You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Release Pipeline跨网络远程执行PowerShell脚本失败解决方案

解决Azure Release Pipeline跨网段远程执行PowerShell脚本失败问题

已知背景

  • 已完成操作:
    • 通过Bash脚本将.dll和PowerShell脚本从GitHub下载至本地代理服务器onPrem1(172.24.243.193)的D:\agent_work\r65\a\DeploymentPackage\ReleaseFiles路径,执行成功
    • 通过Windows Machine File Copy (WinRM)将.dll复制至远程服务器AppServer1(172.26.143.22)的D:\release\,执行成功
  • 问题:使用PowerShell v2.*执行下载的脚本失败,原因是跨网段从onPrem代理访问远程服务器受限
  • 脚本预期功能:检查远程服务器D:\app\下的现有.dll文件,存在则备份;将新.dll从D:\release\复制到D:\app\;重启AKServ服务

核心解决方案

方案1:使用Azure Pipeline「PowerShell on Target Machines」任务(推荐)

该任务通过WinRM直接在目标服务器上执行脚本,规避跨网段共享访问限制,步骤如下:

  1. 新增Windows Machine File Copy任务,将PowerShell脚本和.dll文件一起复制到AppServer1的本地路径(如D:\temp\)
  2. 添加「PowerShell on Target Machines」任务,配置:
    • 目标服务器:填写AppServer1的IP、WinRM端口(默认5985/http或5986/https)
    • 凭据:使用拥有AppServer1管理员权限的账号
    • 脚本路径:指定AppServer1本地的脚本路径(如D:\temp\deploy-script.ps1)
    • 参数:传递脚本所需的变量(如文件名、服务名)

方案2:修正脚本并解除跨网段网络限制

若需保留从代理执行脚本的方式,需同时修复脚本错误和网络限制:

2.1 修正原脚本的语法与逻辑错误

原脚本存在重复函数定义、未定义变量、逻辑错误等问题,修正后的版本如下:

param(
    [String] $appServerName,
    [String] $fileName,
    [String] $username,
    [String] $plaintextPassword
)

function Backup-file {
    param(
        [String] $serverName, 
        [String] $fileName
    )

    $releaseFolderPath = "\\$serverName\d$\app\"
    $backupFileDirectory = "$releaseFolderPath\Backups\"

    Write-Host "Backing up $releaseFolderPath to $backupFileDirectory"

    $releaseFileFullPath = Join-Path -Path $releaseFolderPath -ChildPath $fileName

    if (Test-Path -Path $releaseFileFullPath) {
        Write-Host "File Exists $releaseFileFullPath "
        try {
            # 创建备份目录(不存在则创建)
            if (-not (Test-Path -Path $backupFileDirectory)) {
                New-Item -ItemType Directory -Path $backupFileDirectory
                Write-Host "Backup folder created on $backupFileDirectory"
            }

            # 重命名原文件并移动至备份目录
            $backupFileName = "ABC_" + (Get-Date -Format "yyyyMMddHHmmss") + ".dll"
            Rename-Item -Path $releaseFileFullPath -NewName $backupFileName
            Move-Item -Path (Join-Path $releaseFolderPath $backupFileName) -Destination $backupFileDirectory

            Write-Host "File backup and rename successful in Server !!!"
        } catch {
            Write-Host "Error: $_"
        }
    } else {
        Write-Host "Error: File not found $releaseFileFullPath!!!"
    }
}

function Copy-Source-Files {
    param(
        [String] $serverName,
        [String] $fileName
    )
    try {
        Write-Host "Copy-Source-Files started .."
        $sourceFilePath = "\\$serverName\d$\release\$fileName"
        $destFilePath = "\\$serverName\d$\app\$fileName"

        Write-Host "Copying from $sourceFilePath to $destFilePath"
        Copy-Item -Path $sourceFilePath -Destination $destFilePath -Force
    }
    catch {
        Write-Host "Error occured in Copy-Source-Files $_"
    }
}

function Restart-Service {
    param(
        [String] $ServerName, 
        [String] $ServiceName,
        [String] $username,
        [String] $plaintextPassword
    )
    Write-Host "Restarting $ServiceName of $ServerName"

    $securePassword = ConvertTo-SecureString $plaintextPassword -AsPlainText -Force
    $credential = New-Object System.Management.Automation.PSCredential($username, $securePassword)

    $scriptBlock = {
        param($Service)
        Restart-Service -Name $Service -Force -ErrorAction Stop
    }
    Invoke-Command -ComputerName $ServerName -ScriptBlock $scriptBlock -ArgumentList $ServiceName -Credential $credential -ErrorAction Stop
}

try {
    Write-Host "Processing Started...."

    Backup-file -serverName $appServerName -fileName $fileName

    Copy-Source-Files -serverName $appServerName -fileName $fileName

    Restart-Service -ServerName $appServerName -ServiceName "AKServ" -username $username -plaintextPassword $plaintextPassword

    Write-Host "Release completed ..."

} catch {
    Write-Host "Error occured .. $_"
    throw $_ # 抛出错误触发Pipeline失败
}

2.2 解除跨网段网络限制

  1. WinRM配置:确保AppServer1已启用WinRM,防火墙允许onPrem1的IP访问WinRM端口(5985或5986)
  2. SMB权限:确保执行脚本的账号拥有AppServer1的D$共享访问权限,防火墙允许SMB流量(端口445)
  3. 网络连通性:确认两个网段之间路由连通,或通过VPN/专线打通网络

方案3:使用Azure Automation Runbook(可选)

若跨网段网络限制无法解除,可通过Azure Automation远程执行:

  1. 在AppServer1上安装Hybrid Runbook Worker
  2. 将修正后的脚本部署为Azure Automation Runbook
  3. 在Azure Release Pipeline中添加「Azure Automation Runbook」任务,触发脚本执行

内容的提问来源于stack exchange,提问作者Kalana D

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 00:45:57