Azure Pipelines:如何通过CLI/API批量审批多流水线环境部署请求
Great question—batch approving pipeline approvals is such a common pain point when you’re managing dozens (or hundreds!) of production deployment pipelines, especially since the UI doesn’t support bulk actions. Let’s walk through all the viable methods to solve this, covering REST API, CLI, scripted approaches, and even automated workflows:
1. REST API Approach
This is the most direct way to handle bulk approvals, and it’s fully supported in Azure DevOps. You’ll need two steps: fetch pending approvals, then approve them in bulk.
Step 1: Retrieve Pending Approvals
Use the Approval Requests - List endpoint to filter for pending approvals. You can narrow results by environment, pipeline, or other criteria using the $filter parameter:
GET https://dev.azure.com/{organization}/{project}/_apis/pipelines/approvals?api-version=7.1-preview.1&$filter=status eq 'pending' and environment.name eq 'Production'
This example targets only pending approvals for your Production environment—adjust the filter to match your needs.
Step 2: Approve Individual Requests
For each approval ID returned from the first call, send a PATCH request to the Approval Requests - Update endpoint:
PATCH https://dev.azure.com/{organization}/{project}/_apis/pipelines/approvals/{approvalId}?api-version=7.1-preview.1 Content-Type: application/json { "status": "approved", "comments": "Batch approved via REST API (audit trail)" }
Permissions note: You’ll need a PAT token with vso.build_execute and vso.release_execute scopes, and the account must have Pipeline Approver access to the target environments/pipelines.
2. Azure DevOps CLI Method
While there’s no dedicated az devops pipeline approval approve command, you can use az devops invoke to call the same REST APIs directly from the CLI. This is great for scripting in bash/zsh environments.
Example Bulk Approve Script
# Set your variables ORG="https://dev.azure.com/your-org-name" PROJ="your-project-name" API_VERSION="7.1-preview.1" # Get all pending production approvals PENDING_APPROVALS=$(az devops invoke --org $ORG --project $PROJ --area pipelines --resource approvals --api-version $API_VERSION --query "value[?status=='pending' && environment.name=='Production'].id" -o tsv) # Loop through and approve each for APPROVAL_ID in $PENDING_APPROVALS; do az devops invoke --org $ORG --project $PROJ --area pipelines --resource approvals --resource-id $APPROVAL_ID --api-version $API_VERSION --http-method PATCH --body '{"status":"approved","comments":"Batch approved via Azure CLI"}' echo "Approved request ID: $APPROVAL_ID" done
Make sure you’re logged into the CLI (az devops login) or set the AZURE_DEVOPS_EXT_PAT environment variable for non-interactive use.
3. PowerShell Script for Bulk Approval
If you prefer PowerShell (especially for Windows environments), this script will automate the entire process with added flexibility for filtering:
# Configure your settings $orgUrl = "https://dev.azure.com/your-org-name" $projectName = "your-project-name" $patToken = "your-pat-token-here" $targetEnvironment = "Production" # Encode PAT for authentication $encodedPat = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes(":$patToken")) $headers = @{Authorization = "Basic $encodedPat"} # Fetch pending approvals for target environment $approvalsUrl = "$orgUrl/$projectName/_apis/pipelines/approvals?api-version=7.1-preview.1&`$filter=status eq 'pending' and environment.name eq '$targetEnvironment'" $pendingApprovals = Invoke-RestMethod -Uri $approvalsUrl -Headers $headers -Method Get # Approve each request foreach ($approval in $pendingApprovals.value) { $approveUrl = "$orgUrl/$projectName/_apis/pipelines/approvals/$($approval.id)?api-version=7.1-preview.1" $body = @{ status = "approved" comments = "Bulk approved via PowerShell - $(Get-Date)" } | ConvertTo-Json Invoke-RestMethod -Uri $approveUrl -Headers $headers -Method Patch -Body $body -ContentType "application/json" Write-Host "Successfully approved request ID: $($approval.id)" }
You can expand the filter to include specific pipelines, requestors, or other attributes as needed.
4. Automated Workflows (Azure Logic Apps/Automation Runbooks)
For ongoing bulk approval needs (e.g., daily cleanup of pending production approvals), automate the process with these tools:
- Azure Logic Apps: Use the built-in Azure DevOps connector to set up a scheduled trigger (e.g., daily at 9 AM). Fetch pending approvals, loop through them, and send approval requests—no code required for basic flows.
- Azure Automation Runbooks: Upload the PowerShell script above as a runbook, set a schedule, and let Azure handle the bulk approval automatically. This is ideal for more complex filtering or integration with other Azure services.
Key Best Practices
- Filter aggressively: Always narrow your approval scope (e.g., by environment or pipeline) to avoid approving unintended requests.
- Audit trails: Add descriptive comments to each approval to track who/what initiated the bulk action for compliance.
- Restrict permissions: Use a dedicated service account with minimal approval permissions (only for the environments/pipelines you need) to reduce risk.
内容的提问来源于stack exchange,提问作者ebashmakov

