You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps流水线拉取镜像失败:Invalid clientid or client secret

Azure DevOps流水线构建报错:Invalid clientid or client secret 排查求助

所有Azure DevOps流水线突发无法构建,无明显诱因。报错显示“Invalid clientid or client secret”,但无法定位错误指向对象。

错误日志

2023-07-18T13:20:47.8763131Z ##[debug]found: '/usr/bin/docker'
2023-07-18T13:20:47.8763506Z ##[debug]/usr/bin/docker arg: pull`
2023-07-18T13:20:47.8764166Z ##[debug]/usr/bin/docker arg: ***/php8-base:latest
2023-07-18T13:20:47.8764916Z ##[debug]exec tool: /usr/bin/docker
2023-07-18T13:20:47.8765285Z ##[debug]arguments:
2023-07-18T13:20:47.8765637Z ##[debug]   pull
2023-07-18T13:20:47.8766055Z ##[debug]   ***/php8-base:latest
2023-07-18T13:20:47.8766779Z [command]/usr/bin/docker pull ***/php8-base:latest
2023-07-18T13:20:53.4683424Z Error response from daemon: Head "https://***/v2/php8-base/manifests/latest": unauthorized: Invalid clientid or client secret.
2023-07-18T13:20:53.4707635Z ##[debug]An error was found pulling the image ***/php8-base:latest, the command output was Error response from daemon: Head "https://***/v2/php8-base/manifests/latest": unauthorized: Invalid clientid or client secret.

2023-07-18T13:20:53.4708257Z ##[debug]which '/usr/bin/docker'
2023-07-18T13:20:53.4709275Z ##[debug]found: '/usr/bin/docker'
2023-07-18T13:20:53.4709633Z ##[debug]/usr/bin/docker arg: inspect
2023-07-18T13:20:53.4710044Z ##[debug]/usr/bin/docker arg: ***/php8-base:latest
2023-07-18T13:20:53.4710414Z ##[debug]exec tool: /usr/bin/docker
2023-07-18T13:20:53.4710746Z ##[debug]arguments:
2023-07-18T13:20:53.4711066Z ##[debug]   inspect
2023-07-18T13:20:53.4711449Z ##[debug]   ***/php8-base:latest
2023-07-18T13:20:53.4712071Z [command]/usr/bin/docker inspect ***/php8-base:latest
2023-07-18T13:20:53.5095970Z Error: No such object: ***/php8-base:latest

流水线文件(怀疑SSH构建环节有问题,替换后仍报错)

# Docker
# Build and push an image to Azure Container Registry
# https://docs.microsoft.com/azure/devops/pipelines/languages/docker

trigger:
- develop

resources:
- repo: self

variables:
  # Variable group definition for specific site
- group: *******-dev
  # Container registry service connection established during pipeline creation
- name: dockerRegistryServiceConnection
  value: '*********-****-****-****-***********'
- name: imageRepository
  value: '$(IMAGE_NAME)'
- name: containerRegistry
  value: '***********.azurecr.io'
- name: dockerfilePath
  value: '$(Build.SourcesDirectory)/Dockerfile'
- name: tag
  value: '$(Build.BuildId)'
  # Agent VM image name
- name: vmImageName
  value: 'ubuntu-latest'
- name: image
  value: '$(Build.BuildId)'

# ----------------
# Build stage, dockerbuild and ACR tag/push
# ----------------

stages:
- stage: Build
  displayName: Build and push stage
  jobs:
  - job: Build
    displayName: Build
    variables:
    - group: *******-dev
    pool:
      vmImage: $(vmImageName)
    steps:
# ----------------
# Stage ssh keys from securefiles
# ----------------

    - task: DownloadSecureFile@1
      name: satis_id_rsa
      inputs:
        secureFile: satis_id_rsa

# ----------------
# Setup ssh key from secure file used by dockerbuild for azure repo access, also used by satis for repo access
# ----------------

    - task: CmdLine@2
      displayName: ssh key setup for dockerbuild
      inputs:
        script: |
          AZURE_ID_RSA=$(cat $(satis_id_rsa.secureFilePath) | base64 -w 0)
          echo "##vso[task.setvariable variable=AZURE_ID_RSA;issecret=true]$AZURE_ID_RSA"

    - task: Docker@2
      displayName: Build container image from dockerfile
      inputs:
        command: build
        repository: $(imageRepository)
        dockerfile: $(dockerfilePath)
        containerRegistry: $(dockerRegistryServiceConnection)
        arguments: --build-arg COMPOSER_REPO_URL=$(COMPOSER_REPO_URL) --build-arg AZURE_ID_RSA=$(AZURE_ID_RSA)
        tags: |
          $(tag)
          latest
    - task: Docker@2
      displayName: Push container image from dockerfile
      inputs:
        command: push
        repository: $(imageRepository)
        containerRegistry: $(dockerRegistryServiceConnection)
        tags: |
          $(tag)
          latest

# ----------------
# Deploy stage, deploys to aks cluster
# ----------------

- stage: Deploy_dev
  displayName: Deploy to dev
  jobs:
  - deployment: Deploy_dev
    displayName: Deploy_dev
    variables:
    - group: ******-dev
    pool:
      vmImage: $(vmImageName)
    environment: '******-dev'
    strategy: 
      runOnce:
        deploy:
          steps:
          - checkout: self

# ----------------
# task to replace vars in aks-*.yml files, based on site var group
# ----------------

          - task: qetza.replacetokens.replacetokens-task.replacetokens@3
            displayName: 'Prepare aks-*.yaml manifest file'
            inputs:
              targetFiles: 'pipeline/aks-*.yml'
              tokenPrefix: ___
              tokenSuffix: ___

# ----------------
# task to deploy site k8s config to aks cluster
# ----------------

          - task: Kubernetes@1
            displayName: Deploy latest image to aks cluster
            inputs:
              connectionType: 'Kubernetes Service Connection'
              kubernetesServiceEndpoint: '**************************'
              namespace: '$(SITE_NAME)'
              command: 'apply'
              useConfigurationFile: true
              configuration: 'pipeline/aks-deployment.yml'
              secretType: 'dockerRegistry'
              containerRegistryType: 'Azure Container Registry'

排查情况

  • 确认Azure Resource Manager服务连接有效并重新生成
  • 替换了SSH密钥,问题仍未解决

恳请各位提供解决思路!

相关服务连接截图

服务连接截图


内容的提问来源于stack exchange,提问作者SulllivanWorks

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 12:37:07