Azure DevOps YAML流水线变量无法传递至所有阶段问题
Azure DevOps YAML流水线跨阶段传递Auth0密钥异常问题
我搭建了一条基于Terraform的Azure DevOps YAML流水线,用于部署Auth0配置。流水线在Preparation初始化阶段从Azure KeyVault中获取密钥,代码如下:
stages: - stage: Preparation displayName: Preparation jobs: - job: FetchSecrets displayName: Fetch Auth0 secrets from Azure Key Vault steps: - checkout: none - task: AzureCLI@2 name: FetchSecretsfromKeyVault displayName: FetchSecretsfromKeyVault inputs: azureSubscription: "$(AZURE_SERVICE_CONNECTION)" scriptType: bash scriptLocation: inlineScript inlineScript: | echo "Fetching Auth0 secrets..." CLIENT_ID=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-ID" --query value -o tsv) CLIENT_SECRET=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-SECRET" --query value -o tsv) echo "Auth0 Client ID: ${CLIENT_ID}" echo "Auth0 Client Secret: ${CLIENT_SECRET:0:4}******* (truncated)" echo "##vso[task.setvariable variable=auth0_client_id;issecret=true;isOutput=true]$CLIENT_ID" echo "##vso[task.setvariable variable=auth0_client_secret;issecret=true;isOutput=true]$CLIENT_SECRET"
我通过以下方式在其他阶段引用这些输出变量:
- stage: Plan_Base displayName: Terraform Plan - Base resources dependsOn: Preparation jobs: - job: Plan_Base variables: auth0_client_id: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_id'] ] auth0_client_secret: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_secret'] ] steps: ...
这种方式在Preparation之后的首个阶段Plan_Base中有效,但后续的Apply_Base和Associations阶段无法正常获取变量(已添加打印步骤验证值)。流水线完整阶段结构如下:
stages: - stage: Preparation displayName: Preparation jobs: - job: FetchSecrets displayName: Fetch Auth0 secrets from Azure Key Vault steps: - checkout: none - task: AzureCLI@2 name: FetchSecretsfromKeyVault displayName: FetchSecretsfromKeyVault inputs: azureSubscription: "$(AZURE_SERVICE_CONNECTION)" scriptType: bash scriptLocation: inlineScript inlineScript: | echo "Fetching Auth0 secrets..." CLIENT_ID=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-ID" --query value -o tsv) CLIENT_SECRET=$(az keyvault secret show --vault-name "kv-okta-auth0" --name "AUTH0-CLIENT-SECRET" --query value -o tsv) echo "Auth0 Client ID: ${CLIENT_ID}" echo "Auth0 Client Secret: ${CLIENT_SECRET:0:4}******* (truncated)" echo "##vso[task.setvariable variable=auth0_client_id;issecret=true;isOutput=true]$CLIENT_ID" echo "##vso[task.setvariable variable=auth0_client_secret;issecret=true;isOutput=true]$CLIENT_SECRET" # ---------------------- # Plan & Apply Base # ---------------------- - stage: Plan_Base displayName: Terraform Plan - Base resources dependsOn: Preparation jobs: - job: Plan_Base variables: auth0_client_id: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_id'] ] auth0_client_secret: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_secret'] ] steps: - checkout: self # Print credentials - script: | echo "Auth0 Client ID: $(auth0_client_id)" echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******" displayName: Print Auth0 credentials - task: TerraformTaskV4@4 displayName: Terraform Init inputs: provider: "azurerm" command: "init" backendServiceArm: "$(AZURE_SERVICE_CONNECTION)" backendAzureRmResourceGroupName: "$(AZURE_RESOURCE_GROUP_NAME)" backendAzureRmStorageAccountName: "$(AZURE_STORAGE_ACCOUNT_NAME)" backendAzureRmContainerName: "tfstate" backendAzureRmKey: "$(AZURE_PROJECT_NAME)-$(environment).tfstate" workingDirectory: "$(rootFolder)/$(environment)" - task: TerraformTaskV4@4 displayName: Terraform Plan (Base) inputs: provider: "azurerm" command: "plan" environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)" workingDirectory: "$(rootFolder)/$(environment)" commandOptions: > -input=false -out=tfplan-base -target=module.auth0_base.module.auth0_tenant -target=module.auth0_base.module.auth0_ui -target=module.auth0_base.module.auth0_database -target=module.auth0_base.module.auth0_apps -target=module.auth0_base.module.auth0_actions -target=module.auth0_base.module.auth0_roles -target=module.auth0_base.module.app_m2m_actions env: TF_VAR_auth0_domain: $(AUTH0_DOMAIN) TF_VAR_auth0_client_id: $(auth0_client_id) TF_VAR_auth0_client_secret: $(auth0_client_secret) TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID) TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME) TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME) TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME) - task: PublishPipelineArtifact@1 displayName: "Upload Base Plan" inputs: targetPath: "$(rootFolder)/$(environment)/tfplan-base" artifact: "terraform-plan-base" - stage: Validate_Base displayName: Manual Validation - Base dependsOn: Plan_Base condition: succeeded() jobs: - job: waitForValidation pool: server condition: ne('${{ parameters.targetEnv }}', 'dev') steps: - task: ManualValidation@0 timeoutInMinutes: 600 inputs: instructions: "Validate and approve to apply base resources (connections & apps)." onTimeout: "reject" - stage: Apply_Base displayName: Terraform Apply - Base dependsOn: Validate_Base condition: | and( succeeded(), or( ne(variables['environment'], 'production'), and( eq(variables['environment'], 'production'), eq(variables['Build.SourceBranchName'], 'main') ) ) ) jobs: - deployment: Apply_Base environment: "$(environment)" variables: auth0_client_id: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_id'] ] auth0_client_secret: $[ stageDependencies.Preparation.FetchSecrets.outputs['FetchSecretsfromKeyVault.auth0_client_secret'] ] strategy: runOnce: deploy: steps: - checkout: self - script: | echo "Auth0 Client ID: $(auth0_client_id)" echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******" displayName: Print Auth0 credentials - task: DownloadPipelineArtifact@2 displayName: Download Base Plan inputs: artifact: "terraform-plan-base" path: "$(rootFolder)/$(environment)" - task: TerraformTaskV4@4 displayName: Terraform Init for Apply (Base) inputs: provider: "azurerm" command: "init" backendServiceArm: "$(AZURE_SERVICE_CONNECTION)" backendAzureRmResourceGroupName: "$(AZURE_RESOURCE_GROUP_NAME)" backendAzureRmStorageAccountName: "$(AZURE_STORAGE_ACCOUNT_NAME)" backendAzureRmContainerName: "tfstate" backendAzureRmKey: "$(AZURE_PROJECT_NAME)-$(environment).tfstate" workingDirectory: "$(rootFolder)/$(environment)" - task: TerraformTaskV4@4 displayName: Terraform Apply (Base) inputs: provider: "azurerm" command: "apply" environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)" workingDirectory: "$(rootFolder)/$(environment)" commandOptions: > -input=false tfplan-base env: TF_VAR_auth0_domain: $(AUTH0_DOMAIN) TF_VAR_auth0_client_id: $(auth0_client_id) TF_VAR_auth0_client_secret: $(auth0_client_secret) TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID) TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME) TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME) TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME) # ---------------------- # Plan & Apply Associations # ---------------------- - stage: Associations displayName: Terraform Plan & Apply - Associations dependsOn: Apply_Base condition: succeeded() jobs: - job: Associations displayName: Plan & Apply Associations variables: auth0_client_id: $[ dependencies.FetchSecretsAgain.outputs['FetchSecretsAssoc.auth0_client_id'] ] auth0_client_secret: $[ dependencies.FetchSecretsAgain.outputs['FetchSecretsAssoc.auth0_client_secret'] ] steps: - checkout: self - script: | echo "Auth0 Client ID: $(auth0_client_id)" echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******" displayName: Print Auth0 credentials - task: TerraformTaskV4@4 displayName: Terraform Init (Associations) inputs: provider: "azurerm" command: "init" backendServiceArm: "$(AZURE_SERVICE_CONNECTION)" backendAzureRmResourceGroupName: "$(AZURE_RESOURCE_GROUP_NAME)" backendAzureRmStorageAccountName: "$(AZURE_STORAGE_ACCOUNT_NAME)" backendAzureRmContainerName: "tfstate" backendAzureRmKey: "$(AZURE_PROJECT_NAME)-$(environment).tfstate" workingDirectory: "$(rootFolder)/$(environment)" - task: TerraformTaskV4@4 displayName: Terraform Plan (Associations) inputs: provider: "azurerm" command: "plan" environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)" workingDirectory: "$(rootFolder)/$(environment)" commandOptions: > -input=false -refresh=false -out=tfplan-assoc -target=module.auth0_base.module.auth0_database -target=module.auth0_base.module.auth0_apps -target=module.auth0_base.module.auth0_apps_associations env: TF_VAR_auth0_domain: $(AUTH0_DOMAIN) TF_VAR_auth0_client_id: $(auth0_client_id) TF_VAR_auth0_client_secret: $(auth0_client_secret) TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID) TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME) TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME) TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME) - script: | echo "Auth0 Client ID: $(auth0_client_id)" echo "Auth0 Client Secret (truncated): ${auth0_client_secret:0:4}*******" displayName: Print Auth0 credentials again - task: TerraformTaskV4@4 displayName: Terraform Apply (Associations) inputs: provider: "azurerm" command: "apply" environmentServiceNameAzureRM: "$(AZURE_SERVICE_CONNECTION)" workingDirectory: "$(rootFolder)/$(environment)" commandOptions: > -input=false tfplan-assoc env: TF_VAR_auth0_domain: $(AUTH0_DOMAIN) TF_VAR_auth0_client_id: $(auth0_client_id) TF_VAR_auth0_client_secret: $(auth0_client_secret) TF_VAR_azure_tenant_id: $(AZURE_TENANT_ID) TF_VAR_azure_resource_group_name: $(AZURE_RESOURCE_GROUP_NAME) TF_VAR_azure_storage_account_name: $(AZURE_STORAGE_ACCOUNT_NAME) TF_VAR_azure_project_name: $(AZURE_PROJECT_NAME)
各阶段运行情况总结
- Preparation阶段:成功从KeyVault获取密钥
- Plan_Base阶段:可正常接收变量
- Apply_Base阶段:无法接收变量(预期可接收)
- Associations阶段:无法接收变量(预期可接收)
内容的提问来源于stack exchange,提问作者Hekmil
相关产品推荐
相关产品推荐

