Azure Release Pipeline动态引用多客户密钥变量的问题
问题描述
- Azure密钥保管库中密钥命名格式为
customerName-customerEnvironmentType-secretName - 采用多配置作业的Azure发布流水线,为每个客户创建独立作业,包含两步:
- 通过过滤器
customerName-customerEnvironmentType-secretName从保管库拉取密钥 - 执行Bash脚本打印环境变量和密钥(日志需显示为****)
- 通过过滤器
- 已将
customerName-customerEnvironmentType存入变量FULL_NAME,但尝试多种变量替换方式均无法动态获取对应密钥,相关脚本及执行日志如下:
测试Bash脚本
#!/bin/bash env | sort echo "FULL_NAME: $(FULL_NAME)" # This prints customerName-customerEnvironmentType echo "normal usage: $(customerName-customerEnvironmentType-secretName)" # This works and prints ***, but this wouldn't be dynamic and would only work for one customer # Some options I tried, all of them do not resolve. Some of them don't even resolve the FULL_NAME variable echo "variables['customerName-customerEnvironmentType-secretName']" echo "${{ variables['FULL_NAME'] }}" echo "${{ variables.FULL_NAME }}" echo "$($(FULL_NAME)-secretName)" echo "$(${{ variables.FULL_NAME }}-secretName)" echo "variables['$(FULL_NAME)-secretName']" echo "$(variables['$(FULL_NAME)-secretName'])" echo "$[variables['$(FULL_NAME)-secretName']]"
Azure密钥保管库任务日志
2022-12-27T13:38:38.0903674Z ##[section]Starting: Azure Key Vault: customer-environments 2022-12-27T13:38:38.0909613Z ============================================================================== 2022-12-27T13:38:38.0909898Z Task : Azure Key Vault 2022-12-27T13:38:38.0910115Z Description : Download Azure Key Vault secrets 2022-12-27T13:38:38.0910336Z Version : 2.211.1 2022-12-27T13:38:38.0910524Z Author : Microsoft Corporation 2022-12-27T13:38:38.0910836Z Help : https://docs.microsoft.com/azure/devops/pipelines/tasks/deploy/azure-key-vault 2022-12-27T13:38:38.0911185Z ============================================================================== 2022-12-27T13:38:38.2801948Z SubscriptionId: hidden-for-security. 2022-12-27T13:38:38.2804271Z Key vault name: customer-environments. 2022-12-27T13:38:38.2810602Z Downloading secrets using: hidden-for-security. 2022-12-27T13:38:38.8860681Z Number of secrets found in customer-environments: 8 2022-12-27T13:38:38.8900028Z Number of enabled and unexpired secrets found in customer-environments: 8 2022-12-27T13:38:38.8909999Z Downloading secret value for: customerName-customerEnvironmentType-secretName. .... there where more here, but i have hidden them 2022-12-27T13:38:39.0434461Z ##[section]Finishing: Azure Key Vault: customer-environments
Bash脚本任务日志
2022-12-27T13:38:39.7977754Z ##[section]Starting: Bash Script 2022-12-27T13:38:39.7990665Z ============================================================================== 2022-12-27T13:38:39.7991040Z Task : Bash 2022-12-27T13:38:39.7991348Z Description : Run a Bash script on macOS, Linux, or Windows 2022-12-27T13:38:39.7991674Z Version : 3.211.0 2022-12-27T13:38:39.7991955Z Author : Microsoft Corporation 2022-12-27T13:38:39.7992334Z Help : https://docs.microsoft.com/azure/devops/pipelines/tasks/utility/bash 2022-12-27T13:38:39.7992749Z ============================================================================== 2022-12-27T13:38:40.0194291Z Generating script. 2022-12-27T13:38:40.0198418Z ========================== Starting Command Output =========================== 2022-12-27T13:38:40.0202702Z [command]/usr/bin/bash /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh ... removed the output of env | sort for security reasons 2022-12-27T13:38:40.0288018Z FULL_NAME: customerName-customerEnvironmentType 2022-12-27T13:38:40.0298702Z normal usage: *** 2022-12-27T13:38:40.0299290Z variables['customerName-customerEnvironmentType-secretName'] 2022-12-27T13:38:40.0299794Z 2022-12-27T13:38:40.0300226Z 2022-12-27T13:38:40.0301018Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 11: ${{ variables['FULL_NAME'] }}: bad substitution 2022-12-27T13:38:40.0302092Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 12: ${{ variables.FULL_NAME }}: bad substitution 2022-12-27T13:38:40.0304197Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 13: customerName-customerEnvironmentType-secretName: command not found 2022-12-27T13:38:40.0305052Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 14: ${{ variables.FULL_NAME }}-secretName: bad substitution 2022-12-27T13:38:40.0305862Z variables['customerName-customerEnvironmentType-secretName'] 2022-12-27T13:38:40.0306661Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 15: variables[customerName-customerEnvironmentType-secretName]: command not found 2022-12-27T13:38:40.0307284Z 2022-12-27T13:38:40.0308101Z /home/vsts/work/_temp/6ad51bf7-2673-449a-9e74-66b2bb6abb19.sh: line 16: 'customerName-customerEnvironmentType-secretName': syntax error: operand expected (error token is "'customerName-customerEnvironmentType-secretName'") 2022-12-27T13:38:40.0337412Z ##[error]Bash exited with code '1'. 2022-12-27T13:38:40.0352993Z ##[section]Finishing: Bash Script
解决方案
方法1:Bash间接变量引用(推荐,支持运行时变量)
Azure密钥保管库任务会将下载的密钥作为环境变量注入作业,利用Bash的间接引用语法可以动态获取:
#!/bin/bash env | sort echo "FULL_NAME: $FULL_NAME" # 拼接完整密钥名称,通过间接引用获取值 SECRET_KEY="${FULL_NAME}-secretName" echo "dynamic usage: ${!SECRET_KEY}"
${!SECRET_KEY}会解析SECRET_KEY的值作为实际环境变量名,自动获取对应密钥,且日志中会显示为****。
方法2:流水线编译期变量拼接(仅适用于预定义流水线变量)
如果FULL_NAME是流水线级别预定义的变量,可利用Azure Pipelines的编译期表达式提前拼接密钥名:
#!/bin/bash env | sort echo "FULL_NAME: $FULL_NAME" # 编译阶段拼接密钥名称,运行时直接引用 echo "dynamic usage: $(${{ variables.FULL_NAME }}-secretName)"
注意:此方法仅适用于编译阶段就能确定值的流水线变量,如果FULL_NAME是运行时生成的,只能用方法1。
错误原因说明
${{ variables['FULL_NAME'] }}是Azure Pipelines编译期表达式,不能直接在Bash脚本中使用,会被Bash识别为无效变量替换语法$(variables['xxx'])是错误语法,Azure Pipelines变量在Bash中直接用$VAR_NAME引用即可$($(FULL_NAME)-secretName)会被Bash当作命令执行,而非变量引用,因此报"command not found"错误
内容的提问来源于stack exchange,提问作者timos
相关产品推荐
相关产品推荐

