You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipeline用task.setvariable创建变量失败,无法配置Key Vault访问策略

问题排查及解决方法

错误原因

  • 错误1:跨任务变量未声明为输出变量
    你通过##vso[task.setvariable]设置的变量默认作用域仅为当前任务,后续任务无法直接读取。如果需要跨任务传递,必须在设置变量时添加isOutput=true标记,同时给生成变量的任务配置名称,后续任务引用时需要加上任务名前缀。
  • 错误2:拼写错误 + shell变量调用语法误用
    你在同一个脚本内定义了shell变量identity,调用时犯了两个问题:
    1. 拼写错误:变量名是identity,你写成了indentity
    2. 语法错误:同一个bash脚本内调用shell变量直接用$identity即可,你用的$(indentity)是bash的命令替换语法,会被识别为要执行名为indentity的命令,所以抛出command not found报错,最终--object-id参数没有拿到有效值。

解决方案

方案1:合并任务(最简单,无需跨任务传参)

将创建Key Vault和配置访问策略的逻辑合并到第一个AzureCLI任务中,直接使用shell变量identity即可,示例代码:

- task: AzureCLI@2
  displayName: 'Create and configure web app + key vault'
  inputs:
    azureSubscription: '$(serviceConnector)'
    scriptLocation: 'inlineScript'
    scriptType: 'bash'
    failOnStandardError: false
    inlineScript: |
      echo ">>>> Create app service plan"
      az appservice plan create \
        --name $(appPlan) \
        --resource-group $(appResourceGroupName) \
        --location $(location) \
        --sku $(planSkuName) \
        --is-linux 2>/dev/null

      # create web app
      echo ">>>> Create web app"
      az webapp create \
        --resource-group $(appResourceGroupName) \
        --name $(appName) \
        --runtime "Python|3.7" \
        --plan $(appPlan) 
      
      # enable managed identity
      echo ">>>> Enable managed identity"
      identity=`az webapp identity assign \
        --name $(appName) \
        --resource-group $(appResourceGroupName) \
        --query principalId -o tsv`
      echo ">>>> Managed identity ID: $identity"

      echo ">>>> Create key vault"
      az keyvault create \
        --name $(keyVaultName) \
        --resource-group $(appResourceGroupName) \
        --location $(location) \
        --no-self-perms \
        --sku standard \
        --enable-soft-delete true \
        2>&1

      # add set policy for managed service identities
      echo ">>>> Add set policy for function app"
      az keyvault set-policy \
        --name $(keyVaultName) \
        --secret-permissions get \
        --object-id $identity

方案2:保留多任务,配置输出变量

如果你需要拆分任务,修改如下:

  1. 给第一个AzureCLI任务添加名称,设置变量时加isOutput=true
- task: AzureCLI@2
  name: configureWebApp # 新增任务名称
  displayName: 'Create and configure web app'
  inputs:
    azureSubscription: '$(serviceConnector)'
    scriptLocation: 'inlineScript'
    scriptType: 'bash'
    failOnStandardError: false
    inlineScript: |
      # 其余原有逻辑不变
      identity=`az webapp identity assign \
        --name $(appName) \
        --resource-group $(appResourceGroupName) \
        --query principalId -o tsv`
      # 新增isOutput=true标记
      echo "##vso[task.setvariable variable=WEB_APP_MANAGED_IDENTITY;isOutput=true]$identity"
  1. 后续任务引用变量时加上任务名前缀:
az keyvault set-policy \
  --name $(keyVaultName) \
  --secret-permissions get \
  --object-id $(configureWebApp.WEB_APP_MANAGED_IDENTITY)

内容的提问来源于stack exchange,提问作者Jaana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 00:45:03