如何在Azure DevOps管道部署Azure Bicep时延长客户端断言有效期?
解决Azure DevOps管道中联合令牌10分钟超时问题
你有一个在Azure DevOps管道中运行的大型脚本,用于部署多个Bicep基础设施,运行10分钟后触发新Bicep部署时出现令牌超时错误:
Client assertion is not within its valid time range. Current time: 2024-05-09T12:53:26.4180283Z, assertion valid from 2024-05-09T12:37:55.0000000Z, expiry time of assertion 2024-05-09T12:47:54.0000000Z
当前使用的管道配置如下:
trigger: - develop pool: vmImage: "windows-latest" variables: BuildNumber: $(Build.BuildNumber) steps: - task: AzureCLI@2 displayName: "Deploy App Environment" inputs: azureSubscription: "Dev-AzureSubscription" scriptType: "ps" scriptLocation: scriptPath scriptPath: $(Build.SourcesDirectory)/mainBuildScirpt.ps1 workingDirectory: $(Build.SourcesDirectory)
其中Dev-AzureSubscription通过Azure应用联合令牌连接Azure,以下是可行的解决方案:
解决方案
1. 拆分长脚本为多个AzureCLI任务
将原有的单一大脚本拆分为多个独立的AzureCLI@2任务,每个任务负责一部分Bicep部署。每个任务执行时会自动重新获取新的联合令牌,避免单个任务内令牌过期:
trigger: - develop pool: vmImage: "windows-latest" variables: BuildNumber: $(Build.BuildNumber) steps: - task: AzureCLI@2 displayName: "Deploy Core Infrastructure" inputs: azureSubscription: "Dev-AzureSubscription" scriptType: "ps" scriptLocation: scriptPath scriptPath: $(Build.SourcesDirectory)/deployCore.ps1 workingDirectory: $(Build.SourcesDirectory) - task: AzureCLI@2 displayName: "Deploy App Services" inputs: azureSubscription: "Dev-AzureSubscription" scriptType: "ps" scriptLocation: scriptPath scriptPath: $(Build.SourcesDirectory)/deployAppServices.ps1 workingDirectory: $(Build.SourcesDirectory) # 按需添加更多拆分后的部署任务
2. 在脚本内主动刷新令牌
如果无法拆分脚本,可在PowerShell脚本中每隔一段时间主动重新登录Azure以刷新令牌,利用Azure DevOps自动注入的服务连接凭据即可:
# 在脚本中定期执行登录操作刷新令牌 az login --service-principal -u $env:servicePrincipalId -p $env:servicePrincipalKey --tenant $env:tenantId
3. 调整Azure应用的令牌过期时间(需Azure AD权限)
若拥有Azure AD管理员权限,可修改用于联合身份验证的Azure应用程序的令牌过期时间:
- 登录Azure门户,找到对应的Azure应用注册
- 进入令牌配置选项卡
- 修改访问令牌和ID令牌的过期时间(最长可设置为1小时)
- 保存配置后,新生成的令牌会使用更新后的过期时间
4. 改用Azure PowerShell任务(可选)
使用AzurePowerShell@5任务,它会自动管理令牌的生命周期,适合长时间运行的部署脚本:
steps: - task: AzurePowerShell@5 displayName: "Deploy App Environment" inputs: azureSubscription: "Dev-AzureSubscription" ScriptType: "FilePath" ScriptPath: $(Build.SourcesDirectory)/mainBuildScirpt.ps1 azurePowerShellVersion: "LatestVersion"
内容的提问来源于stack exchange,提问作者Eliott Roynette
相关产品推荐
相关产品推荐

