Unable to run a correct Azure CLI command from Azure Devops CLI task (Bad request)

Viewed 909

I am running the following command from Azure CLI in Azure portal, and it works.

az resource list -g RG_SE_Polisen_Dev --query "[?type=='Microsoft.Storage/storageAccounts'].name" --output tsv | xargs -n 1 -t -I "{}" az lock delete -n "DevTestLabs Lock" -g RG_SE_Polisen_Dev --resource "{}" --resource-type "Microsoft.Storage/storageAccounts"

Running the same command via Azure CLI task in Azure Devops pipelines for automation, getting the following error:

Agent output

In Text:

E:\agent_1\_work\r30\a>az resource list -g RG_SE_Polisen_Dev --query "[?type=='Microsoft.KeyVault/vaults'].name" --output tsv   | xargs -n 1 -t -I '{}' az lock delete -n "DevTestLabs Lock" -g RG_SE_Polisen_Dev --resource '{}' --resource-type "Microsoft.KeyVault/vaults" 
2021-09-23T07:31:36.4258125Z az lock delete -n DevTestLabs Lock -g RG_SE_Polisen_Dev --resource SEDEVDTL9342
2021-09-23T07:31:36.4258390Z  --resource-type Microsoft.KeyVault/vaults 
2021-09-23T07:31:37.8440554Z ERROR: Operation returned an invalid status 'Bad Request'
2021-09-23T07:31:37.9668128Z ##[error]Script failed with error: Error: E:\agent_1\_work\_temp\azureclitaskscript1632382287742.bat failed with return code: 123
3 Answers

Looks like your trying to run the script from the agent. It might not have access to the same resources/permissions as your user when you run it in the portal.

The lock is successfully deleted for all storage account with the task: enter image description here

enter image description here

  1. Obeserve your issue screenshot, the command is split into two lines. The storageaccount resource name cannot be correctly got with your command in Azure CLI task(but it works locally). For example, i validate with below command:

    az resource list -g wadetestrg --query "[?type=='Microsoft.Storage/storageAccounts'].name" --output tsv | xargs -I "{}" echo "{}"

It returns:

enter image description here

Hence, I changed to use foreach command instead, and it works fine:

az resource list -g wadetestrg --query "[?type=='Microsoft.Storage/storageAccounts'].name" --output tsv | foreach-object {az lock delete -n "testlock3" -g wadetestrg --resource $_ --resource-type "Microsoft.Storage/storageAccounts"}
  1. Add owner role to service principal which created in the service connection.

Check doc:

Deletes the management lock of a resource or any level below the resource. To delete management locks, you must have access to Microsoft.Authorization/* or Microsoft.Authorization/locks/* actions. Of the built-in roles, only Owner and User Access Administrator are granted those actions.

In Azure CLI task, it use service connection to connect to your subscription, which is different with local user on local machine.

a. Go to project settings -> service connection -> find your service connection used in the Azure CLI task -> Manage Service Principal-> It will redirect to azure portal service principal -> Note the name and client ID.

b. Go to your resource group -> Access control(IAM) -> Add the service principal in previous step as owner role.

I managed to apply a workaround by doing it in the following code for each lock:

for /f "delims=" %%i in ('az resource list -g RG_SE_Polisen_Dev --query "[?type=='Microsoft.KeyVault/vaults'].name" --output tsv') do set output=%%i
        
  az lock delete --ids "/subscriptions/{SubID}/resourcegroups/{Rg_name}/providers/Microsoft.KeyVault/vaults/%output%/providers/Microsoft.Authorization/locks/DevTestLabs Lock"
Related