You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法在YAML/Azure PowerShell管道中切换活动订阅求助

如何在Azure DevOps YAML管道中切换活动订阅?

这是此前问题的续篇。

当前配置与问题

YAML管道配置

parameters:
- name: sub_name # name of the subscription; required
  type: string 
  default: false

steps:
  - script: echo "Here is subscription name:" ${{ parameters.sub_name }}
  - task: AzurePowerShell@5
    displayName: 'Launching Main.yml'
    inputs:
      azurePowerShellVersion: LatestVersion
      azureSubscription: My-SPN # 全能服务主体
      ScriptType: 'FilePath'
      ScriptPath: '$(System.DefaultWorkingDirectory)/MyPowerShell.ps1'
      ScriptArguments: -sub_name ${{ parameters.sub_name  }}

PowerShell脚本(MyPowerShell.ps1)

#param ($sub_name)
Get-AzContext -ListAvailable | Where{$_.Name -match $sub_name} | Set-AzContext
$SID=(Get-AzContext).Subscription.id
Write-Output "The active subscription SID is" $SID

问题现象

无论给$sub_name传入什么值,$SID始终输出服务主体"My-SPN"默认对应的订阅ID。脚本在Azure CLI中运行正常,但在YAML管道中无效。尝试使用Set-AzContext -Subscription $sub_name -TenantId 2a1c169e-715a-412b-b526-05da3f8412fa时,触发以下错误:

Starting: Launching Main.yml
Task : Azure PowerShell
Description : Run a PowerShell script within an Azure environment
Version : 5.209.0
Author : Microsoft Corporation

Generating script.
========================== Starting Command Output ===========================
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command ". 'D:\a_temp\adfb7562-7db5-4be6-ae08-dca4664e460c.ps1'"
Added TLS 1.2 in session.
Import-Module -Name C:\Modules\az_7.5.0\Az.Accounts\2.9.1\Az.Accounts.psd1 -Global
WARNING: Both Az and AzureRM modules were detected on this machine. Az and AzureRM modules cannot be imported in the
same session or used in the same script or runbook. If you are running PowerShell in an environment you control you can
use the 'Uninstall-AzureRm' cmdlet to remove all AzureRm modules from your machine. If you are running in Azure
Automation, take care that none of your runbooks import both Az and AzureRM modules.
Clear-AzContext -Scope CurrentUser -Force -ErrorAction SilentlyContinue
Clear-AzContext -Scope Process
Connect-AzAccount -ServicePrincipal -Tenant 2a1c169e-715a-412b-b526-05da3f8412fa -Credential System.Management.Automation.PSCredential -Environment AzureCloud @processScope
Set-AzContext -SubscriptionId 72245732-XXXXXXX -TenantId 2a1c169e-XXXXXXXX
##[error]Please provide a valid tenant or a valid subscription.
##[error]PowerShell exited with code '1'.

Added TLS 1.2 in session.
Finishing: Launching Main.yml

解决方案

1. 确认服务主体权限

首先确保服务主体"My-SPN"在目标订阅中拥有至少Reader级别的权限,否则无法切换到该订阅。

2. 修正脚本参数接收

脚本中注释掉了参数声明,导致$sub_name无法正确接收管道传入的值,取消注释:

param ($sub_name)

3. 直接指定订阅切换上下文

AzurePowerShell@5任务会自动清理现有上下文并重新连接服务主体,Get-AzContext -ListAvailable可能无法获取目标订阅,直接使用Set-AzContext指定订阅:

param ($sub_name)
# 直接通过订阅名称切换上下文,添加错误终止确保及时排查问题
Set-AzContext -Subscription $sub_name -ErrorAction Stop
$SID=(Get-AzContext).Subscription.Id
Write-Output "The active subscription SID is $SID"

4. 可选:改用订阅ID(更可靠)

若订阅名称存在重复或歧义,建议改用订阅ID作为参数:

  • 修改YAML参数:
parameters:
- name: sub_id # 订阅ID;必填
  type: string 

steps:
  - script: echo "Here is subscription ID:" ${{ parameters.sub_id }}
  - task: AzurePowerShell@5
    displayName: 'Launching Main.yml'
    inputs:
      azurePowerShellVersion: LatestVersion
      azureSubscription: My-SPN
      ScriptType: 'FilePath'
      ScriptPath: '$(System.DefaultWorkingDirectory)/MyPowerShell.ps1'
      ScriptArguments: -sub_id ${{ parameters.sub_id  }}
  • 对应修改PowerShell脚本:
param ($sub_id)
Set-AzContext -SubscriptionId $sub_id -ErrorAction Stop
$SID=(Get-AzContext).Subscription.Id
Write-Output "The active subscription SID is $SID"

5. 解决Az与AzureRM冲突

如果使用自托管代理,卸载AzureRM模块消除冲突:

Uninstall-AzureRm -Force -ErrorAction SilentlyContinue

如果是微软托管代理,可忽略警告,或在任务中指定较新的Az版本(如Az 9.0.0),新版本会自动处理模块冲突。


内容的提问来源于stack exchange,提问作者Iliko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 06:40:44