如何避免Jenkins日志打印从Vault获取的密钥信息
问题
我有一个从Vault获取密钥的自定义脚本(无法使用Jenkins credentials存储密钥)。我的代码如下:
def executeCommand(def command) { return sh(script: command, returnStatus: true, label: "Executing Command") } def cred = <call some script> // 返回 {username : '', password : '' } withEnv(["DOCKER_USER=${cred.username}", "DOCKER_PASS=${cred.password}"]) { def command = "printf '%s' \"\$DOCKER_PASS\" | docker login ${DockerRepo}.${tmpRepoUrl} -u \$DOCKER_USER --password-stdin" def status = executeCommand(command) }
问题在于,凭证信息被打印到了Jenkins日志中:
[Pipeline] sh (Executing Command) (hide)
- printf somepassword
- docker login docker.test.net -u test --password-stdin
WARNING! Your password will be stored unencrypted in /root/.docker/config.json.
请问如何避免命令信息在Jenkins日志中被打印?
解决方案
方法1:避免字符串拼接,直接在shell内部引用环境变量
修改executeCommand方法,将固定命令逻辑封装在方法内,只传递非敏感参数,敏感变量通过环境变量在shell内部引用,避免完整命令字符串被Jenkins日志捕获:
def executeDockerLogin(String repoUrl, String dockerUser) { return sh( script: """ printf '%s' "\$DOCKER_PASS" | docker login ${repoUrl} -u ${dockerUser} --password-stdin """, returnStatus: true, label: "Executing Docker Login" ) } def cred = <call some script> withEnv(["DOCKER_PASS=${cred.password}"]) { def status = executeDockerLogin("${DockerRepo}.${tmpRepoUrl}", cred.username) }
方法2:关闭shell的命令回显
在执行的命令开头添加set +x,关闭shell的调试输出功能,避免执行的命令被打印到日志:
def executeCommand(def command) { return sh(script: "set +x; ${command}", returnStatus: true, label: "Executing Command") } def cred = <call some script> withEnv(["DOCKER_USER=${cred.username}", "DOCKER_PASS=${cred.password}"]) { def command = "printf '%s' \"\$DOCKER_PASS\" | docker login ${DockerRepo}.${tmpRepoUrl} -u \$DOCKER_USER --password-stdin" def status = executeCommand(command) }
方法3:使用Jenkins Docker Pipeline插件内置的登录方法(推荐)
如果Jenkins安装了Docker Pipeline插件,直接使用内置的docker.login方法,它会自动处理敏感信息的日志隐藏,无需手动拼接命令:
def cred = <call some script> docker.login( username: cred.username, password: cred.password, url: "${DockerRepo}.${tmpRepoUrl}" )
内容的提问来源于stack exchange,提问作者pythonhmmm
相关产品推荐
相关产品推荐

