You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps流水线AzureKeyVault@2预作业模式权限错误排查

问题分析与解决方案建议

问题场景

在Azure DevOps流水线中配置了如下Azure Key Vault任务,设置RunAsPreJob: true以在后续作业任务中使用密钥变量,但预作业执行时报错:

- task: AzureKeyVault@2
  displayName: 'Fetch secrets from KeyVault used in Deploy stage'
  inputs:
    azureSubscription: '$(AzureServiceConnectionName)'
    KeyVaultName: '$(AzureKeyVaultName)'
    SecretsFilter: '*'  # Fetch all secrets
    RunAsPreJob: true
# Note: all the variables above are correctly resolving.

错误日志如下:

Pre-job: Fetch secrets from KeyVault used in Deploy stage

View raw log

Starting: Fetch secrets from KeyVault used in Deploy stage
==============================================================================
Task         : Azure Key Vault
Description  : Download Azure Key Vault secrets
Version      : 2.249.1
Author       : Microsoft Corporation
Help         : https://docs.microsoft.com/azure/devops/pipelines/tasks/deploy/azure-key-vault
==============================================================================
SubscriptionId: <not-the-actual-value>.
Key vault name: <not-the-actual-value>.
Downloading secrets using: https://<not-the-actual-value>.vault.azure.net/secrets?maxresults=25&api-version=2016-10-01.
##[error]Get secrets failed. Error: Client address is not authorized and caller is not a trusted service.
Client address: <not-the-actual-value>
Caller: appid=***;oid=<not-the-actual-value>;iss=https://sts.windows.net/<not-the-actual-value>/
Vault: <not-the-actual-value>;location=westeurope. The specified Azure service connection needs to have Get, List secret management permissions on the selected key vault. To set these permissions, download the ProvisionKeyVaultPermissions.ps1 script from build/release logs and execute it, or set them from the Azure portal..
Uploading /home/vsts/work/1/ProvisionKeyVaultPermissions.ps1 as attachment
Finishing: Fetch secrets from KeyVault used in Deploy stage

已尝试的操作:

  • 成功运行ProvisionKeyVaultPermissions.ps1脚本添加Key Vault访问策略
  • 手动添加过访问策略
  • 尝试使用链接Key Vault的变量组作为替代方案,未成功
  • 当RunAsPreJob: false时任务可正常运行

可能的原因及解决办法

1. 预作业的网络访问限制

当RunAsPreJob: true时,任务在独立的预作业容器/虚拟机中运行,其出站IP地址可能与主作业不同。如果Key Vault配置了防火墙/虚拟网络限制,需要将预作业的IP地址加入允许列表:

  • 提取错误日志中的Client address,将该IP添加到Key Vault的防火墙允许规则中
  • 如果使用Microsoft托管代理,可查询对应区域的托管代理出站IP范围,将整个范围加入允许列表

2. 服务连接权限的作用范围问题

确认服务连接的服务主体是否拥有Key Vault的Get、List权限,且权限应用范围正确:

  • 检查Key Vault的访问策略,确保服务主体的权限覆盖所有目标密钥(或设置为所有对象)
  • 如果使用Azure RBAC而非访问策略,需确认服务主体被分配了Key Vault Secrets User或更高权限的角色

3. 任务版本或执行环境差异

预作业任务的执行环境可能与主作业存在差异,尝试以下操作:

  • 调整AzureKeyVault任务版本(当前版本为2.249.1),测试是否为版本兼容性问题
  • 检查流水线代理池配置,确认预作业和主作业使用同一代理池(尤其是自托管代理场景)

4. 缓存或权限生效延迟

有时Azure权限变更需要一定时间生效,可尝试:

  • 等待10-15分钟后重新运行流水线
  • 重启自托管Azure DevOps代理(若使用自托管代理)
  • 重新创建服务连接,确保新连接的权限正确应用

内容的提问来源于stack exchange,提问作者Paula Gouveia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 11:33:17