You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无交互无域加入解决Azure Pipelines VMSS代理池文件共享执行权限问题

解决Azure VMSS Windows代理使用Azure File Share作为工作区的PowerShell执行限制问题

问题原因

  1. PowerShell执行策略限制:默认RemoteSigned策略下,未签名的远程(网络共享)脚本会被阻止;即使指定Unrestricted,非交互式会话中仍会因文件的Zone.Identifier标记(Windows将来自网络的文件标记为不信任区域)而执行失败。
  2. Azure File Share的网络属性:挂载的SMB共享被Windows识别为远程位置,下载的Pipeline任务脚本会被自动标记为"来自Internet",触发PowerShell的安全检查。

静默解决方案(无GUI、无域)

1. 修改现有自定义脚本扩展,添加执行策略与文件信任逻辑

在你的自定义脚本末尾添加以下代码,实现全局执行策略配置和自动解锁共享中的文件:

# ------------------- 新增:配置PowerShell执行策略与文件信任 -------------------
# 设置机器级PowerShell执行策略为RemoteSigned(允许本地无签名脚本,远程脚本可通过解锁绕过)
Set-ExecutionPolicy RemoteSigned -Scope LocalMachine -Force -ErrorAction Stop

# 解锁Azure File Share工作目录下的所有文件,移除Zone.Identifier标记
if (Test-Path "${DriveLetter}:\a") {
    Write-Host "Unblocking files in ${DriveLetter}:\a..."
    Get-ChildItem -Path "${DriveLetter}:\a" -Recurse -File -ErrorAction SilentlyContinue | Unblock-File -ErrorAction SilentlyContinue
}

# 可选:配置代理启动时强制使用Bypass执行策略(确保所有PowerShell会话不受限制)
$agentInstallDir = "C:\agent" # 替换为你的Azure Pipelines代理安装目录
if (Test-Path "$agentInstallDir\.agent") {
    Write-Host "Updating agent PowerShell execution policy..."
    $agentConfig = Get-Content "$agentInstallDir\.agent" | ConvertFrom-Json
    $agentConfig.powershellExeArguments = "-NoLogo -Sta -NoProfile -NonInteractive -ExecutionPolicy Bypass"
    $agentConfig | ConvertTo-Json -Depth 10 | Set-Content "$agentInstallDir\.agent" -Force
    # 重启代理服务生效
    if (Get-Service -Name "Azure Pipelines Agent" -ErrorAction SilentlyContinue) {
        Restart-Service -Name "Azure Pipelines Agent" -Force
    }
}
# ---------------------------------------------------------------------------

2. 验证配置

  • 重新部署VMSS实例,或手动在现有实例上执行修改后的脚本。
  • 运行Pipeline任务,检查是否还出现AuthorizationManager check failed错误。

补充说明

  • RemoteSigned vs Bypass:RemoteSigned更安全,仅允许本地无签名脚本,远程脚本通过Unblock-File移除标记后即可执行;Bypass则完全跳过执行策略检查,适合实验环境。
  • 自动解锁文件:如果Pipeline每次都会下载新的任务文件,建议在代理的启动脚本中添加Unblock-File逻辑,确保新文件始终被信任。
  • SMB端口检查:确保VMSS子网允许445端口出站,否则Azure File Share挂载会失败(你的脚本已包含此检查)。

内容的提问来源于stack exchange,提问作者mark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 06:33:23