Azure Pipeline中Maven任务部署Jar至Azure Artifact遇403权限问题
问题现象
已将Azure Artifact配置到pom.xml,CentOS7代理本地部署可正常运行,但Azure Pipeline的Maven任务部署时出现403 Forbidden错误,提示用户7ba7a839-2613-4554-84a4-4aa2d4cf4162缺少AddPackage权限(实际该用户已拥有完整权限),Windows代理可成功执行。错误日志如下:
[ERROR] Failed to execute goal org.apache.maven.plugins:maven-deploy-plugin:3.0.0:deploy (default-deploy) on project my-server: Failed to deploy artifacts: Could not transfer artifact:pom:1.0 from/to artifact authorization failed for https://pkgs.dev.azure.com/, status: 403 Forbidden - User '7ba7a839-2613-4554-84a4-4aa2d4cf4162' lacks permission to complete this action. You need to have 'AddPackage'. (DevOps Activity ID: 46D5F76C-E82C-48C8-8D63-4269F3CE4F65) -> [Help 1]
[ERROR]
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR]
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException
排查与解决步骤
验证settings.xml的路径与权限
- 确认Pipeline执行Maven任务时使用的是你配置的
~/.m2/settings.xml,而非系统级配置(如/etc/maven/settings.xml)。可在Pipeline中添加脚本任务执行mvn help:effective-settings查看生效配置。 - 将settings.xml的文件权限设置为600(仅所有者可读),执行命令:
chmod 600 ~/.m2/settings.xml,避免权限过宽导致Maven拒绝加载配置。 - 核对settings.xml中server的
id与pom.xml里repository的id完全一致,确保令牌无换行、空格或拼写错误。
- 确认Pipeline执行Maven任务时使用的是你配置的
确认Pipeline执行的用户上下文
- 在Pipeline中添加脚本任务,执行
whoami和ls -la ~/.m2/settings.xml,确认执行任务的用户(通常是azagent)与settings.xml的所属用户一致。如果不一致,需将settings.xml复制到azagent用户的~/.m2目录下。
- 在Pipeline中添加脚本任务,执行
排查令牌问题
- 若令牌包含特殊字符(如
+、/、=),检查settings.xml中是否保留了原始令牌值,未被shell转义。 - 重新生成仅包含**Packaging (Read & Write)**权限的PAT令牌,替换现有令牌,排除旧令牌的隐性权限异常。
- 若令牌包含特殊字符(如
强制指定settings.xml路径
在Azure Pipeline的Maven任务中添加参数:-s ~/.m2/settings.xml,强制Maven加载你配置的settings文件,避免自动加载其他配置。
内容的提问来源于stack exchange,提问作者Muha-mmad

