Mengelola variabel dalam grup variabel dengan Azure DevOps CLI

Layanan Azure DevOps | Azure DevOps Server

Mengelola variabel di Azure Pipelines sangat penting untuk menjaga fleksibilitas dan keamanan dalam alur kerja CI/CD Anda. Artikel ini memperlihatkan cara menggunakan Azure DevOps CLI untuk membuat dan mengelola variabel rahasia dan nonsecret dalam grup variabel Azure Pipelines. Dengan menggunakan grup variabel, Anda dapat mempusatkan manajemen variabel dan memastikan bahwa informasi sensitif ditangani dengan aman.

Dengan menggunakan sampel dalam artikel ini, Anda mempelajari cara:

  • Tentukan alur Azure Pipelines menggunakan file YAML yang disimpan di GitHub.
  • Buat grup variabel yang berisi variabel rahasia dan nonsecret.
  • Jalankan alur dengan menggunakan Azure DevOps CLI dan pantau pemrosesan dan output eksekusi.

Catatan

Sampel ini menunjukkan fungsionalitas Azure DevOps CLI dengan grup variabel. Untuk peningkatan keamanan, tentukan variabel dalam grup variabel di UI Alur Kerja atau hubungkan grup variabel ke rahasia di Azure Key Vault.

Prasyarat

Simpan file YAML alur

Simpan definisi alur YAML berikut sebagai file bernama azure-pipelines.yml di direktori akar dan main cabang repositori GitHub Anda.

parameters:
- name: image
  displayName: 'Pool image'
  default: ubuntu-latest
  values:
  - windows-latest
  - ubuntu-latest
  - macOS-latest
- name: test
  displayName: Run Tests?
  type: boolean
  default: false

variables:
- group: "Contoso Variable Group"
- name: va
  value: $[variables.a]
- name: vb
  value: $[variables.b]
- name: vcontososecret
  value: $[variables.contososecret]

trigger:
- main

pool:
  vmImage: ubuntu-latest

steps:
- script: |
    echo "Hello, world!"
    echo "Pool image: ${{ parameters.image }}"
    echo "Run tests? ${{ parameters.test }}"
  displayName: 'Show runtime parameter values'

- script: |
    echo "a=$(va)"
    echo "b=$(vb)"
    echo "contososecret=$(vcontososecret)"
    echo
    echo "Count up to the value of the variable group's nonsecret variable *a*:"
    for number in {1..$(va)}
    do
        echo "$number"
    done
    echo "Count up to the value of the variable group's nonsecret variable *b*:"
    for number in {1..$(vb)}
    do
        echo "$number"
    done
    echo "Count up to the value of the variable group's secret variable *contososecret*:"
    for number in {1..$(vcontososecret)}
    do
        echo "$number"
    done
  displayName: 'Test variable group variables (secret and nonsecret)'
  env:
    SYSTEM_ACCESSTOKEN: $(System.AccessToken)

Contoh skrip

Contoh skrip ini melakukan tugas-tugas berikut:

  • Membuat sumber daya DevOps
  • Menjalankan pipa
  • Memodifikasi nilai variabel tiga kali
  • Menjalankan alur lagi setiap kali nilai variabel berubah

Skrip membuat sumber daya berikut di Azure DevOps:

  • Proyek di organisasi DevOps Anda
  • Koneksi layanan GitHub
  • Sebuah alur
  • Grup variabel dengan dua variabel nonsecret dan satu variabel rahasia

Sebelum Anda menjalankan skrip, ganti placeholder berikut:

  • <devops-organization> Nama organisasi Azure DevOps Anda. Misalnya, jika URL Azure DevOps Anda adalah https://dev.azure.com/Contoso, gunakan Contoso.
  • <github-organization> Organisasi GitHub atau nama pengguna Anda. Misalnya, myusername atau myorganization.
  • <github-repository> Nama repositori GitHub Anda. Misalnya, jika URL repositori Anda adalah https://github.com/myusername/my-repo, gunakan my-repo.
  • <pipelinename> Nama untuk alur yang berjarak antara 3-19 karakter dan hanya berisi angka dan huruf kecil. Skrip menambahkan pengidentifikasi unik lima digit. Contohnya, mypipeline.

Simpan Pat GitHub Anda di lingkungan lokal Anda.

AZURE_DEVOPS_EXT_GITHUB_PAT=<your-github-pat>

Setelah menyimpan file YAML di GitHub, jalankan skrip Azure DevOps CLI berikut di shell Bash di Azure Cloud Shell atau secara lokal.

Penting

Pastikan Anda memiliki versi terbaru Azure CLI dan ekstensi DevOps yang terinstal. Jalankan az upgrade dan az extension add --name azure-devops sebelum menjalankan skrip ini.

