You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps YAML流水线变量无法传递至所有阶段问题

Azure DevOps YAML流水线跨阶段传递Auth0密钥异常问题

我搭建了一条基于Terraform的Azure DevOps YAML流水线,用于部署Auth0配置。流水线在Preparation初始化阶段从Azure KeyVault中获取密钥,代码如下:

stages:
- stage: Preparation
  displayName: Preparation
  jobs:
    - job: FetchSecrets
      displayName: Fetch Auth0 secrets from Azure Key Vault
      steps:
        - checkout: none
        - task: AzureCLI@2
          name: FetchSecretsfromKeyVault
          displayName: FetchSecretsfromKeyVault
          inputs:
            azureSubscription: "$(AZURE_SERVICE_CONNECTION)"
            scriptType: bash
            scriptLocation: inlineScript
            inlineScript: |
              echo "Fetching Auth0 secrets..."

              CLIENT_ID=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-ID" --query value -o tsv)
              CLIENT_SECRET=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-SECRET" --query value -o tsv)

              echo "Auth0 Client ID: ${CLIENT_ID}"
              echo "Auth0 Client Secret: ${CLIENT_SECRET:0:4}******* (truncated)"

              echo "##vso[task.setvariable variable=auth0_client_id;issecret=true;isOutput=true]$CLIENT_ID"
              echo "##vso[task.setvariable variable=auth0_client_secret;issecret=true;isOutput=true]$CLIENT_SECRET"

我通过以下方式在其他阶段引用这些输出变量:

- stage: Plan_Base
  displayName: Terraform Plan - Base resources
  dependsOn: Preparation
  jobs:
    - job: Plan_Base
      variables:
        auth0_client_id: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_id'] ]
        auth0_client_secret: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_secret'] ]
      steps:
          ...

这种方式在Preparation之后的首个阶段Plan_Base中有效,但后续的Apply_Base和Associations阶段无法正常获取变量(已添加打印步骤验证值)。流水线完整阶段结构如下:

stages:
  - stage: Preparation
    displayName: Preparation
    jobs:
      - job: FetchSecrets
        displayName: Fetch Auth0 secrets from Azure Key Vault
        steps:
          - checkout: none
          - task: AzureCLI@2
            name: FetchSecretsfromKeyVault
            displayName: FetchSecretsfromKeyVault
            inputs:
              azureSubscription: "$(AZURE_SERVICE_CONNECTION)"
              scriptType: bash
              scriptLocation: inlineScript
              inlineScript: |
                echo "Fetching Auth0 secrets..."

                CLIENT_ID=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-ID" --query value -o tsv)
                CLIENT_SECRET=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-SECRET" --query value -o tsv)

                echo "Auth0 Client ID: ${CLIENT_ID}"
                echo "Auth0 Client Secret: ${CLIENT_SECRET:0:4}******* (truncated)"

                echo "##vso[task.setvariable variable=auth0_client_id;issecret=true;isOutput=true]$CLIENT_ID"
                echo "##vso[task.setvariable variable=auth0_client_secret;issecret=true;isOutput=true]$CLIENT_SECRET"

  # ----------------------
  # Plan & Apply Base
  # ----------------------
  - stage: Plan_Base
    displayName: Terraform Plan - Base resources
    dependsOn: Preparation
    jobs:
      - job: Plan_Base
        variables:
          auth0_client_id: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_id'] ]
          auth0_client_secret: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_secret'] ]
        steps:
          - checkout: self

          # Print credentials
          - script: |
              echo "Auth0 Client ID: $(auth0_client_id)"
              echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******"
            displayName: Print Auth0 credentials

          - task: TerraformTaskV4@4
            displayName: Terraform Init
            inputs:
              provider: "azurerm"
              command: "init"
              backendServiceArm: "$(AZURE_SERVICE_CONNECTION)"
              backendAzureRmResourceGroupName: "$(AZURE_RESOURCE_GROUP_NAME)"
              backendAzureRmStorageAccountName: "$(AZURE_STORAGE_ACCOUNT_NAME)"
              backendAzureRmContainerName: "tfstate"
              backendAzureRmKey: "$(AZURE_PROJECT_NAME)-$(environment).tfstate"
              workingDirectory: "$(rootFolder)/$(environment)"

          - task: TerraformTaskV4@4
            displayName: Terraform Plan (Base)
            inputs:
              provider: "azurerm"
              command: "plan"
              environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)"
              workingDirectory: "$(rootFolder)/$(environment)"
              commandOptions: >
                -input=false
                -out=tfplan-base
                -target=module.auth0_base.module.auth0_tenant
                -target=module.auth0_base.module.auth0_ui
                -target=module.auth0_base.module.auth0_database
                -target=module.auth0_base.module.auth0_apps
                -target=module.auth0_base.module.auth0_actions
                -target=module.auth0_base.module.auth0_roles
                -target=module.auth0_base.module.app_m2m_actions
            env:
              TF_VAR_auth0_domain: $(AUTH0_DOMAIN)
              TF_VAR_auth0_client_id: $(auth0_client_id)
              TF_VAR_auth0_client_secret: $(auth0_client_secret)
              TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID)
              TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME)
              TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME)
              TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME)

          - task: PublishPipelineArtifact@1
            displayName: "Upload Base Plan"
            inputs:
              targetPath: "$(rootFolder)/$(environment)/tfplan-base"
              artifact: "terraform-plan-base"

  - stage: Validate_Base
    displayName: Manual Validation - Base
    dependsOn: Plan_Base
    condition: succeeded()
    jobs:
      - job: waitForValidation
        pool: server
        condition: ne('${{ parameters.targetEnv }}', 'dev')
        steps:
          - task: ManualValidation@0
            timeoutInMinutes: 600
            inputs:
              instructions: "Validate and approve to apply base resources (connections & apps)."
              onTimeout: "reject"

