Azure DevOps Server 2020本地部署:如何用流水线/PowerShell设置库秘密变量
在Azure DevOps Server 2020中通过流水线或PowerShell设置库组秘密变量
可以。Azure DevOps Server 2020支持通过REST API结合PowerShell或流水线任务修改库组中的秘密变量,以下是具体操作方法:
方法一:本地PowerShell脚本直接修改
- 准备权限与令牌
- 创建具备
Variable Groups (Manage)权限的个人访问令牌(PAT),权限范围选择Variable Groups下的Manage。
- 创建具备
- 编写执行脚本
脚本通过调用Azure DevOps REST API获取库组信息,更新目标秘密变量后提交修改:# 配置环境参数 $collectionUri = "http://你的AzureDevOps服务器地址:8080/tfs/DefaultCollection" $projectName = "你的项目名称" $variableGroupName = "目标库组名称" $variableName = "要更新的秘密变量名" $newSecretValue = "新的秘密变量值" $pat = "你的PAT令牌" # 转换令牌为Base64格式 $base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$pat")) # 获取目标库组ID $getGroupUri = "$collectionUri/$projectName/_apis/distributedtask/variablegroups?api-version=6.0-preview.2&name=$variableGroupName" $groupResponse = Invoke-RestMethod -Uri $getGroupUri -Headers @{Authorization=("Basic {0}" -f $base64AuthInfo)} -Method Get $groupId = $groupResponse.value[0].id # 构造更新请求体(保留现有变量,仅更新目标秘密变量) $variables = @{} foreach ($var in $groupResponse.value[0].variables.PSObject.Properties) { $variables[$var.Name] = @{ value = $var.Value.value isSecret = $var.Value.isSecret } } $variables[$variableName] = @{ value = $newSecretValue isSecret = $true } $updateBody = @{ variables = $variables name = $variableGroupName description = $groupResponse.value[0].description } | ConvertTo-Json -Depth 10 # 发送更新请求 $updateUri = "$collectionUri/$projectName/_apis/distributedtask/variablegroups/$groupId?api-version=6.0-preview.2" Invoke-RestMethod -Uri $updateUri -Headers @{Authorization=("Basic {0}" -f $base64AuthInfo)} -Method Put -Body $updateBody -ContentType "application/json"- 替换脚本中的占位参数为实际环境值
- PAT需妥善保管,避免明文泄露
方法二:在Azure DevOps流水线中修改
通过流水线的PowerShell任务调用API,可使用系统自动生成的OAuth令牌,无需手动创建PAT:
- 配置流水线权限
- 确保流水线服务账号拥有目标库组的
Manage权限 - 在流水线编辑页面的
Agent job设置中,启用Allow scripts to access the OAuth token选项
- 确保流水线服务账号拥有目标库组的
- 添加YAML流水线步骤
steps: - powershell: | # 使用系统变量自动填充环境信息 $collectionUri = "$(System.TeamFoundationCollectionUri)" $projectName = "$(System.TeamProject)" $variableGroupName = "目标库组名称" $variableName = "要更新的秘密变量名" $newSecretValue = "$(NewSecretValue)" # 从流水线秘密变量传入新值 # 转换系统令牌为Base64格式 $base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$(System.AccessToken)")) # 获取目标库组ID $getGroupUri = "$collectionUri/$projectName/_apis/distributedtask/variablegroups?api-version=6.0-preview.2&name=$variableGroupName" $groupResponse = Invoke-RestMethod -Uri $getGroupUri -Headers @{Authorization=("Basic {0}" -f $base64AuthInfo)} -Method Get $groupId = $groupResponse.value[0].id # 构造更新请求体 $variables = @{} foreach ($var in $groupResponse.value[0].variables.PSObject.Properties) { $variables[$var.Name] = @{ value = $var.Value.value isSecret = $var.Value.isSecret } } $variables[$variableName] = @{ value = $newSecretValue isSecret = $true } $updateBody = @{ variables = $variables name = $variableGroupName description = $groupResponse.value[0].description } | ConvertTo-Json -Depth 10 # 发送更新请求 $updateUri = "$collectionUri/$projectName/_apis/distributedtask/variablegroups/$groupId?api-version=6.0-preview.2" Invoke-RestMethod -Uri $updateUri -Headers @{Authorization=("Basic {0}" -f $base64AuthInfo)} -Method Put -Body $updateBody -ContentType "application/json" displayName: '更新库组中的秘密变量' env: SYSTEM_ACCESSTOKEN: $(System.AccessToken)NewSecretValue需提前配置为流水线的秘密变量,避免明文暴露
注意事项
- 操作前确认账号权限,无权限会返回403错误
- 秘密变量更新后无法查看历史值,操作前请确认必要性
- Azure DevOps Server 2020仅支持
6.0-preview.2版本的变量组API,请勿使用更高版本
内容的提问来源于stack exchange,提问作者Rod
相关产品推荐
相关产品推荐

