Azure流水线执行Helm/Kubectl命令反复要求浏览器身份验证
已在部署流水线中执行az login和az aks get-credentials命令,但后续运行helm install甚至kubectl get all时,系统仍持续要求通过浏览器完成身份验证。本地VM中执行相同操作可正常完成。
流水线脚本
echo "Getting credentials to AKS cluster: akstest1" az aks get-credentials -g rgtest1 -n akstest1 --overwrite-existing echo "Container Registry Login to $(acrurl)" helm registry login $(acrurl) --username $(acruser) --password $(acrtoken) echo "Running helm uninstall" helm delete nfs --kubeconfig /home/AzDevOps/.kube/config
流水线输出
/usr/bin/bash --noprofile --norc
/agent/_work/_temp/08e2b7e1-4985-4d94-9809-b8cf0d1a2d5d.sh
/agent/_work/_temp/08e2b7e1-4985-4d94-9809-b8cf0d1a2d5d.sh: line 1:
Getting credentials to AKS cluster: ${{ parameters.clusterName }}: bad substitution
WARNING: Merged "akstest1" as current context in /home/AzDevOps/.kube/configContainer Registry Login to crviyatrsasptvaldecc1.azurecr.io
WARNING: Using --password via the CLI is insecure. Use --password-stdin.
Login Succeeded
Running helm uninstall
To sign in, use a web browser to open the page https://microsoft.com/devicelogin and enter the code A9EVL8AVJ to authenticate.
##[error]The operation was canceled. Finishing: nfs
解决方案
使用管理员权限kubeconfig:如果AKS启用了Azure AD集成,
az aks get-credentials仅获取配置文件但不授权服务主体访问。添加--admin参数可跳过AD验证,直接获取管理员权限的kubeconfig:az aks get-credentials -g rgtest1 -n akstest1 --overwrite-existing --admin为服务主体分配集群角色:若需非管理员权限,给流水线服务主体分配Kubernetes Cluster Admin角色:
# 获取AKS集群资源ID AKS_ID=$(az aks show -g rgtest1 -n akstest1 --query id -o tsv) # 分配Cluster Admin角色 az role assignment create --assignee <服务主体ID> --role "Azure Kubernetes Service Cluster Admin Role" --scope $AKS_ID直接用服务主体生成kubeconfig:在
az aks get-credentials中传入服务主体信息,确保配置使用服务主体认证而非交互式登录:az aks get-credentials -g rgtest1 -n akstest1 --overwrite-existing --service-principal <服务主体ID> --client-secret <服务主体密钥>验证kubeconfig路径与权限:确认
/home/AzDevOps/.kube/config路径正确,且流水线代理对该路径有读写权限。也可设置环境变量KUBECONFIG=/home/AzDevOps/.kube/config,让kubectl/Helm自动读取配置,无需每次命令指定。检查服务主体基础权限:确保执行
az login的服务主体拥有AKS集群所在资源组的Contributor权限,或至少拥有AKS集群的访问权限。可通过以下命令查看现有权限:az role assignment list --assignee <服务主体ID> --scope <AKS集群资源ID>
内容的提问来源于stack exchange,提问作者Nerd in Training

