Azure DevOps部署IIS Web应用时证书指定目录放置问题
Let's break down what's going wrong and fix it step by step:
Core Issues
- Your current workflow copies the cert to the Certificates folder but leaves the original in the root directory — when you re-archive the files, both the root-level
.cerand the one inCertificatesget included in the deployment package. That's why you see the cert in both places after deployment. - If you're observing that the solution deploys first then the cert gets placed, that likely means your original step order was out of alignment (though the YAML you shared shows the correct "process first, deploy later" flow — maybe there was a misconfiguration earlier).
Solution 1: Download Cert Directly to Certificates Folder (Recommended)
This cuts out unnecessary steps and ensures the cert never hits the root directory. We'll add a step to create the Certificates folder if it doesn't exist (since your extracted Web package might not include it):
steps: - task: ExtractFiles@1 displayName: 'Extract Web package' inputs: archiveFilePatterns: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\drop\Web.zip' destinationFolder: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' # Create Certificates folder if it doesn't exist in the extracted package - task: PowerShell@2 displayName: 'Ensure Certificates folder exists' inputs: targetType: 'inline' script: | $certFolder = "$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip\Certificates" if (-not (Test-Path $certFolder)) { New-Item -ItemType Directory -Path $certFolder | Out-Null } # Download cert directly to the Certificates folder - task: mattlabrum.build-task.custom-build-task.downloadsSecureFile@0 displayName: 'Download Cert to Certificates folder' inputs: fileInput: 'certnew_64.cer' targetPath: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip\Certificates' # Archive the modified package (use a unique name to avoid overwriting the original) - task: ArchiveFiles@2 displayName: 'Archive modified Web package' inputs: rootFolderOrFile: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' includeRootFolder: false archiveFile: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\drop\Web-modified.zip' replaceExistingArchive: true # Deploy the modified package to IIS - task: IISWebAppDeploymentOnMachineGroup@0 displayName: 'IIS Web App Deploy' inputs: WebSiteName: '$(Parameters.WebsiteName)' Package: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\drop\Web-modified.zip' TakeAppOfflineFlag: True XmlVariableSubstitution: true
Solution 2: Keep Copy Step, But Remove Root Cert
If you prefer to keep your original copy workflow, add a step to delete the root-level .cer file after copying it to the Certificates folder. This ensures only the correctly placed cert gets included in the deployment package:
steps: - task: ExtractFiles@1 displayName: 'Extract files ' inputs: archiveFilePatterns: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\drop\Web.zip' destinationFolder: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' - task: mattlabrum.build-task.custom-build-task.downloadsSecureFile@0 displayName: 'Download Certs' inputs: fileInput: 'certnew_64.cer' targetPath: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' - task: CopyFiles@2 displayName: 'Copy Cert to Certificates folder' inputs: SourceFolder: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' Contents: '*.cer' TargetFolder: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip\Certificates' OverWrite: true # Delete the root-level cert after copying - task: DeleteFiles@1 displayName: 'Remove cert from root directory' inputs: SourceFolder: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' Contents: '*.cer' - task: ArchiveFiles@2 displayName: 'Archive modified Web package' inputs: rootFolderOrFile: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\Web-unzip' includeRootFolder: false archiveFile: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\drop\Web-unzip.zip' replaceExistingArchive: true - task: IISWebAppDeploymentOnMachineGroup@0 displayName: 'IIS Web App Deploy' inputs: WebSiteName: '$(Parameters.WebsiteName)' Package: '$(System.DefaultWorkingDirectory)\_DevOpsTestProject-ASP.NET-CI\drop\Web-unzip.zip' TakeAppOfflineFlag: True XmlVariableSubstitution: true
Why You Saw "Deploy First, Then Cert Placement"
If your actual pipeline was deploying the original Web.zip before processing the cert, that would cause this behavior. The fixes above ensure all file modifications (including cert placement) happen before creating the deployment package, so everything gets deployed in one go.
Don't forget to enable replaceExistingArchive in the ArchiveFiles task — this prevents old versions of the package from being deployed by accident.
内容的提问来源于stack exchange,提问作者subsoft

