You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure流水线执行Helm/Kubectl命令反复要求浏览器身份验证

问题:Helm/Kubectl在Azure DevOps流水线中反复要求浏览器验证身份

已在部署流水线中执行az login和az aks get-credentials命令,但后续运行helm install甚至kubectl get all时,系统仍持续要求通过浏览器完成身份验证。本地VM中执行相同操作可正常完成。

流水线脚本

echo "Getting credentials to AKS cluster: akstest1"
az aks get-credentials -g rgtest1 -n akstest1 --overwrite-existing

echo "Container Registry Login to $(acrurl)"
helm registry login $(acrurl) --username $(acruser) --password $(acrtoken)

echo "Running helm uninstall"
helm delete nfs --kubeconfig /home/AzDevOps/.kube/config

流水线输出

/usr/bin/bash --noprofile --norc
/agent/_work/_temp/08e2b7e1-4985-4d94-9809-b8cf0d1a2d5d.sh
/agent/_work/_temp/08e2b7e1-4985-4d94-9809-b8cf0d1a2d5d.sh: line 1:
Getting credentials to AKS cluster: ${{ parameters.clusterName }}: bad substitution
WARNING: Merged "akstest1" as current context in /home/AzDevOps/.kube/config

Container Registry Login to crviyatrsasptvaldecc1.azurecr.io

WARNING: Using --password via the CLI is insecure. Use --password-stdin.

Login Succeeded

Running helm uninstall

To sign in, use a web browser to open the page https://microsoft.com/devicelogin and enter the code A9EVL8AVJ to authenticate.

##[error]The operation was canceled. Finishing: nfs

解决方案

  • 使用管理员权限kubeconfig:如果AKS启用了Azure AD集成,az aks get-credentials仅获取配置文件但不授权服务主体访问。添加--admin参数可跳过AD验证,直接获取管理员权限的kubeconfig:

    az aks get-credentials -g rgtest1 -n akstest1 --overwrite-existing --admin
    
  • 为服务主体分配集群角色:若需非管理员权限,给流水线服务主体分配Kubernetes Cluster Admin角色:

    # 获取AKS集群资源ID
    AKS_ID=$(az aks show -g rgtest1 -n akstest1 --query id -o tsv)
    # 分配Cluster Admin角色
    az role assignment create --assignee <服务主体ID> --role "Azure Kubernetes Service Cluster Admin Role" --scope $AKS_ID
    
  • 直接用服务主体生成kubeconfig:在az aks get-credentials中传入服务主体信息,确保配置使用服务主体认证而非交互式登录:

    az aks get-credentials -g rgtest1 -n akstest1 --overwrite-existing --service-principal <服务主体ID> --client-secret <服务主体密钥>
    
  • 验证kubeconfig路径与权限:确认/home/AzDevOps/.kube/config路径正确,且流水线代理对该路径有读写权限。也可设置环境变量KUBECONFIG=/home/AzDevOps/.kube/config,让kubectl/Helm自动读取配置,无需每次命令指定。

  • 检查服务主体基础权限:确保执行az login的服务主体拥有AKS集群所在资源组的Contributor权限,或至少拥有AKS集群的访问权限。可通过以下命令查看现有权限:

    az role assignment list --assignee <服务主体ID> --scope <AKS集群资源ID>
    

内容的提问来源于stack exchange,提问作者Nerd in Training

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 05:21:11