DevOps Pipeline AzureCLI@2 with dynamic azureSubscription

Viewed 1089

I have a DevOps pipeline that gives me this error:

There was a resource authorization issue: "The pipeline is not valid. Job ExecutionTerraform: Step AzureCLI input connectedServiceNameARM references service connection Azure: $(subscriptionName) which could not be found. The service connection does not exist or has not been authorized for use. For authorization details, refer to https://aka.ms/yamlauthz."

The configuration I am using is looking up the Subscription name dynamically.

The step I use for that is:

- bash: |
    # pull the subscription data
    # ... read data into local variables

    # set the shared variables
    echo "##vso[task.setvariable variable=subscriptionId]${SUBSCRIPTION_ID}"
    echo "##vso[task.setvariable variable=subscriptionName]${SUBSCRIPTION_NAME}"

From there I attempt to call the Azure CLI via a template:

- template: execution-cli.yml
  parameters:
    azureSubscriptionId: $(subscriptionId)
    azureSubscriptionName: $(subscriptionName)

Inside the template my CLI step uses:

steps:
  - task: AzureCLI@2
    displayName: Test CLI
    inputs:
      azureSubscription: "ARMTest ${{ parameters.azureSubscriptionName }}"
      scriptType: bash
      scriptLocation: inlineScript
      inlineScript: |
        az --version
      addSpnToEnvironment: true
      useGlobalConfig: true

It looks like Pipelines is trying to preemptively check authorization without noticing that there's a variable in there. What am I doing wrong here that is causing Azure to attempt to resolve that at the wrong time?

I do this in other pipelines without issues and I am not sure what is different in this particular instance.

Update 1: Working Template I have Elsewhere

Full template:

parameters:
  - name: environment
    type: string

jobs:
  - job: AKSCredentials
    displayName: "AKS Credentials Pull"
    steps:
      - task: AzureCLI@2
        displayName: AKS Credentials
        inputs:
          azureSubscription: "Azure: testbed-${{ parameters.environment }}"
          scriptType: bash
          scriptLocation: inlineScript
          inlineScript: az aks get-credentials -g testbed-${{ parameters.environment }} -n testbed-${{ parameters.environment }}-aks
          addSpnToEnvironment: true
          useGlobalConfig: true
1 Answers

This is not possible because azure subscription needs to be known at compilation time. You set your variable on run time.

Here an issue with similar case when it is explained:

run time variables aren't supported for service connection OR azure subscription. In your code sample, you are referring to AzureSubscription variable which will get initialized at the run time (but not at save time). Your syntax is correct but you need to set AzureSubscription variable as part of variables.

If you define your variables like:

variables:
  subscriptionId: someValue
  subscriptionName: someValue

and then you will use it

- template: execution-cli.yml
  parameters:
    azureSubscriptionId: $(subscriptionId)
    azureSubscriptionName: $(subscriptionName)

it should work. But since you set up your variables on runtime it causes your issue.

Related