompt because terminal prompts have been disabled.
fatal: could not read Username for 'https://myorg.visualstudio.com': terminal prompts disabled
Unable to fetch in submodule path 'submodue01'; trying to directly fetch 834654e979acb0c929794db7261e6f8a73b6e37e:
fatal: Cannot prompt because terminal prompts have been disabled.
fatal: Cannot prompt because terminal prompts have been disabled.
fatal: could not read Username for 'https://myorg.visualstudio.com': terminal prompts disabled
fatal: Fetched in submodule path 'submodue01', but it did not contain 834654e979acb0c929794db7261e6f8a73b6e37e. Direct fetching of that commit failed.
##[error]Git submodule update failed with exit code: 128

所有代码库均位于同一个Azure DevOps项目中。按预期,git --config-env命令应从环境变量获取认证令牌并配置到Git,用于子模块身份认证;若令牌为空应抛出异常,但实际并未出现该情况,反而因终端无法弹出凭据输入提示导致认证失败。

已完成的配置

代码库权限配置

  • 每个子模块代码库:项目设置>代码库>安全>[对应子模块代码库]的Build Service账号,已验证继承自Project Collection Build Service Accounts的Allow权限
  • Project Collection Build Service Accounts:项目设置>代码库>安全中,已授予Contribute、Create branch、Create tag和Read权限
  • 代码库Pipeline权限:项目设置>代码库>Pipeline权限中,已添加当前运行的Pipeline

Pipeline全局设置

  • 项目设置>Pipelines>设置>保护对YAML Pipeline中代码库的访问:已关闭

Pipeline YAML配置

steps:
- checkout: self
  submodules: true
  persistCredentials: true

显式代码库资源引用

resources:
  repositories:
    - repository: name
      type: git
      name: project/_git/repo

.gitmodules文件内容

[submodule "submodue01"]
    path = submodue01
    url = https://myorg.visualstudio.com/repos/_git/submodue01
[submodule "submodue02"]
    path = submodue02
    url = https://myorg.visualstudio.com/repos/_git/submodue02
[submodule "submodue03"]
    path = submodue03
    url = https://myorg.visualstudio.com/repos/_git/submodue03
[submodule "submodue04"]
    path = submodue04
    url = https://myorg.visualstudio.com/repos/_git/submodue04
[submodule "submodue05"]
    path = submodue05
    url = https://myorg.visualstudio.com/repos/_git/submodue05

已尝试的操作

  • 创建新Pipeline(相同定义、相同代理、新工作区),问题依旧存在
  • 该问题为新出现情况,此前Pipeline运行正常
  • 若提前手动拉取所需提交到本地,Pipeline可成功检出目标提交

疑问

已查阅相关讨论,提到SSH或手动添加PAT的解决方案,但希望使用微软原生机制解决问题,请问还遗漏了哪些配置?


内容的提问来源于stack exchange,提问作者Adam Winter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 04:25:19