You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipeline上传Python包到Artifacts认证失败求助

Azure Pipeline发布Python包到Artifacts Feed的401认证问题

本地使用Twine可正常上传Python包到Azure Artifacts Feed,但在Azure Pipeline中执行时遭遇401未授权错误,报错中出现匿名用户ID aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa。

Pipeline配置代码

trigger:
- main

pool:
  vmImage: ubuntu-22.04
variables:
  pip_cache_dir: '$(Pipeline.Workspace)/.pip_cache'

steps:
- task: UsePythonVersion@0
  inputs:
    versionSpec: '3.10'
    addToPath: true

- bash: |
    python -m venv worker_venv
    source worker_venv/bin/activate
    pip install --upgrade pip
    pip install pipenv
    pipenv requirements > requirements.txt
    pipenv requirements --dev > requirements-dev.txt
    pip install --cache-dir $(pip_cache_dir) -r ./requirements.txt
    pip install --target="./.python_packages/lib/site-packages" --cache-dir $(pip_cache_dir) -r ./requirements.txt
  displayName: 'Install tools'

- script: |
    source worker_venv/bin/activate
    python setup.py sdist bdist_wheel
  displayName: 'Build package'

- task: TwineAuthenticate@1
  inputs:
    artifactFeed: sample-feed-01

- script: |
    source worker_venv/bin/activate
    python -m twine upload --verbose --config-file $(PYPIRC_PATH) --repository-url https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-01/pypi/upload/ dist/*
  env:
    TWINE_USERNAME: "azure"
    TWINE_PASSWORD: $(PYPI_TOKEN)
  displayName: 'Upload package to Azure Artifacts'

报错信息

/usr/bin/bash --noprofile --norc /home/vsts/work/_temp/75d0c60b-0c2a-44e9-be0f-29d838a3b86e.sh
Uploading distributions to 
https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-01/pypi/up
load/
INFO     dist/**package**.whl (2.6 KB)                 
INFO     dist/**package**.tar.gz (2.6 KB)                            
INFO     username set by command options                                         
INFO     password set by command options                                         
INFO     username: azure                                                         
INFO     password: <hidden>                                                      
Uploading **package**.whl
25l
  0% ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 0.0/5.7 kB • --:-- • ?
100% ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 5.7/5.7 kB • 00:00 • ?
100% ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 5.7/5.7 kB • 00:00 • ?
25hINFO     Response from                                                           
         https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-0
         1/pypi/upload/:                                                         
         401 Unauthorized                                                        
INFO     {"$id":"1","innerException":null,"message":"TF400813: The user        
         'aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa' is not authorized to access this
         resource.","typeName":"Microsoft.TeamFoundation.Framework.Server.Unauth
         orizedRequestException,                                                
         Microsoft.TeamFoundation.Framework.Server","typeKey":"UnauthorizedReque
         stException","errorCode":0,"eventId":3000}                              
ERROR    HTTPError: 401 Unauthorized from                                        
         https://pkgs.dev.azure.com/**company**/Platform/_packaging/sample-feed-0
         1/pypi/upload/                                                          
         Unauthorized                                       

问题分析与解决方案

1. 移除冲突的认证配置

TwineAuthenticate@1任务会自动生成包含有效认证信息的.pypirc文件(路径为$(PYPIRC_PATH)),但当前Pipeline中同时手动设置了TWINE_USERNAME和TWINE_PASSWORD,这会覆盖任务生成的认证配置,导致无效凭据被使用。

修改上传步骤,删除手动设置的环境变量,同时无需指定--repository-url(任务已在.pypirc中配置好):

source worker_venv/bin/activate
python -m twine upload --verbose --config-file $(PYPIRC_PATH) dist/*

2. 检查Pipeline服务账号权限

报错中的aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa是Azure DevOps的匿名用户标识,说明请求未携带有效权限的凭据。需确保Pipeline运行的服务账号拥有Feed的发布权限:

  • 进入Azure DevOps的目标Feed页面,点击「设置」→「权限」
  • 添加项目级的[项目名] Build Service ([组织名])账号
  • 将该账号的权限设置为发布者(Publisher)

3. 确认TwineAuthenticate任务的Feed路径

artifactFeed参数需使用正确的格式:

  • 项目级Feed:项目名/Feed名,例如Platform/sample-feed-01
  • 组织级Feed:组织名/Feed名,例如company/sample-feed-01

若仅填写sample-feed-01,任务可能无法正确定位到目标Feed,导致认证失败。

内容的提问来源于stack exchange,提问作者prhmma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 16:12:53