Azure DevOps CI/CD构建中NuGet还原401未授权问题求助
Azure DevOps流水线NuGet还原401未授权问题解决
问题现象
使用Azure DevOps流水线进行CI/CD时,构建过程中还原NuGet包频繁出现401未授权错误,示例错误信息如下:
/home/vsts/work/1/s/backend/tests/DemoModule.IntegrationTests/DemoModule.IntegrationTests.csproj : error NU1301: Failed to retrieve information about 'Humanizer.Core.sl' from remote source 'https://microsofthealthoss.pkgs.visualstudio.com/7621b231-1a7d-4364-935b-2f72b911c43d/_packaging/a60b7c8b-c6ae-4a8e-bd15-a526b603a1f2/nuget/v3/flat2/humanizer.core.sl/index.json'. Response status code does not indicate success: 401 (Unauthorized - No local versions of package 'skiasharp'; please provide authentication to access versions from upstream that have not yet been saved to your feed. (DevOps Activity ID: C5C4A299-C79F-4456-ABA4-8D876A094568)). Retrying 'FindPackagesByIdAsync' for source 'https://microsofthealthoss.pkgs.visualstudio.com/7621b231-1a7d-4364-935b-2f72b911c43d/_packaging/a60b7c8b-c6ae-4a8e-bd15-a526b603a1f2/nuget/v3/flat2/skiasharp.nativeassets.linux.nodependencies/index.json'.
因业务需求需使用https://microsofthealthoss.pkgs.visualstudio.com/FhirServer/_packaging/Public/nuget/v3/index.json源中的Microsoft.Health.Dicom.Client包,当前配置如下:
当前NuGet.config配置
<?xml version="1.0" encoding="utf-8"?> <configuration> <packageSources> <clear /> <add key="nuget.org" value="https://api.nuget.org/v3/index.json" protocolVersion="3" /> <add key="Public" value="https://microsofthealthoss.pkgs.visualstudio.com/FhirServer/_packaging/Public/nuget/v3/index.json" /> </packageSources> </configuration>
当前Azure DevOps流水线配置
stages: - stage: build_and_deploy jobs: - deployment: DeployToDev displayName: Deploy to dev pool: vmImage: "ubuntu-latest" environment: demo-module-dev strategy: runOnce: deploy: steps: - checkout: self - task: NuGetCommand@2 displayName: "NuGet restore" inputs: restoreSolution: '**\*.sln' feedsToUse: config nugetConfigPath: 'backend/NuGet.config' - task: DotNetCoreCLI@2 displayName: Build Solution inputs: command: build projects: "**/src/*.csproj" publishWebProjects: false modifyOutputPath: false zipAfterPublish: false
已尝试方案(2023年7月10日更新)
- 修改NuGet.config添加凭据,但不清楚目标源的正确认证信息
- 使用
NuGetAuthenticate@1任务,但microsoft/artifacts-credprovider不支持该外部源
解决方案
1. 通过Azure DevOps服务连接实现安全认证
- 创建Generic服务连接:在当前Azure DevOps项目的「项目设置」→「服务连接」中,新建Generic类型的服务连接,目标URL填写
https://microsofthealthoss.pkgs.visualstudio.com/FhirServer/_packaging/Public/nuget/v3/index.json,认证方式选择Personal Access Token (PAT),该PAT需要在microsofthealthoss组织中生成,权限至少勾选「Packaging → Read」。 - 更新流水线任务:在NuGet restore任务前添加
NuGetAuthenticate@1任务,指定刚才创建的服务连接:
该任务会自动将凭据注入到NuGet.config中,无需手动修改配置文件。- task: NuGetAuthenticate@1 displayName: 'NuGet Authenticate for External Feed' inputs: nuGetServiceConnections: '你的服务连接名称'
2. 配置NuGet.config注入PAT(需注意保密)
- 修改NuGet.config,添加
packageSourceCredentials节点,用户名可任意填写(如PAT),密码使用有权限访问目标源的PAT:<?xml version="1.0" encoding="utf-8"?> <configuration> <packageSources> <clear /> <add key="nuget.org" value="https://api.nuget.org/v3/index.json" protocolVersion="3" /> <add key="Public" value="https://microsofthealthoss.pkgs.visualstudio.com/FhirServer/_packaging/Public/nuget/v3/index.json" /> </packageSources> <packageSourceCredentials> <Public> <add key="Username" value="PAT" /> <add key="ClearTextPassword" value="$(ExternalFeedPAT)" /> </Public> </packageSourceCredentials> </configuration> - 在流水线的「变量」中添加
ExternalFeedPAT变量,将其标记为秘密变量,避免明文泄露。
3. 确认目标Feed的权限
- 确保生成PAT的账号在
microsofthealthoss组织的PublicFeed中被分配了Feed Reader角色,否则会因权限不足导致401错误。
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

