VSTS Build和PowerShell和AzureAD身份验证

Mur*_*oft 5 powershell build azure-active-directory azure-devops

我有一个VSTS项目,该项目通过服务主体通过Azure资源管理器终结点连接到Azure订阅。对于通过模板化,参数驱动的部署配置ARM资源的我的构建而言,这工作得很好。

作为构建的一部分,我还有其他要求设置Azure AD组。我有一个可以在本地计算机上正常运行的脚本。当我通过构建将其部署并在托管构建控制器上执行时,脚本最初无法找到AzureAD模块。我通过将脚本包含在git Repo中并通过以下方式对其进行访问来解决此问题:

$adModulePath = $PSScriptRoot + "\PsModules\AzureAD\2.0.0.131\AzureAD.psd1"
Import-Module $adModulePath 
Run Code Online (Sandbox Code Playgroud)

但是,现在在运行时还有另一个问题New-AzureADGroup。该脚本需要Connect-AzureAD在发出命令之前运行。通过对凭证进行硬编码可以很好地实现此目的,但是我不想这样做,我希望它在创建的SPN的上下文中运行,该SPN在托管的构建控制器上运行脚本。

因此,问题是,是否可以获取Azure PowerShell执行SPN的当前上下文并将其传递,Connect-AzureAD以避免将凭据存储为纯文本?我错过了一个把戏吗?还有其他选择吗?

我当前的代码如下,注释的连接在命令中可以像硬编码值一样正常工作。没有参数的调用将显示登录UI,该UI终止构建,因为它显然不是交互式的。

## Login to Azure
#$SecurePassword = ConvertTo-SecureString $AdminPassword -AsPlainText -Force
#$AdminCredential = New-Object System.Management.Automation.PSCredential ($AdminUserEmailAddress, $SecurePassword)
#Connect-AzureAD -Credential $AdminCredential

Connect-AzureAD

Write-Output "------------------ Start: Group Creation ------------------"

$TestForAdminGroup = Get-AzureADGroup -SearchString $AdminGroup
$TestForContributorGroup = Get-AzureADGroup -SearchString $ContributorGroup
$TestForReaderGroup = Get-AzureADGroup -SearchString $ReaderGroup
Run Code Online (Sandbox Code Playgroud)

谢谢

Ral*_*sen 8

这个有可能。今天就可以为我自己发布的VSTS扩展程序工作了。我的扩展程序使用a Azure Resource Manager endpoint作为输入。

现在,使用以下代码在Microsoft Hosted Visual Studio 2017代理池上运行它。有关更多信息,请参见有关如何在VSTS代理上使用AzureAD PowerShell cmdlet的信息。

Write-Verbose "Import AzureAD module because is not on default VSTS agent"
$azureAdModulePath = $PSScriptRoot + "\AzureAD\2.0.1.16\AzureAD.psd1"
Import-Module $azureAdModulePath 

# Workaround to use AzureAD in this task. Get an access token and call Connect-AzureAD
$serviceNameInput = Get-VstsInput -Name ConnectedServiceNameSelector -Require
$serviceName = Get-VstsInput -Name $serviceNameInput -Require
$endPointRM = Get-VstsEndpoint -Name $serviceName -Require

$clientId = $endPointRM.Auth.Parameters.ServicePrincipalId
$clientSecret = $endPointRM.Auth.Parameters.ServicePrincipalKey
$tenantId = $endPointRM.Auth.Parameters.TenantId

$adTokenUrl = "https://login.microsoftonline.com/$tenantId/oauth2/token"
$resource = "https://graph.windows.net/"

$body = @{
    grant_type    = "client_credentials"
    client_id     = $clientId
    client_secret = $clientSecret
    resource      = $resource
}

$response = Invoke-RestMethod -Method 'Post' -Uri $adTokenUrl -ContentType "application/x-www-form-urlencoded" -Body $body
$token = $response.access_token

Write-Verbose "Login to AzureAD with same application as endpoint"
Connect-AzureAD -AadAccessToken $token -AccountId $clientId -TenantId $tenantId
Run Code Online (Sandbox Code Playgroud)

  • 上面的代码只能在Azure DevOps扩展内部运行。如果要通过Azure Powershell任务执行相同的操作,请参见/sf/ask/2926267151/ (2认同)