  - stage: Apply_Base
    displayName: Terraform Apply - Base
    dependsOn: Validate_Base
    condition: |
      and(
        succeeded(),
        or(
          ne(variables['environment'], 'production'),
          and(
            eq(variables['environment'], 'production'),
            eq(variables['Build.SourceBranchName'], 'main')
          )
        )
      )
    jobs:
      - deployment: Apply_Base
        environment: "$(environment)"
        variables:
          auth0_client_id: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_id'] ]
          auth0_client_secret: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_secret'] ]
        strategy:
          runOnce:
            deploy:

              steps:
                - checkout: self

                - script: |
                    echo "Auth0 Client ID: $(auth0_client_id)"
                    echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******"
                  displayName: Print Auth0 credentials

                - task: DownloadPipelineArtifact@2
                  displayName: Download Base Plan
                  inputs:
                    artifact: "terraform-plan-base"
                    path: "$(rootFolder)/$(environment)"

                - task: TerraformTaskV4@4
                  displayName: Terraform Init for Apply (Base)
                  inputs:
                    provider: "azurerm"
                    command: "init"
                    backendServiceArm: "$(AZURE_SERVICE_CONNECTION)"
                    backendAzureRmResourceGroupName: "$(AZURE_RESOURCE_GROUP_NAME)"
                    backendAzureRmStorageAccountName: "$(AZURE_STORAGE_ACCOUNT_NAME)"
                    backendAzureRmContainerName: "tfstate"
                    backendAzureRmKey: "$(AZURE_PROJECT_NAME)-$(environment).tfstate"
                    workingDirectory: "$(rootFolder)/$(environment)"

                - task: TerraformTaskV4@4
                  displayName: Terraform Apply (Base)
                  inputs:
                    provider: "azurerm"
                    command: "apply"
                    environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)"
                    workingDirectory: "$(rootFolder)/$(environment)"
                    commandOptions: >
                      -input=false
                      tfplan-base
                  env:
                    TF_VAR_auth0_domain: $(AUTH0_DOMAIN)
                    TF_VAR_auth0_client_id: $(auth0_client_id)
                    TF_VAR_auth0_client_secret: $(auth0_client_secret)
                    TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID)
                    TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME)
                    TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME)
                    TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME)

  # ----------------------
  # Plan & Apply Associations
  # ----------------------
  - stage: Associations
    displayName: Terraform Plan & Apply - Associations
    dependsOn: Apply_Base
    condition: succeeded()
    jobs:
      - job: Associations
        displayName: Plan & Apply Associations
        variables:
          auth0_client_id: $[ dependencies.FetchSecretsAgain.outputs['FetchSecretsAssoc.auth0_client_id'] ]
          auth0_client_secret: $[ dependencies.FetchSecretsAgain.outputs['FetchSecretsAssoc.auth0_client_secret'] ]
        steps:
          - checkout: self

          - script: |
              echo "Auth0 Client ID: $(auth0_client_id)"
              echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******"
            displayName: Print Auth0 credentials

          - task: TerraformTaskV4@4
            displayName: Terraform Init (Associations)
            inputs:
              provider: "azurerm"
              command: "init"
              backendServiceArm: "$(AZURE_SERVICE_CONNECTION)"
              backendAzureRmResourceGroupName: "$(AZURE_RESOURCE_GROUP_NAME)"
              backendAzureRmStorageAccountName: "$(AZURE_STORAGE_ACCOUNT_NAME)"
              backendAzureRmContainerName: "tfstate"
              backendAzureRmKey: "$(AZURE_PROJECT_NAME)-$(environment).tfstate"
              workingDirectory: "$(rootFolder)/$(environment)"

          - task: TerraformTaskV4@4
            displayName: Terraform Plan (Associations)
            inputs:
              provider: "azurerm"
              command: "plan"
              environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)"
              workingDirectory: "$(rootFolder)/$(environment)"
              commandOptions: > 
                -input=false
                -refresh=false
                -out=tfplan-assoc
                -target=module.auth0_base.module.auth0_database
                -target=module.auth0_base.module.auth0_apps
                -target=module.auth0_base.module.auth0_apps_associations
            env:
              TF_VAR_auth0_domain: $(AUTH0_DOMAIN)
              TF_VAR_auth0_client_id: $(auth0_client_id)
              TF_VAR_auth0_client_secret: $(auth0_client_secret)
              TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID)
              TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME)
              TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME)
              TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME)

          - script: |
              echo "Auth0 Client ID: $(auth0_client_id)"
              echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******"
            displayName: Print Auth0 credentials again

          - task: TerraformTaskV4@4
            displayName: Terraform Apply (Associations)
            inputs:
              provider: "azurerm"
              command: "apply"
              environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)"
              workingDirectory: "$(rootFolder)/$(environment)"
              commandOptions: >
                -input=false
                tfplan-assoc
            env:
              TF_VAR_auth0_domain: $(AUTH0_DOMAIN)
              TF_VAR_auth0_client_id: $(auth0_client_id)
              TF_VAR_auth0_client_secret: $(auth0_client_secret)
              TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID)
              TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME)
              TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME)
              TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME)

各阶段运行情况总结

  • Preparation阶段:成功从KeyVault获取密钥
  • Plan_Base阶段:可正常接收变量
  • Apply_Base阶段:无法接收变量(预期可接收)
  • Associations阶段:无法接收变量(预期可接收)

内容的提问来源于stack exchange,提问作者Hekmil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 17:30:53