You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自托管代理DevOps管道因PowerShell执行策略导致构建验证失败

问题:Azure DevOps管道中PowerShell临时脚本签名失败

背景

我的DevOps管道包含以下步骤:

  • 初始化任务
  • 检出解决方案
  • 检出模板
  • 还原包
  • 版本控制
  • 构建解决方案(VSBuild@1)
  • 单元测试
  • 收集工件
  • 构建验证
  • 打包工件
  • 发布CI工件
  • 打包管道工件

最初管道在**构建解决方案(VSBuild@1)**步骤失败,报错:*.ps1未进行数字签名,无法在当前系统运行。有关运行脚本和设置执行策略的详细信息...

修改当前用户或本地机器级别的执行策略无效,仅通过以下命令修改机器策略才有效:

Set-ItemProperty -Path HKLM:\Software\Policies\Microsoft\Windows\PowerShell -Name ExecutionPolicy -Value Bypass (or RemoteSigned)

但该设置会被组策略更新覆盖,且IT部门不愿永久修改机器策略。因此我签署了C:\agent_Work父目录下的所有脚本,当前该步骤已正常运行。

当前问题:PowerShell@2任务临时脚本签名失败

现在构建验证步骤出现相同错误,移除该步骤后,打包管道工件步骤也出现类似错误。这两个步骤均使用PowerShell@2任务执行inline脚本,运行时会生成以GUID命名的临时.ps1文件,每次管道运行GUID都会变化,无法预先签名,也无法物理查看这些文件。

构建验证任务代码

- task: PowerShell@2
      displayName: 'Build Verification'
      condition: and(succeeded(), eq(variables['System.Debug'], 'true'))
      inputs:
        targetType: 'inline'
        script: |
          Get-ChildItem "$(Build.ArtifactStagingDirectory)" -Recurse

打包管道工件任务代码

- task: PowerShell@2
          displayName: 'Pack Pipeline Artifacts'
          inputs:
            targetType: 'inline'
            script: |
              New-Item -ItemType Directory -Force -Path "$(Build.ArtifactStagingDirectory)/Artifact" | out-null

报错信息

生成脚本。
##[debug]AGENT_VERSION: '3.236.1'
##[debug]AGENT_TEMPDIRECTORY: 'C:\agent\agent01_work_temp'
##[debug]Asserting container path exists: 'C:\agent\agent01_work_temp'
##[debug]Asserting leaf path exists: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
========================== 开始命令输出 ===========================
##[debug]Entering Invoke-VstsTool.
##[debug] 参数: '-NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command ". 'C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1'"'
##[debug] 文件名: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
##[debug] 工作目录: 'C:\agent\agent01_work\17\s' "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoLogo
-NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command ". 'C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1'"
##[debug]代理环境资源 - 磁盘: C:\ 可用46746.00 MB/总129481.00 MB,内存: 已用3836.00 MB/总8190.00 MB,CPU:
使用率9.07% . : 文件
C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1
无法加载。该文件
C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1
未进行数字签名,无法在当前系统运行。有关运行脚本和设置执行策略的详细信息,请参阅 about_Execution_Policies at
https:/go.microsoft.com/fwlink/?LinkID=135170.

求助需求

如何在运行时签署这些自动生成的临时PowerShell脚本?已尝试所有可行的本地策略修改方案,均被组策略限制,恳请提供解决方案。

内容的提问来源于stack exchange,提问作者user2921973

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 10:42:13