You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Webhook测试返回200但服务未触发脚本的排查

GitLab Webhook测试返回200但脚本未执行的排查与解决

问题描述

GitLab配置Webhook后,测试触发返回状态码200,但目标机器上的systemd监听服务未执行构建脚本(脚本直接运行正常),需排查并修复Webhook服务接收GitLab通知的配置。

现有配置信息

1. Ansible配置的systemd服务

- name: Create the webhooks service
  copy:
    dest: /etc/systemd/system/webhook.service
    content: |
      [Unit]
      Description=Webhooks
      [Service]
      ExecStart=/usr/bin/webhook -secure \
      -cert /etc/letsencrypt/live/my-project.mywebsite.com/fullchain.pem \
      -key /etc/letsencrypt/live/my-project.mywebsite.com/privkey.pem \
      -hooks /home/myuser/webhooks/hooks.json \
      -hotreload \
      -verbose
      WorkingDirectory=/home/myuser/webhooks
      Restart=always
      RestartSec=5
      [Install]
      WantedBy=multi-user.target

- name: Enable the webhooks service
  command: systemctl enable webhook.service

- name: (Re-)start the webhooks service
  command: systemctl restart webhook.service

2. hooks.json配置

[{
  "id": "my-repository",
  "execute-command": "/home/myuser/webhooks/my-repository/deploy.sh",
  "command-working-directory": "/home/myuser/my-repository/",
  "response-message": "Executing deploy script...",
  "trigger-rule": {
    "match": {
      "type": "payload-hmac-sha1",
      "secret":"<WEBHOOK_SECRET_LIKE_IN_GITLAB>",
      "parameter": {
        "source": "header",
        "name": "X-Hub-Signature"
      }
    }
  }
}]

3. 端口监听确认

myuser@mymachine:~$ sudo lsof -i -P -n | grep 9000
webhook   609262            root    6u  IPv6 1589700      0t0  TCP *:9000 (LISTEN)

4. systemd服务状态

myuser@mymachine:~$ sudo systemctl status webhook.service
● webhook.service - Webhooks
     Loaded: loaded (/etc/systemd/system/webhook.service; enabled; preset: enabled)
     Active: active (running) since Tue 2024-10-08 18:42:34 UTC; 23s ago
   Main PID: 637049 (webhook)
      Tasks: 9 (limit: 18692)
     Memory: 2.1M (peak: 2.4M)
        CPU: 8ms
     CGroup: /system.slice/webhook.service
             └─637049 /usr/bin/webhook -secure -cert /etc/letsencrypt/live/my-project.mywebsite.com/fullchain.pem -key /etc/letsencrypt/live/my-project.mywebsite.com/privkey.pem -hooks >

Oct 08 18:42:34 my-project.mywebsite.com systemd[1]: Started webhook.service - Webhooks.
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 version 2.8.0 starting
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 setting up os signal watcher
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 attempting to load hooks from /home/myuser/webhooks/hooks.json
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 found 1 hook(s) in file
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34         loaded: my-repository
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 os signal watcher ready
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 setting up file watcher for /home/myuser/webhooks/hooks.json
Oct 08 18:42:34 my-project.mywebsite.com webhook[637049]: [webhook] 2024/10/08 18:42:34 serving hooks on https://0.0.0.0:9000/hooks/{id}

网络环境

GitLab服务器与目标机器位于同一Hetzner私有网络,GitLab地址为10.0.2.1,目标机器地址为10.0.3.1。

排查与解决步骤

1. 修复HMAC签名匹配规则

GitLab发送的X-Hub-Signature格式为sha1=xxxxxx,webhook工具默认不会自动识别前缀,需在hooks.json的触发规则中添加prefix字段:

"trigger-rule": {
  "match": {
    "type": "payload-hmac-sha1",
    "secret":"<WEBHOOK_SECRET_LIKE_IN_GITLAB>",
    "parameter": {
      "source": "header",
      "name": "X-Hub-Signature"
    },
    "prefix": "sha1="
  }
}

修改后重启服务:sudo systemctl restart webhook.service

2. 确认权限配置

当前webhook以root用户运行,需确保root能访问并执行脚本:

  • 检查脚本执行权限:chmod +x /home/myuser/webhooks/my-repository/deploy.sh
  • 检查工作目录权限:确保root对/home/myuser/my-repository/有读写权限

3. 查看详细日志定位问题

利用-verbose参数查看实时日志:

journalctl -u webhook.service -f

触发GitLab测试Webhook,观察日志中是否有签名验证失败、脚本执行报错等信息,精准定位问题。

4. 模拟请求测试

在目标机器上用curl模拟GitLab请求,验证签名和触发逻辑:

# 生成测试payload的签名
echo -n "test payload" | openssl dgst -sha1 -hmac "<WEBHOOK_SECRET_LIKE_IN_GITLAB>" | sed 's/^.* //'
# 发送请求
curl -X POST https://10.0.3.1:9000/hooks/my-repository \
  -H "X-Hub-Signature: sha1=生成的签名值" \
  -H "Content-Type: application/json" \
  -d '{"test": "payload"}'

观察是否触发脚本执行,同时核对日志输出。

5. 排查HTTPS证书问题(私有网络场景)

若私有网络内无需HTTPS,可暂时禁用HTTPS测试:
修改systemd服务的ExecStart:

ExecStart=/usr/bin/webhook -hooks /home/myuser/webhooks/hooks.json -hotreload -verbose

重启服务后,将GitLab的Webhook地址改为http://10.0.3.1:9000/hooks/my-repository测试。若正常执行,再排查GitLab是否不信任目标机器的Let's Encrypt证书。


内容的提问来源于stack exchange,提问作者C4X

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 09:52:32