Azure DevOps部署至AKS突发network_error故障求助
问题
我们有多条部署至2个AKS集群的流水线,正常运行约6个月后,上周四起所有部署突然失败。流水线配置为部署更新代码前删除上一次部署,AKS集群为私有集群,部署操作由自托管代理机器执行,相关步骤如下:
strategy: runOnce: deploy: steps: - task: KubernetesManifest@1 displayName: Delete previous deployment inputs: connectionType: "azureResourceManager" azureSubscriptionConnection: "$(aksServiceConnection)" azureResourceGroup: $(askResourceGroupName) kubernetesCluster: $(aksName) namespace: $(namespaceDv) action: delete arguments: deployment mynamespace-deploy --ignore-not-found=true
流水线执行时出现如下错误:
##[debug]MSAL - ServicePrincipal - clientSecret is used. ##[debug][Thu, 27 Jun 2024 15:03:52 GMT] : [] : @azure/msal-node@2.9.2 : Info - acquireTokenByClientCredential called ##[debug][Thu, 27 Jun 2024 15:03:52 GMT] : [9a5f7d9c-befc-48a8-aede-4f35e9f59201] : @azure/msal-node@2.9.2 : Info - Building oauth client configuration with the following authority: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token. ##[debug][Thu, 27 Jun 2024 15:03:52 GMT] : [9a5f7d9c-befc-48a8-aede-4f35e9f59201] : @azure/msal-common@14.12.0 : Info - Sending token request to endpoint: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token ##[debug]MSAL - retrying getMSALToken - temporary error code: network_error ##[debug]MSAL - retrying getMSALToken - remaining attempts: 3 ##[debug]Agent environment resources - Disk: / Available 53442.00 MB out of 68979.00 MB, Memory: Used 521.00 MB out of 11957.00 MB, CPU: Usage 6.34% ##[debug]MSAL - getMSALToken called. force=undefined ##[debug][Thu, 27 Jun 2024 15:03:54 GMT] : [] : @azure/msal-node@2.9.2 : Info - acquireTokenByClientCredential called ##[debug][Thu, 27 Jun 2024 15:03:54 GMT] : [a2b748f6-2067-4bd1-841c-d1c386f57725] : @azure/msal-node@2.9.2 : Info - Building oauth client configuration with the following authority: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token. ##[debug][Thu, 27 Jun 2024 15:03:54 GMT] : [a2b748f6-2067-4bd1-841c-d1c386f57725] : @azure/msal-common@14.12.0 : Info - Sending token request to endpoint: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token ##[debug]MSAL - retrying getMSALToken - temporary error code: network_error ##[debug]MSAL - retrying getMSALToken - remaining attempts: 2 ##[debug]MSAL - getMSALToken called. force=undefined ##[debug][Thu, 27 Jun 2024 15:03:56 GMT] : [] : @azure/msal-node@2.9.2 : Info - acquireTokenByClientCredential called ##[debug][Thu, 27 Jun 2024 15:03:56 GMT] : [22e38295-49ce-40c4-b4a5-6d59afb0e24a] : @azure/msal-node@2.9.2 : Info - Building oauth client configuration with the following authority: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token. ##[debug][Thu, 27 Jun 2024 15:03:56 GMT] : [22e38295-49ce-40c4-b4a5-6d59afb0e24a] : @azure/msal-common@14.12.0 : Info - Sending token request to endpoint: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token ##[debug]MSAL - retrying getMSALToken - temporary error code: network_error ##[debug]MSAL - retrying getMSALToken - remaining attempts: 1 ##[debug]Agent environment resources - Disk: / Available 53442.00 MB out of 68979.00 MB, Memory: Used 521.00 MB out of 11957.00 MB, CPU: Usage 6.16% ##[debug]MSAL - getMSALToken called. force=undefined ##[debug][Thu, 27 Jun 2024 15:03:58 GMT] : [] : @azure/msal-node@2.9.2 : Info - acquireTokenByClientCredential called ##[debug][Thu, 27 Jun 2024 15:03:58 GMT] : [cf0db17c-ccb6-41f1-a3a5-a67c2698a467] : @azure/msal-node@2.9.2 : Info - Building oauth client configuration with the following authority: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token. ##[debug][Thu, 27 Jun 2024 15:03:58 GMT] : [cf0db17c-ccb6-41f1-a3a5-a67c2698a467] : @azure/msal-common@14.12.0 : Info - Sending token request to endpoint: https://login.microsoftonline.com/xxxxxxxxxxxxxxx/oauth2/v2.0/token ##[warning]Can't find loc string for key: CantDownloadAccessProfile ##[debug]Processed: ##vso[task.issue type=warning;source=TaskInternal;]Can't find loc string for key: CantDownloadAccessProfile ##[debug]task result: Failed ##[error]CantDownloadAccessProfile mycluster-aks Could not fetch access token for Azure. Status code: network_error, status message: Network request failed
已完成的排查步骤:
- 确认客户端密钥未过期
- 在代理机器上通过curl调用login.microsoftonline.com,使用客户端密钥可正常获取令牌
- 在代理机器上通过kubelogin使用客户端密钥可正常获取令牌
- 将kubectl和kubelogin更新至最新版本
故障仍未解决,需要排查思路或解决方案。
排查思路与解决方案
1. 更新自托管代理的MSAL依赖版本
错误日志显示使用的是@azure/msal-node@2.9.2,该版本较旧可能存在网络适配问题:
- 找到代理安装目录下的
_work/_tasks/KubernetesManifest_xxxxxx文件夹,检查其中node_modules内的MSAL版本 - 手动替换为最新版的
@azure/msal-node和@azure/msal-common,或直接重新部署自托管代理
2. 统一代理的网络配置
curl和kubelogin能正常请求,但Azure DevOps任务可能未继承系统代理设置:
- 检查自托管代理的系统级代理配置,确认任务进程是否继承该配置
- 在流水线KubernetesManifest任务前添加脚本步骤,显式设置代理环境变量:
export HTTP_PROXY=http://your-proxy:port export HTTPS_PROXY=http://your-proxy:port export NO_PROXY=localhost,127.0.0.1,login.microsoftonline.com
3. 切换任务认证方式
避开MSAL网络问题,改用kubeconfig直接认证:
- 在自托管代理上预先用kubelogin获取并保存AKS的kubeconfig文件
- 修改流水线任务,将
connectionType改为kubernetesServiceConnection,配置对应kubeconfig服务连接,或直接指定本地kubeconfig路径
4. 检查AKS集群访问控制
确认自托管代理IP仍在AKS私有集群允许列表中:
- 查看AKS集群的API服务器授权IP范围,确保代理机器的公网/内网IP未被移除
- 若使用虚拟网络集成,检查代理所在网络与AKS集群的网络连通性是否有变化
5. 重置Azure服务连接
服务连接缓存可能存在异常:
- 在Azure DevOps中删除并重新创建
aksServiceConnection服务连接 - 确保重新创建时使用的客户端ID、密钥、租户ID与之前一致,且权限未变更
内容的提问来源于stack exchange,提问作者JakeUT
相关产品推荐
相关产品推荐