#!/bin/bash

# ===== CONFIGURATION =====
# Replace the placeholder values with your own.
devopsOrg="https://dev.azure.com/<devops-organization>"
githubOrg="<github-organization>"
githubRepo="<github-repository>"
pipelineName="<pipeline-name>"
repoName="$githubOrg/$githubRepo"
repoType="github"
branch="main"

# Declare other variables.
uniqueId=$RANDOM
devopsProject="Contoso DevOps Project $uniqueId"
serviceConnectionName="Contoso Service Connection $uniqueId"
variableGroupName="Contoso Variable Group $uniqueId"

# ===== AUTHENTICATION =====
# Sign in to Azure CLI and follow the sign-in instructions, if necessary.
echo "Signing in to Azure CLI..."
az login

# Sign in to Azure DevOps with your Azure DevOps PAT, if necessary.
# Uncomment the following line if your Azure AD account doesn't have Azure DevOps access.
# echo "Signing in to Azure DevOps..."
# az devops login

# ===== PROJECT CREATION =====
# Create the Azure DevOps project and set defaults.
echo "Creating Azure DevOps project..."
projectId=$(az devops project create \
    --name "$devopsProject" \
    --organization "$devopsOrg" \
    --visibility private \
    --query id \
    --output tsv)
echo "Project created with ID: $projectId"

# Set default organization and project for subsequent commands.
az devops configure --defaults organization="$devopsOrg" project="$devopsProject"
pipelineRunUrlPrefix="$devopsOrg/$projectId/_build/results?buildId="

# ===== SERVICE CONNECTION =====
# Create GitHub service connection.
echo "Creating GitHub service connection..."
githubServiceEndpointId=$(az devops service-endpoint github create \
    --name "$serviceConnectionName" \
    --github-url "https://www.github.com/$repoName" \
    --query id \
    --output tsv)
echo "Service connection created with ID: $githubServiceEndpointId"

# ===== PIPELINE CREATION =====
# Create the pipeline from the YAML file.
echo "Creating pipeline..."
pipelineId=$(az pipelines create \
    --name "$pipelineName" \
    --skip-first-run \
    --repository $repoName \
    --repository-type $repoType \
    --branch $branch \
    --service-connection $githubServiceEndpointId \
    --yml-path azure-pipelines.yml \
    --query id \
    --output tsv)
echo "Pipeline created with ID: $pipelineId"

# ===== VARIABLE GROUP =====
# Create a variable group with 2 non-secret variables and 1 secret variable.
echo "Creating variable group..."
variableGroupId=$(az pipelines variable-group create \
    --name "$variableGroupName" \
    --authorize true \
    --variables a=12 b=29 \
    --query id \
    --output tsv)
echo "Variable group created with ID: $variableGroupId"

# Add a secret variable to the group.
echo "Adding secret variable to the group..."
az pipelines variable-group variable create \
    --group-id $variableGroupId \
    --name contososecret \
    --secret true \
    --value 17

# ===== PIPELINE RUNS =====
# Run the pipeline for the first time.
echo "Running pipeline (1st run)..."
pipelineRunId1=$(az pipelines run \
    --id $pipelineId \
    --query id \
    --output tsv)
echo "Pipeline run 1 started with ID: $pipelineRunId1"
echo "Go to the pipeline run's web page to view the output results of the 'Test variable group variables' job."
echo "URL: ${pipelineRunUrlPrefix}${pipelineRunId1}"
read -p "Press Enter to change the value of variable 'a', then run again:"

# Change the value of one of the variable group's nonsecret variables.
echo "Updating variable 'a'..."
az pipelines variable-group variable update \
    --group-id $variableGroupId \
    --name a \
    --value 22

# Run the pipeline for the second time.
echo "Running pipeline (2nd run)..."
pipelineRunId2=$(az pipelines run \
    --id $pipelineId \
    --query id \
    --output tsv)
echo "Pipeline run 2 started with ID: $pipelineRunId2"
echo "URL: ${pipelineRunUrlPrefix}${pipelineRunId2}"
read -p "Press Enter to change the value of the secret variable, then run once more:"

# Change the value of the variable group's secret variable.
echo "Updating secret variable 'contososecret'..."
az pipelines variable-group variable update \
    --group-id $variableGroupId \
    --name contososecret \
    --value 35

# Run the pipeline for the third time.
echo "Running pipeline (3rd run)..."
pipelineRunId3=$(az pipelines run \
    --id $pipelineId \
    --query id \
    --output tsv)
echo "Pipeline run 3 started with ID: $pipelineRunId3"
echo "URL: ${pipelineRunUrlPrefix}${pipelineRunId3}"
read -p "Press Enter to continue:"

Membersihkan sumber daya

Untuk menghindari dikenakan biaya untuk proyek Azure, hapus proyek sampel. Tindakan ini juga menghapus sumber dayanya.

id Salin proyek sampel dari output perintah berikut:

az devops project list --org <your-organization>

Hapus proyek dengan menjalankan perintah berikut:

az devops project delete --id <project-id> --org <your-organization> --yes

Bersihkan lingkungan lokal Anda dengan menjalankan perintah berikut:

export AZURE_DEVOPS_EXT_GITHUB_PAT=""
az devops configure --defaults organization="" project=""

Referensi Azure CLI

Sampel dalam artikel ini menggunakan perintah Azure CLI berikut: