Azure Pipeline访问第二仓库报fatal: could not read Username错误如何解决
问题根因说明
- 勾选「不同步来源」时,流水线默认不会拉取作为
self的Pipelines仓库,所以你存放在这个仓库里的awesome_stuff.ps1自然不存在 - 同步来源时,
persistCredentials: true仅会把流水线的身份凭证注入到默认拉取的self仓库的Git配置里,你调用git ls-remote访问Source仓库时没有用到这个凭证,所以触发鉴权失败
具体修复步骤
第一步:显式配置多仓库checkout
不要只拉取self仓库,直接在YAML头部声明两个仓库的拉取规则,避免文件路径互相覆盖:
resources: repositories: - repository: SourceRepo # 给Source仓库定义别名 type: git name: 你的项目名/Source仓库实际名称 # 替换为Source仓库的真实路径 ref: ${{ variables.BRANCH }} # 可替换为你实际使用的分支变量 steps: # 拉取Pipelines仓库(self),指定独立存放目录 - checkout: self path: s/Pipelines persistCredentials: true # 拉取Source仓库,指定独立存放目录 - checkout: SourceRepo path: s/Source
第二步:调整PowerShell脚本逻辑
有两种方案可选,优先推荐第一种:
方案1:使用系统预定义变量跳过手动Git请求
直接用流水线内置变量获取Source仓库的commit哈希,完全避开手动调用git ls-remote的鉴权问题:
- powershell: | # 直接调用系统预定义的Source仓库commit哈希变量 $commit = $(Build.SourceVersion) # 调整脚本路径为Pipelines仓库的实际拉取路径 . "$(Agent.BuildDirectory)/s/Pipelines/PowerShell/awesome_stuff.ps1" Start-Awesome -WorkingDirectory $(Agent.BuildDirectory) -CloningDirectory "$(Agent.BuildDirectory)/s/Source" -BranchName $ENV:BRANCH -RepositryUrl $ENV:REPOURL -Commit $commit errorActionPreference: continue displayName: "Run Awesome"
方案2:手动注入凭证执行Git请求
如果业务场景必须调用git ls-remote,可以把流水线OAuth令牌注入到Git请求Header中解决鉴权问题,注意先开启流水线作业设置里的「允许脚本访问OAuth令牌」开关:
- powershell: | $encodedPat = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes(":$(System.AccessToken)")) $gitHeader = "Authorization: Basic $encodedPat" $commit = git -c http.extraHeader="$gitHeader" ls-remote $ENV:REPOURL $ENV:BRANCH . "$(Agent.BuildDirectory)/s/Pipelines/PowerShell/awesome_stuff.ps1" Start-Awesome -WorkingDirectory $(Agent.BuildDirectory) -CloningDirectory "$(Agent.BuildDirectory)/s/Source" -BranchName $ENV:BRANCH -RepositryUrl $ENV:REPOURL -Commit $commit errorActionPreference: continue displayName: "Run Awesome"
验证说明
配置完成后不需要再勾选「不同步来源」,直接运行流水线即可:
- Pipelines仓库的脚本会正常拉取到指定路径,可正常引用执行
- Source仓库的代码会拉取到对应目录,不会触发鉴权报错
内容的提问来源于stack exchange,提问作者B.McKee
相关产品推荐
相关产品推荐

