Azure Pipeline上传Python包到Artifacts认证失败求助
Azure Pipeline发布Python包到Artifacts Feed的401认证问题
本地使用Twine可正常上传Python包到Azure Artifacts Feed,但在Azure Pipeline中执行时遭遇401未授权错误,报错中出现匿名用户ID aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa。
Pipeline配置代码
trigger: - main pool: vmImage: ubuntu-22.04 variables: pip_cache_dir: '$(Pipeline.Workspace)/.pip_cache' steps: - task: UsePythonVersion@0 inputs: versionSpec: '3.10' addToPath: true - bash: | python -m venv worker_venv source worker_venv/bin/activate pip install --upgrade pip pip install pipenv pipenv requirements > requirements.txt pipenv requirements --dev > requirements-dev.txt pip install --cache-dir $(pip_cache_dir) -r ./requirements.txt pip install --target="./.python_packages/lib/site-packages" --cache-dir $(pip_cache_dir) -r ./requirements.txt displayName: 'Install tools' - script: | source worker_venv/bin/activate python setup.py sdist bdist_wheel displayName: 'Build package' - task: TwineAuthenticate@1 inputs: artifactFeed: sample-feed-01 - script: | source worker_venv/bin/activate python -m twine upload --verbose --config-file $(PYPIRC_PATH) --repository-url https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-01/pypi/upload/ dist/* env: TWINE_USERNAME: "azure" TWINE_PASSWORD: $(PYPI_TOKEN) displayName: 'Upload package to Azure Artifacts'
报错信息
/usr/bin/bash --noprofile --norc /home/vsts/work/_temp/75d0c60b-0c2a-44e9-be0f-29d838a3b86e.sh Uploading distributions to https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-01/pypi/up load/ INFO dist/**package**.whl (2.6 KB) INFO dist/**package**.tar.gz (2.6 KB) INFO username set by command options INFO password set by command options INFO username: azure INFO password: <hidden> Uploading **package**.whl 25l 0% ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 0.0/5.7 kB • --:-- • ? 100% ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 5.7/5.7 kB • 00:00 • ? 100% ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 5.7/5.7 kB • 00:00 • ? 25hINFO Response from https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-0 1/pypi/upload/: 401 Unauthorized INFO {"$id":"1","innerException":null,"message":"TF400813: The user 'aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa' is not authorized to access this resource.","typeName":"Microsoft.TeamFoundation.Framework.Server.Unauth orizedRequestException, Microsoft.TeamFoundation.Framework.Server","typeKey":"UnauthorizedReque stException","errorCode":0,"eventId":3000} ERROR HTTPError: 401 Unauthorized from https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-0 1/pypi/upload/ Unauthorized
问题分析与解决方案
1. 移除冲突的认证配置
TwineAuthenticate@1任务会自动生成包含有效认证信息的.pypirc文件(路径为$(PYPIRC_PATH)),但当前Pipeline中同时手动设置了TWINE_USERNAME和TWINE_PASSWORD,这会覆盖任务生成的认证配置,导致无效凭据被使用。
修改上传步骤,删除手动设置的环境变量,同时无需指定--repository-url(任务已在.pypirc中配置好):
source worker_venv/bin/activate python -m twine upload --verbose --config-file $(PYPIRC_PATH) dist/*
2. 检查Pipeline服务账号权限
报错中的aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa是Azure DevOps的匿名用户标识,说明请求未携带有效权限的凭据。需确保Pipeline运行的服务账号拥有Feed的发布权限:
- 进入Azure DevOps的目标Feed页面,点击「设置」→「权限」
- 添加项目级的
[项目名] Build Service ([组织名])账号 - 将该账号的权限设置为发布者(Publisher)
3. 确认TwineAuthenticate任务的Feed路径
artifactFeed参数需使用正确的格式:
- 项目级Feed:
项目名/Feed名,例如Platform/sample-feed-01 - 组织级Feed:
组织名/Feed名,例如company/sample-feed-01
若仅填写sample-feed-01,任务可能无法正确定位到目标Feed,导致认证失败。
内容的提问来源于stack exchange,提问作者prhmma
相关产品推荐
相关产品推荐

