Jenkins Active Choice Parameter中Groovy脚本实现Azure VM列表获取及执行节点认证疑问
Question 1: Correctly Implementing the Groovy Script in Active Choice Parameter
Let’s walk through fixing your script and setting it up properly in Active Choice Parameters—here’s what you need to know:
Step 1: Refine the Groovy Script
Your original script has minor syntax quirks and error-handling that doesn’t fit how Active Choice expects to receive options. Use this revised version instead:
// Use triple quotes for multi-line commands to avoid messy escape characters def command = '''az vm list --resource-group test-test-test \ --query '[].{computerName:osProfile.computerName}' \ --output tsv''' def proc = command.execute() proc.waitFor() def output = proc.in.text.trim() def error = proc.err.text.trim() def exitCode = proc.exitValue() // Handle errors by returning a user-friendly option instead of an exit code if (error || exitCode != 0) { def errorMsg = error ?: "Process exited with code ${exitCode}" return ["Error fetching VMs: ${errorMsg}"] } // Split cleaned-up TSV output into a list of VM names return output.split("\n").findAll { it != "" }
Key fixes and improvements:
- Triple quotes eliminate the need for unnecessary backslashes when splitting the command across lines.
- Error handling returns a clear error message as a parameter option (Active Choice requires a list of options, not a numeric exit code).
- Trimmed output removes extra whitespace and empty lines to ensure a clean list of VM names.
Step 2: Configure the Active Choice Parameter
- First, make sure the Active Choice Plugin is installed in Jenkins (check under Manage Jenkins > Plugins if you need to add it).
- Create or edit your Jenkins project, go to the General section, and check "This project is parameterized".
- Click "Add Parameter" and select Active Choice Parameter.
- Set up the parameter:
- Name: Pick a clear name like
TargetVM. - Type: Choose "Single Select" or "Multi Select" based on your workflow needs.
- Script: Paste the revised Groovy script into the "Script" text box.
- Script Approval: If Jenkins blocks the script, head to Manage Jenkins > In-process Script Approval to approve the required method calls (like
execute()andwaitFor()).
- Name: Pick a clear name like
Critical Prerequisites
- The Jenkins node (master or agent) running this script must have Azure CLI installed.
- The node must be authenticated to Azure:
- For testing, run
az loginon the node once. - For automated pipelines, use a service principal (set environment variables
AZURE_CLIENT_ID,AZURE_CLIENT_SECRET,AZURE_TENANT_IDon the node) or integrate Jenkins’ Azure Credentials Plugin to inject credentials dynamically.
- For testing, run
Question 2: Running Authentication on a Jenkins Agent Node (Not Just Master)
Nope, Active Choice Parameters aren’t restricted to the Jenkins master—you can absolutely run the script on an agent node with Azure CLI installed, as long as you configure it right:
How to Route the Script to a Specific Agent
- When setting up your Active Choice Parameter, look for the Run on node option (available in newer versions of the Active Choice Plugin).
- Enter the node name or node label of your agent that has Azure CLI installed. Jenkins will execute the script directly on this node.
Configuring Authentication on the Agent
- Service Principal: Set the required Azure service principal environment variables on the agent (via Jenkins node configuration or the EnvInject Plugin). Add
az login --service-principal -u $AZURE_CLIENT_ID -p $AZURE_CLIENT_SECRET --tenant $AZURE_TENANT_IDat the start of your Groovy script to authenticate automatically. - Managed Identity: If your agent is an Azure VM, enable a system-assigned or user-assigned Managed Identity. Azure CLI will use this identity for authentication without needing
az loginat all. - Stored Credentials: Use Jenkins’ Azure Credentials Plugin to store your service principal details, then reference them in your script to authenticate dynamically.
Just ensure the agent’s identity (service principal or managed identity) has permission to list VMs in your target resource group—assign the Virtual Machine Contributor role or a custom role with Microsoft.Compute/virtualMachines/read access.
内容的提问来源于stack exchange,提问作者WhoAmI

