Azure Release Pipeline跨网络远程执行PowerShell脚本失败解决方案
解决Azure Release Pipeline跨网段远程执行PowerShell脚本失败问题
已知背景
- 已完成操作:
- 通过Bash脚本将.dll和PowerShell脚本从GitHub下载至本地代理服务器
onPrem1(172.24.243.193)的D:\agent_work\r65\a\DeploymentPackage\ReleaseFiles路径,执行成功 - 通过Windows Machine File Copy (WinRM)将.dll复制至远程服务器
AppServer1(172.26.143.22)的D:\release\,执行成功
- 通过Bash脚本将.dll和PowerShell脚本从GitHub下载至本地代理服务器
- 问题:使用PowerShell v2.*执行下载的脚本失败,原因是跨网段从onPrem代理访问远程服务器受限
- 脚本预期功能:检查远程服务器
D:\app\下的现有.dll文件,存在则备份;将新.dll从D:\release\复制到D:\app\;重启AKServ服务
核心解决方案
方案1:使用Azure Pipeline「PowerShell on Target Machines」任务(推荐)
该任务通过WinRM直接在目标服务器上执行脚本,规避跨网段共享访问限制,步骤如下:
- 新增Windows Machine File Copy任务,将PowerShell脚本和.dll文件一起复制到AppServer1的本地路径(如
D:\temp\) - 添加「PowerShell on Target Machines」任务,配置:
- 目标服务器:填写AppServer1的IP、WinRM端口(默认5985/http或5986/https)
- 凭据:使用拥有AppServer1管理员权限的账号
- 脚本路径:指定AppServer1本地的脚本路径(如
D:\temp\deploy-script.ps1) - 参数:传递脚本所需的变量(如文件名、服务名)
方案2:修正脚本并解除跨网段网络限制
若需保留从代理执行脚本的方式,需同时修复脚本错误和网络限制:
2.1 修正原脚本的语法与逻辑错误
原脚本存在重复函数定义、未定义变量、逻辑错误等问题,修正后的版本如下:
param( [String] $appServerName, [String] $fileName, [String] $username, [String] $plaintextPassword ) function Backup-file { param( [String] $serverName, [String] $fileName ) $releaseFolderPath = "\\$serverName\d$\app\" $backupFileDirectory = "$releaseFolderPath\Backups\" Write-Host "Backing up $releaseFolderPath to $backupFileDirectory" $releaseFileFullPath = Join-Path -Path $releaseFolderPath -ChildPath $fileName if (Test-Path -Path $releaseFileFullPath) { Write-Host "File Exists $releaseFileFullPath " try { # 创建备份目录(不存在则创建) if (-not (Test-Path -Path $backupFileDirectory)) { New-Item -ItemType Directory -Path $backupFileDirectory Write-Host "Backup folder created on $backupFileDirectory" } # 重命名原文件并移动至备份目录 $backupFileName = "ABC_" + (Get-Date -Format "yyyyMMddHHmmss") + ".dll" Rename-Item -Path $releaseFileFullPath -NewName $backupFileName Move-Item -Path (Join-Path $releaseFolderPath $backupFileName) -Destination $backupFileDirectory Write-Host "File backup and rename successful in Server !!!" } catch { Write-Host "Error: $_" } } else { Write-Host "Error: File not found $releaseFileFullPath!!!" } } function Copy-Source-Files { param( [String] $serverName, [String] $fileName ) try { Write-Host "Copy-Source-Files started .." $sourceFilePath = "\\$serverName\d$\release\$fileName" $destFilePath = "\\$serverName\d$\app\$fileName" Write-Host "Copying from $sourceFilePath to $destFilePath" Copy-Item -Path $sourceFilePath -Destination $destFilePath -Force } catch { Write-Host "Error occured in Copy-Source-Files $_" } } function Restart-Service { param( [String] $ServerName, [String] $ServiceName, [String] $username, [String] $plaintextPassword ) Write-Host "Restarting $ServiceName of $ServerName" $securePassword = ConvertTo-SecureString $plaintextPassword -AsPlainText -Force $credential = New-Object System.Management.Automation.PSCredential($username, $securePassword) $scriptBlock = { param($Service) Restart-Service -Name $Service -Force -ErrorAction Stop } Invoke-Command -ComputerName $ServerName -ScriptBlock $scriptBlock -ArgumentList $ServiceName -Credential $credential -ErrorAction Stop } try { Write-Host "Processing Started...." Backup-file -serverName $appServerName -fileName $fileName Copy-Source-Files -serverName $appServerName -fileName $fileName Restart-Service -ServerName $appServerName -ServiceName "AKServ" -username $username -plaintextPassword $plaintextPassword Write-Host "Release completed ..." } catch { Write-Host "Error occured .. $_" throw $_ # 抛出错误触发Pipeline失败 }
2.2 解除跨网段网络限制
- WinRM配置:确保AppServer1已启用WinRM,防火墙允许onPrem1的IP访问WinRM端口(5985或5986)
- SMB权限:确保执行脚本的账号拥有AppServer1的
D$共享访问权限,防火墙允许SMB流量(端口445) - 网络连通性:确认两个网段之间路由连通,或通过VPN/专线打通网络
方案3:使用Azure Automation Runbook(可选)
若跨网段网络限制无法解除,可通过Azure Automation远程执行:
- 在AppServer1上安装Hybrid Runbook Worker
- 将修正后的脚本部署为Azure Automation Runbook
- 在Azure Release Pipeline中添加「Azure Automation Runbook」任务,触发脚本执行
内容的提问来源于stack exchange,提问作者Kalana D
相关产品推荐
相关产品推荐

