You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Release Pipeline动态引用多客户密钥变量的问题

问题描述
  • Azure密钥保管库中密钥命名格式为customerName-customerEnvironmentType-secretName
  • 采用多配置作业的Azure发布流水线,为每个客户创建独立作业,包含两步:
    • 通过过滤器customerName-customerEnvironmentType-secretName从保管库拉取密钥
    • 执行Bash脚本打印环境变量和密钥(日志需显示为****)
  • 已将customerName-customerEnvironmentType存入变量FULL_NAME,但尝试多种变量替换方式均无法动态获取对应密钥,相关脚本及执行日志如下:

测试Bash脚本

#!/bin/bash

env | sort

echo "FULL_NAME: $(FULL_NAME)" # This prints customerName-customerEnvironmentType

echo "normal usage: $(customerName-customerEnvironmentType-secretName)" # This works and prints ***, but this wouldn't be dynamic and would only work for one customer

# Some options I tried, all of them do not resolve. Some of them don't even resolve the FULL_NAME variable
echo "variables['customerName-customerEnvironmentType-secretName']"
echo "${{ variables['FULL_NAME'] }}"
echo "${{ variables.FULL_NAME }}"
echo "$($(FULL_NAME)-secretName)"
echo "$(${{ variables.FULL_NAME }}-secretName)"
echo "variables['$(FULL_NAME)-secretName']"
echo "$(variables['$(FULL_NAME)-secretName'])"
echo "$[variables['$(FULL_NAME)-secretName']]"

Azure密钥保管库任务日志

2022-12-27T13:38:38.0903674Z ##[section]Starting: Azure Key Vault: customer-environments
2022-12-27T13:38:38.0909613Z ==============================================================================
2022-12-27T13:38:38.0909898Z Task         : Azure Key Vault
2022-12-27T13:38:38.0910115Z Description  : Download Azure Key Vault secrets
2022-12-27T13:38:38.0910336Z Version      : 2.211.1
2022-12-27T13:38:38.0910524Z Author       : Microsoft Corporation
2022-12-27T13:38:38.0910836Z Help         : https://docs.microsoft.com/azure/devops/pipelines/tasks/deploy/azure-key-vault
2022-12-27T13:38:38.0911185Z ==============================================================================
2022-12-27T13:38:38.2801948Z SubscriptionId: hidden-for-security.
2022-12-27T13:38:38.2804271Z Key vault name: customer-environments.
2022-12-27T13:38:38.2810602Z Downloading secrets using: hidden-for-security.
2022-12-27T13:38:38.8860681Z Number of secrets found in customer-environments: 8
2022-12-27T13:38:38.8900028Z Number of enabled and unexpired secrets found in customer-environments: 8
2022-12-27T13:38:38.8909999Z Downloading secret value for: customerName-customerEnvironmentType-secretName.
.... there where more here, but i have hidden them
2022-12-27T13:38:39.0434461Z ##[section]Finishing: Azure Key Vault: customer-environments

Bash脚本任务日志

2022-12-27T13:38:39.7977754Z ##[section]Starting: Bash Script
2022-12-27T13:38:39.7990665Z ==============================================================================
2022-12-27T13:38:39.7991040Z Task         : Bash
2022-12-27T13:38:39.7991348Z Description  : Run a Bash script on macOS, Linux, or Windows
2022-12-27T13:38:39.7991674Z Version      : 3.211.0
2022-12-27T13:38:39.7991955Z Author       : Microsoft Corporation
2022-12-27T13:38:39.7992334Z Help         : https://docs.microsoft.com/azure/devops/pipelines/tasks/utility/bash
2022-12-27T13:38:39.7992749Z ==============================================================================
2022-12-27T13:38:40.0194291Z Generating script.
2022-12-27T13:38:40.0198418Z ========================== Starting Command Output ===========================
2022-12-27T13:38:40.0202702Z [command]/usr/bin/bash /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh
... removed the output of env | sort for security reasons
2022-12-27T13:38:40.0288018Z FULL_NAME: customerName-customerEnvironmentType
2022-12-27T13:38:40.0298702Z normal usage: ***
2022-12-27T13:38:40.0299290Z variables['customerName-customerEnvironmentType-secretName']
2022-12-27T13:38:40.0299794Z 
2022-12-27T13:38:40.0300226Z 
2022-12-27T13:38:40.0301018Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 11: ${{ variables['FULL_NAME'] }}: bad substitution
2022-12-27T13:38:40.0302092Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 12: ${{ variables.FULL_NAME }}: bad substitution
2022-12-27T13:38:40.0304197Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 13: customerName-customerEnvironmentType-secretName: command not found
2022-12-27T13:38:40.0305052Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 14: ${{ variables.FULL_NAME }}-secretName: bad substitution
2022-12-27T13:38:40.0305862Z variables['customerName-customerEnvironmentType-secretName']
2022-12-27T13:38:40.0306661Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 15: variables[customerName-customerEnvironmentType-secretName]: command not found
2022-12-27T13:38:40.0307284Z 
2022-12-27T13:38:40.0308101Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 16: 'customerName-customerEnvironmentType-secretName': syntax error: operand expected (error token is "'customerName-customerEnvironmentType-secretName'")
2022-12-27T13:38:40.0337412Z ##[error]Bash exited with code '1'.
2022-12-27T13:38:40.0352993Z ##[section]Finishing: Bash Script
解决方案

方法1:Bash间接变量引用(推荐,支持运行时变量)

Azure密钥保管库任务会将下载的密钥作为环境变量注入作业,利用Bash的间接引用语法可以动态获取:

#!/bin/bash

env | sort

echo "FULL_NAME: $FULL_NAME"

# 拼接完整密钥名称,通过间接引用获取值
SECRET_KEY="${FULL_NAME}-secretName"
echo "dynamic usage: ${!SECRET_KEY}"

${!SECRET_KEY}会解析SECRET_KEY的值作为实际环境变量名,自动获取对应密钥,且日志中会显示为****。

方法2:流水线编译期变量拼接(仅适用于预定义流水线变量)

如果FULL_NAME是流水线级别预定义的变量,可利用Azure Pipelines的编译期表达式提前拼接密钥名:

#!/bin/bash

env | sort

echo "FULL_NAME: $FULL_NAME"

# 编译阶段拼接密钥名称,运行时直接引用
echo "dynamic usage: $(${{ variables.FULL_NAME }}-secretName)"

注意:此方法仅适用于编译阶段就能确定值的流水线变量,如果FULL_NAME是运行时生成的,只能用方法1。

错误原因说明
  • ${{ variables['FULL_NAME'] }}是Azure Pipelines编译期表达式,不能直接在Bash脚本中使用,会被Bash识别为无效变量替换语法
  • $(variables['xxx'])是错误语法,Azure Pipelines变量在Bash中直接用$VAR_NAME引用即可
  • $($(FULL_NAME)-secretName)会被Bash当作命令执行,而非变量引用,因此报"command not found"错误

内容的提问来源于stack exchange,提问作者timos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 15:10:23