You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps Ubuntu自托管Agent无法下载Node.js版本求助

Azure VMSS自托管Ubuntu Agent TLS连接失败修复方案

问题描述

  • 使用Azure VMSS自动配置的自托管Agent执行流水线时失败,仅Ubuntu环境出现问题,Windows Agent运行正常
  • 报错信息:

##[error]Client network socket disconnected before secure TLS connection was established

  • 涉及的Pipeline代码:
stages:  
  - stage: "BuildStage"
    displayName: "Build Stage"
    jobs:
      - job: "BuildJob"
        displayName: "BuildJob"
        steps:
          - task: NodeTool@0
            inputs:
              #versionSource: 'spec'
              versionSpec: '18.x'
            displayName: "setting node version"
      
          - script: |
              npm install
            displayName: "Prepare binaries"
  
          - script: |
              npm run build
            displayName: "Building the project"
  
          - task: ArchiveFiles@2
            displayName: "Archiving the files"
            inputs:
              rootFolderOrFile: '$(System.DefaultWorkingDirectory)'
              includeRootFolder: false
              archiveType: 'zip'
              archiveFile: '$(Build.ArtifactStagingDirectory)/$(Build.BuildId).zip'
              replaceExistingArchive: true
            
          - task: PublishBuildArtifacts@1
            displayName: publishing pipeline artifacts
            inputs:
              PathtoPublish: '$(Build.ArtifactStagingDirectory)/$(Build.BuildId).zip'
              ArtifactName: 'drop'
              publishLocation: 'Container'

修复方案

1. 强制Node.js使用兼容的TLS加密方式

Ubuntu环境下Node.js 18+的默认TLS配置可能与部分npm包源不兼容,在npm install和npm run build步骤前添加环境变量:

export NODE_OPTIONS=--openssl-legacy-provider

修改后的对应Pipeline步骤:

- script: |
    export NODE_OPTIONS=--openssl-legacy-provider
    npm install
  displayName: "Prepare binaries"

- script: |
    export NODE_OPTIONS=--openssl-legacy-provider
    npm run build
  displayName: "Building the project"

2. 更新Ubuntu系统根证书

系统根证书过期或缺失会导致TLS握手失败,在Node版本配置步骤后添加证书更新脚本:

- script: |
    sudo apt-get update
    sudo apt-get install --reinstall ca-certificates -y
  displayName: "Update system root certificates"

3. 配置代理(若环境需代理)

如果VMSS实例处于代理网络环境,为npm和Node.js配置代理:

- script: |
    export HTTP_PROXY=http://your-proxy-address:port
    export HTTPS_PROXY=http://your-proxy-address:port
    export NO_PROXY=localhost,127.0.0.1,azure-devops.microsoft.com
    npm install
  displayName: "Prepare binaries with proxy"

注意替换your-proxy-address:port为实际代理地址。

4. 检查VMSS网络安全组规则

确保NSG允许Ubuntu实例访问以下域名的443端口流量:

  • registry.npmjs.org
  • azure-devops.microsoft.com
  • 项目依赖的其他外部资源域名

内容的提问来源于stack exchange,提问作者Sharat Bhaskar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 17:04:57