Azure DevOps Windows流水线Git拉取失败,本地执行正常
Azure DevOps流水线Windows代理Git Checkout认证失败问题
我创建的Azure DevOps流水线在Git checkout阶段失败,使用Windows代理时出现HTTP Basic认证错误,但切换到MAC代理时流水线可正常运行,且本地Windows命令行执行相同Git命令也能成功拉取代码。
流水线错误日志
Starting: Checkout repository@Dev to s ============================================================================== Task : Get sources Description : Get sources from a repository. Supports Git, TfsVC, and SVN repositories. Version : 1.0.0 Author : Microsoft Help : [More Information](https://go.microsoft.com/fwlink/?LinkId=798199) ============================================================================== Syncing repository: repository (ExternalGit) Prepending Path environment variable with directory containing 'git.exe'. git version git version 2.39.1.windows.1 git lfs version git-lfs/2.13.3 (GitHub; windows amd64; go 1.16.2; git a5e65851) git init "D:\a\1\s" Initialized empty Git repository in D:/a/1/s/.git/ git remote add origin http://gitlab.mycompany.net/mycompany/myapp.git git config gc.auto 0 git config --get-all http.http://gitlab.mycompany.net/mycompany/myapp.git.extraheader git config --get-all http.extraheader git config --get-regexp .*extraheader git config --get-all http.proxy git config http.version HTTP/1.1 git remote set-url origin http://***:***@gitlab.mycompany.net/mycompany/myapp.git git remote set-url --push origin http://***:***@gitlab.mycompany.net/mycompany/myapp.git git fetch --force --no-tags --prune --prune-tags --progress --no-recurse-submodules origin remote: HTTP Basic: Access denied. The provided password or token is incorrect or your account has 2FA enabled and you must use a personal access token instead of a password. See http://gitlab.mycompany.net/help/topics/git/troubleshooting_git#error-on-git-fetch-http-basic-access-denied fatal: Authentication failed for 'http://gitlab.mycompany.net/mycompany/myapp.git/' ##[warning]Git fetch failed with exit code 128, back off 6.062 seconds before retry. git fetch --force --no-tags --prune --prune-tags --progress --no-recurse-submodules origin remote: HTTP Basic: Access denied. The provided password or token is incorrect or your account has 2FA enabled and you must use a personal access token instead of a password. See http://gitlab.mycompany.net/help/topics/git/troubleshooting_git#error-on-git-fetch-http-basic-access-denied
本地命令行正常执行日志
C:\Users\Imran\repo>git version git version 2.32.0.windows.2 C:\Users\Imran\repo>git lfs version git-lfs/2.13.3 (GitHub; windows amd64; go 1.16.2; git a5e65851) C:\Users\Imran\repo>git init Initialized empty Git repository in C:/Users//Imran/repo/.git/ C:\Users\Imran\repo>git remote add origin http://gitlab.mycompany.net/mycompany/myapp.git C:\Users\Imran\repo>git config gc.auto 0 C:\Users\Imran\repo>git config --get-all http.http://gitlab.mycompany.net/mycompany/myapp.git.extraheader C:\Users\Imran\repo>git config --get-all http.extraheader C:\Users\Imran\repo>git config --get-regexp .*extraheader C:\Users\Imran\repo>git config --get-all http.proxy C:\Users\Imran\repo>git config http.version HTTP/1.1 C:\Users\Imran\repo>git remote set-url origin http://username:pass@gitlab.mycompany.net/mycompany/myapp.git C:\Users\Imran\repo>git remote set-url --push origin http://username:pass@gitlab.mycompany.net/mycompany/myapp.git C:\Users\Imran\repo>git fetch --force --no-tags --prune --prune-tags --progress --no-recurse-submodules origin warning: redirecting to https://gitlab.mycompany.net/mycompany/myapp.git/ remote: Enumerating objects: 54107, done. remote: Counting objects: 100% (1844/1844), done. remote: Compressing objects: 100% (138/138), done.
流水线代理配置截图

解决方法
1. 清理Windows代理的Git凭据
Windows代理机器可能存储了旧的Git凭据,导致认证冲突:
- 打开Windows凭据管理器(控制面板→用户账户→凭据管理器→Windows凭据)
- 查找
http://gitlab.mycompany.net相关的凭据条目并删除 - 重新运行流水线,让Azure DevOps重新注入正确凭据
2. 统一Git版本
流水线使用Git 2.39.1,本地是2.32.0,版本差异可能导致认证逻辑不同:
- 在Windows代理上降级Git到2.32.0,测试是否解决问题
- 或升级本地Git到2.39.1,确认是否能复现问题,排查版本特性差异
3. 清除Windows代理的全局Git代理配置
系统级代理可能干扰Git请求:
- 在Windows代理机器上执行以下命令清除全局代理:
git config --global --unset http.proxy git config --global --unset https.proxy - 重启代理服务后重新运行流水线
4. 确认PAT权限(若启用2FA)
如果GitLab账户启用了2FA,必须使用Personal Access Token(PAT)而非密码:
- 确保Azure DevOps服务连接中配置的是GitLab PAT,且该PAT拥有仓库读取权限
- 重新生成PAT,覆盖对应仓库权限后更新服务连接凭据
5. 切换仓库地址为HTTPS
本地执行时出现HTTP重定向到HTTPS的警告,流水线使用HTTP可能导致认证问题:
- 修改Azure DevOps流水线的仓库地址为
https://gitlab.mycompany.net/mycompany/myapp.git - 更新对应的服务连接URL后重新运行流水线
内容的提问来源于stack exchange,提问作者Imran Qadir Baksh - Baloch
相关产品推荐
相关产品推荐

