You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipelines任务间如何共享连接?认证问题求助

跨Pipeline任务复用Microsoft Graph认证失败的解决方法

问题场景

我当前的Azure DevOps Pipeline结构如下:

steps:
  - task: AzurePowerShell@5
    inputs:
      azureSubscription: 'ALZPipeline'
      ScriptType: 'FilePath'
      ScriptPath: 'scripts/login.ps1'
      azurePowerShellVersion: 'LatestVersion'
  - task: AzureCLI@2
    inputs:
     azureSubscription: 'ALZPipeline'
     scriptType: 'pscore'
     scriptLocation: 'scriptPath'
     scriptPath: '/deployment.ps1'
     arguments: '-action whatif'

我试图在第一个任务的login.ps1中完成Microsoft Graph认证:

$azToken = [Microsoft.Azure.Commands.Common.Authentication.AzureSession]::Instance.AuthenticationFactory.Authenticate($context.Account, $context.Environment, $context.Tenant.Id.ToString(), $null, [Microsoft.Azure.Commands.Common.Authentication.ShowDialog]::Never, $null, "https://graph.microsoft.com").AccessToken
Write-Output $azToken
$SecuredPasswordPassword = ConvertTo-SecureString -String $azToken -AsPlainText -Force
Connect-MgGraph -AccessToken $SecuredPasswordPassword

然后在第二个任务的deployment.ps1中复用该认证执行Graph操作:

$parAssigneeObjectId = $(Get-MgGroup -Filter "DisplayName eq '$($GroupName)'").Id

但执行时抛出错误:

Get-MgGroup : Authentication needed. Please call Connect-MgGraph.

问题原因

  • Azure DevOps的每个Pipeline任务都是独立运行的进程,任务之间的上下文(包括PowerShell会话状态、认证信息)完全隔离,第一个任务中通过Connect-MgGraph建立的认证不会自动传递到第二个任务。
  • 两个任务类型不同(AzurePowerShell@5和AzureCLI@2),执行环境和运行上下文完全不共享,进一步阻断了认证信息的传递。

解决方法

方案1:在第二个任务中直接获取Graph Token并认证

利用AzureCLI@2任务已通过azureSubscription完成Azure资源认证的特性,直接在deployment.ps1中获取Graph访问令牌并完成认证:

# 在deployment.ps1开头添加认证逻辑
$graphToken = az account get-access-token --resource-type ms-graph --query accessToken -o tsv
$securedToken = ConvertTo-SecureString $graphToken -AsPlainText -Force
Connect-MgGraph -AccessToken $securedToken

# 原业务逻辑代码
$parAssigneeObjectId = $(Get-MgGroup -Filter "DisplayName eq '$($GroupName)'").Id

方案2:合并两个任务为一个AzurePowerShell任务

如果业务逻辑允许,将两个脚本的逻辑合并到一个AzurePowerShell@5任务中,共享同一会话上下文,认证可直接复用:

steps:
  - task: AzurePowerShell@5
    inputs:
      azureSubscription: 'ALZPipeline'
      ScriptType: 'FilePath'
      ScriptPath: 'scripts/combined-script.ps1'
      azurePowerShellVersion: 'LatestVersion'
      arguments: '-action whatif'

在combined-script.ps1中先执行原login.ps1的认证逻辑,再执行deployment.ps1的业务逻辑即可。

方案3:通过Pipeline安全变量传递Token(需谨慎)

如果必须拆分任务,可以将第一个任务生成的Graph Token通过Pipeline安全变量传递到第二个任务:

  1. 在第一个任务的login.ps1末尾添加变量输出逻辑:
# 将Token设置为安全Pipeline变量,避免日志泄露
Write-Host "##vso[task.setvariable variable=GraphToken;issecret=true]$azToken"
  1. 在第二个任务的deployment.ps1中读取变量并完成认证:
$graphToken = $env:GraphToken
$securedToken = ConvertTo-SecureString $graphToken -AsPlainText -Force
Connect-MgGraph -AccessToken $securedToken

# 原业务逻辑代码
$parAssigneeObjectId = $(Get-MgGroup -Filter "DisplayName eq '$($GroupName)'").Id

注意:此方式需严格控制Token的安全,避免在日志或输出中泄露。

内容的提问来源于stack exchange,提问作者Bob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 18:23:15