Azure Pipeline中连接字符串存为变量时数据库迁移失败求助
Azure Pipeline中SqlAzureDacpacDeployment机密连接字符串迁移失败问题解决
背景
之前用SqlAzureDacpacDeployment@1任务执行数据库迁移一切正常,原配置如下:
- task: SqlAzureDacpacDeployment@1 displayName: "App DB migration" inputs: azureSubscription: $(SrvConn) AuthenticationType: 'connectionString' ConnectionString: "Server=tcp:my-server.database.windows.net,1433;Database=my-db;Persist Security Info=False;User=the_user;Password=hash_puppy;MultipleActiveResultSets=False;Encrypt=True;TrustServerCertificate=False;Connection Timeout=30;" deployType: 'SqlTask' SqlFile: '$(Pipeline.Workspace)/migration/db_app.sql' IpDetectionMethod: 'AutoDetect'
为了安全,我把原连接字符串存成了Azure Pipeline的机密变量(命名为connstring),但修改任务后迁移一直失败,试了好几种写法都报错。
错误详情
用以下写法时:
ConnectionString: '%CONNSTR%' # 或者 ConnectionString: $(CONSTRDEV) # 或者 ConnectionString: $(env:CONSTRDEV)报错:
##[error]Format of the initialization string does not conform to specification starting at index 0.Check out how to troubleshoot failures at https://aka.ms/sqlazuredeployreadme#troubleshooting
用
ConnectionString: %CONNSTR%时:
报错:While scanning for the next token, find character that cannot start any token.
异常现象
但通过下面的PowerShell任务能正常输出变量值:
- pwsh: Write-Host ${env:CONSTRDEV}
解决步骤
- 核对变量名:确保任务里引用的变量名和Azure Pipeline中配置的机密变量名完全一致,注意大小写敏感——比如你存的是
connstring,就不能写成CONSTRDEV。 - 正确引用变量:YAML任务里直接用
$(变量名)格式引用机密变量,不用加引号或环境变量前缀。比如变量名叫connstring,写法应为:ConnectionString: $(connstring) - 检查连接字符串完整性:确认存入机密变量的连接字符串和原字符串完全一样,没有多空格、引号或转义字符——机密变量的值会直接注入,不需要手动处理转义。
- 处理特殊字符:如果连接字符串里有
$这类YAML敏感字符,用单引号把整个变量引用包起来:ConnectionString: '$(connstring)'
内容的提问来源于stack exchange,提问作者Konrad Viltersten
相关产品推荐
相关产品推荐

