Docker构建时无法将Poetry认证秘钥挂载至环境变量求助
问题:Docker构建秘钥挂载环境变量失败
我参考Docker官方文档示例修改后,尝试通过构建秘钥提供Poetry认证,但秘钥无法挂载到环境中。
构建命令
export DOCKER_BUILDKIT=1 docker build \ --secret id=poetry_johndoe_auth_username,env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_USERNAME \ --secret id=poetry_johndoe_auth_password,env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_PASSWORD \ -t example:latest .
Dockerfile代码
RUN --mount=type=secret,id=poetry_johndoe_auth_username,env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_USERNAME \ --mount=type=secret,id=poetry_johndoe_auth_password,env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_PASSWORD \ pip install -r /tmp/requirements.txt
CI返回错误
Dockerfile:17
16 |
RUN --mount=type=secret,id=poetry_johndoe_auth_username,env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_USERNAME
--mount=type=secret,id=poetry_johndoe_auth_password,env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_PASSWORD
pip install -r /tmp/requirements.txtERROR: failed to solve: unexpected key 'env' in 'env=POETRY_HTTP_BASIC_JOHNDOE_GITLAB_USERNAME'
解决方案
问题根源是**env不是secret类型挂载的合法参数**,Docker不支持在--mount=type=secret里直接用env设置环境变量。正确做法是挂载秘钥到容器临时文件后,在RUN命令内部读取文件内容赋值给环境变量。
修改后的Dockerfile示例1
RUN --mount=type=secret,id=poetry_johndoe_auth_username \ --mount=type=secret,id=poetry_johndoe_auth_password \ export POETRY_HTTP_BASIC_JOHNDOE_GITLAB_USERNAME=$(cat /run/secrets/poetry_johndoe_auth_username) && \ export POETRY_HTTP_BASIC_JOHNDOE_GITLAB_PASSWORD=$(cat /run/secrets/poetry_johndoe_auth_password) && \ pip install -r /tmp/requirements.txt
修改后的Dockerfile示例2(更简洁)
RUN --mount=type=secret,id=poetry_johndoe_auth_username \ --mount=type=secret,id=poetry_johndoe_auth_password \ POETRY_HTTP_BASIC_JOHNDOE_GITLAB_USERNAME=$(cat /run/secrets/poetry_johndoe_auth_username) \ POETRY_HTTP_BASIC_JOHNDOE_GITLAB_PASSWORD=$(cat /run/secrets/poetry_johndoe_auth_password) \ pip install -r /tmp/requirements.txt
说明
- 使用
--mount=type=secret时,秘钥默认挂载到/run/secrets/<秘钥id>路径 - 必须在RUN命令内部通过读取文件的方式将秘钥内容赋值给环境变量,不能直接在挂载参数里指定
env
内容的提问来源于stack exchange,提问作者tbhaxor
相关产品推荐
相关产品推荐

