自托管代理DevOps管道因PowerShell执行策略导致构建验证失败
背景
我的DevOps管道包含以下步骤:
- 初始化任务
- 检出解决方案
- 检出模板
- 还原包
- 版本控制
- 构建解决方案(VSBuild@1)
- 单元测试
- 收集工件
- 构建验证
- 打包工件
- 发布CI工件
- 打包管道工件
最初管道在**构建解决方案(VSBuild@1)**步骤失败,报错:*.ps1未进行数字签名,无法在当前系统运行。有关运行脚本和设置执行策略的详细信息...
修改当前用户或本地机器级别的执行策略无效,仅通过以下命令修改机器策略才有效:
Set-ItemProperty -Path HKLM:\Software\Policies\Microsoft\Windows\PowerShell -Name ExecutionPolicy -Value Bypass (or RemoteSigned)
但该设置会被组策略更新覆盖,且IT部门不愿永久修改机器策略。因此我签署了C:\agent_Work父目录下的所有脚本,当前该步骤已正常运行。
当前问题:PowerShell@2任务临时脚本签名失败
现在构建验证步骤出现相同错误,移除该步骤后,打包管道工件步骤也出现类似错误。这两个步骤均使用PowerShell@2任务执行inline脚本,运行时会生成以GUID命名的临时.ps1文件,每次管道运行GUID都会变化,无法预先签名,也无法物理查看这些文件。
构建验证任务代码
- task: PowerShell@2 displayName: 'Build Verification' condition: and(succeeded(), eq(variables['System.Debug'], 'true')) inputs: targetType: 'inline' script: | Get-ChildItem "$(Build.ArtifactStagingDirectory)" -Recurse
打包管道工件任务代码
- task: PowerShell@2 displayName: 'Pack Pipeline Artifacts' inputs: targetType: 'inline' script: | New-Item -ItemType Directory -Force -Path "$(Build.ArtifactStagingDirectory)/Artifact" | out-null
报错信息
生成脚本。
##[debug]AGENT_VERSION: '3.236.1'
##[debug]AGENT_TEMPDIRECTORY: 'C:\agent\agent01_work_temp'
##[debug]Asserting container path exists: 'C:\agent\agent01_work_temp'
##[debug]Asserting leaf path exists: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
========================== 开始命令输出 ===========================
##[debug]Entering Invoke-VstsTool.
##[debug] 参数: '-NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command ". 'C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1'"'
##[debug] 文件名: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
##[debug] 工作目录: 'C:\agent\agent01_work\17\s' "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoLogo
-NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command ". 'C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1'"
##[debug]代理环境资源 - 磁盘: C:\ 可用46746.00 MB/总129481.00 MB,内存: 已用3836.00 MB/总8190.00 MB,CPU:
使用率9.07% . : 文件
C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1
无法加载。该文件
C:\agent\agent01_work_temp\879635e3-95db-4615-a7ae-107db204cdef.ps1
未进行数字签名,无法在当前系统运行。有关运行脚本和设置执行策略的详细信息,请参阅 about_Execution_Policies at
https:/go.microsoft.com/fwlink/?LinkID=135170.
求助需求
如何在运行时签署这些自动生成的临时PowerShell脚本?已尝试所有可行的本地策略修改方案,均被组策略限制,恳请提供解决方案。
内容的提问来源于stack exchange,提问作者user2921973

