You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure DevOps管道部署Azure Bicep时延长客户端断言有效期?

解决Azure DevOps管道中联合令牌10分钟超时问题

你有一个在Azure DevOps管道中运行的大型脚本,用于部署多个Bicep基础设施,运行10分钟后触发新Bicep部署时出现令牌超时错误:

Client assertion is not within its valid time range. Current time: 2024-05-09T12:53:26.4180283Z, assertion valid from 2024-05-09T12:37:55.0000000Z, expiry time of assertion 2024-05-09T12:47:54.0000000Z

当前使用的管道配置如下:

trigger:
  - develop

pool:
  vmImage: "windows-latest" 

variables:
  BuildNumber: $(Build.BuildNumber)

steps:
  - task: AzureCLI@2
    displayName: "Deploy App Environment"
    inputs:
      azureSubscription: "Dev-AzureSubscription"
      scriptType: "ps"
      scriptLocation: scriptPath
      scriptPath: $(Build.SourcesDirectory)/mainBuildScirpt.ps1
      workingDirectory: $(Build.SourcesDirectory)

其中Dev-AzureSubscription通过Azure应用联合令牌连接Azure,以下是可行的解决方案:

解决方案

1. 拆分长脚本为多个AzureCLI任务

将原有的单一大脚本拆分为多个独立的AzureCLI@2任务,每个任务负责一部分Bicep部署。每个任务执行时会自动重新获取新的联合令牌,避免单个任务内令牌过期:

trigger:
  - develop

pool:
  vmImage: "windows-latest" 

variables:
  BuildNumber: $(Build.BuildNumber)

steps:
  - task: AzureCLI@2
    displayName: "Deploy Core Infrastructure"
    inputs:
      azureSubscription: "Dev-AzureSubscription"
      scriptType: "ps"
      scriptLocation: scriptPath
      scriptPath: $(Build.SourcesDirectory)/deployCore.ps1
      workingDirectory: $(Build.SourcesDirectory)

  - task: AzureCLI@2
    displayName: "Deploy App Services"
    inputs:
      azureSubscription: "Dev-AzureSubscription"
      scriptType: "ps"
      scriptLocation: scriptPath
      scriptPath: $(Build.SourcesDirectory)/deployAppServices.ps1
      workingDirectory: $(Build.SourcesDirectory)

  # 按需添加更多拆分后的部署任务

2. 在脚本内主动刷新令牌

如果无法拆分脚本,可在PowerShell脚本中每隔一段时间主动重新登录Azure以刷新令牌,利用Azure DevOps自动注入的服务连接凭据即可:

# 在脚本中定期执行登录操作刷新令牌
az login --service-principal -u $env:servicePrincipalId -p $env:servicePrincipalKey --tenant $env:tenantId

3. 调整Azure应用的令牌过期时间(需Azure AD权限)

若拥有Azure AD管理员权限,可修改用于联合身份验证的Azure应用程序的令牌过期时间:

  • 登录Azure门户,找到对应的Azure应用注册
  • 进入令牌配置选项卡
  • 修改访问令牌和ID令牌的过期时间(最长可设置为1小时)
  • 保存配置后,新生成的令牌会使用更新后的过期时间

4. 改用Azure PowerShell任务(可选)

使用AzurePowerShell@5任务,它会自动管理令牌的生命周期,适合长时间运行的部署脚本:

steps:
  - task: AzurePowerShell@5
    displayName: "Deploy App Environment"
    inputs:
      azureSubscription: "Dev-AzureSubscription"
      ScriptType: "FilePath"
      ScriptPath: $(Build.SourcesDirectory)/mainBuildScirpt.ps1
      azurePowerShellVersion: "LatestVersion"

内容的提问来源于stack exchange,提问作者Eliott Roynette

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 15:43:33