Mur*_*oft 5 powershell build azure-active-directory azure-devops
我有一个VSTS项目,该项目通过服务主体通过Azure资源管理器终结点连接到Azure订阅。对于通过模板化,参数驱动的部署配置ARM资源的我的构建而言,这工作得很好。
作为构建的一部分,我还有其他要求设置Azure AD组。我有一个可以在本地计算机上正常运行的脚本。当我通过构建将其部署并在托管构建控制器上执行时,脚本最初无法找到AzureAD模块。我通过将脚本包含在git Repo中并通过以下方式对其进行访问来解决此问题:
$adModulePath = $PSScriptRoot + "\PsModules\AzureAD\2.0.0.131\AzureAD.psd1"
Import-Module $adModulePath
Run Code Online (Sandbox Code Playgroud)
但是,现在在运行时还有另一个问题New-AzureADGroup。该脚本需要Connect-AzureAD在发出命令之前运行。通过对凭证进行硬编码可以很好地实现此目的,但是我不想这样做,我希望它在创建的SPN的上下文中运行,该SPN在托管的构建控制器上运行脚本。
因此,问题是,是否可以获取Azure PowerShell执行SPN的当前上下文并将其传递,Connect-AzureAD以避免将凭据存储为纯文本?我错过了一个把戏吗?还有其他选择吗?
我当前的代码如下,注释的连接在命令中可以像硬编码值一样正常工作。没有参数的调用将显示登录UI,该UI终止构建,因为它显然不是交互式的。
## Login to Azure
#$SecurePassword = ConvertTo-SecureString $AdminPassword -AsPlainText -Force
#$AdminCredential = New-Object System.Management.Automation.PSCredential ($AdminUserEmailAddress, $SecurePassword)
#Connect-AzureAD -Credential $AdminCredential
Connect-AzureAD
Write-Output "------------------ Start: Group Creation ------------------"
$TestForAdminGroup = Get-AzureADGroup -SearchString $AdminGroup
$TestForContributorGroup = Get-AzureADGroup -SearchString $ContributorGroup
$TestForReaderGroup = Get-AzureADGroup -SearchString $ReaderGroup
Run Code Online (Sandbox Code Playgroud)
谢谢
这个有可能。今天就可以为我自己发布的VSTS扩展程序工作了。我的扩展程序使用a Azure Resource Manager endpoint作为输入。
现在,使用以下代码在Microsoft Hosted Visual Studio 2017代理池上运行它。有关更多信息,请参见有关如何在VSTS代理上使用AzureAD PowerShell cmdlet的信息。
Write-Verbose "Import AzureAD module because is not on default VSTS agent"
$azureAdModulePath = $PSScriptRoot + "\AzureAD\2.0.1.16\AzureAD.psd1"
Import-Module $azureAdModulePath
# Workaround to use AzureAD in this task. Get an access token and call Connect-AzureAD
$serviceNameInput = Get-VstsInput -Name ConnectedServiceNameSelector -Require
$serviceName = Get-VstsInput -Name $serviceNameInput -Require
$endPointRM = Get-VstsEndpoint -Name $serviceName -Require
$clientId = $endPointRM.Auth.Parameters.ServicePrincipalId
$clientSecret = $endPointRM.Auth.Parameters.ServicePrincipalKey
$tenantId = $endPointRM.Auth.Parameters.TenantId
$adTokenUrl = "https://login.microsoftonline.com/$tenantId/oauth2/token"
$resource = "https://graph.windows.net/"
$body = @{
grant_type = "client_credentials"
client_id = $clientId
client_secret = $clientSecret
resource = $resource
}
$response = Invoke-RestMethod -Method 'Post' -Uri $adTokenUrl -ContentType "application/x-www-form-urlencoded" -Body $body
$token = $response.access_token
Write-Verbose "Login to AzureAD with same application as endpoint"
Connect-AzureAD -AadAccessToken $token -AccountId $clientId -TenantId $tenantId
Run Code Online (Sandbox Code Playgroud)
| 归档时间: |
|
| 查看次数: |
2327 次 |
| 最近记录: |