You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Runner拉取代码时触发403 Forbidden错误求助

GitLab流水线拉取源代码阶段始终返回403 Forbidden(所有项目,无论公开私有)

所有项目(无论公开或私有)创建并运行GitLab流水线时,均在拉取仓库源代码阶段触发403 Forbidden错误,该错误发生在流水线配置执行之前。已尝试更换不同Runner、调整「Job token permissions」开关状态,问题仍未解决。


流水线配置

stages:
  - build
  - step1
  - step2

variables:
  REGISTRY: "https://index.docker.io/v1/"
  VERSION:
    value: ""
    description: "Введите tag (версию) контейнера. Пример: v0.0.1"

.build: &build_def
  stage: build
  image:
    name: gcr.io/kaniko-project/executor:v1.11.0-debug
    entrypoint: [""]
  before_script:
    - |
      if [ -z $VERSION ]; then
        echo "Please select a container version"
        exit 1 
      fi
    - echo ${PROJECT_DIR}
    - echo ${CONTAINER_NAME}
    - echo "{\"auths\":{\"${REGISTRY}\":{\"auth\":\"$(printf \"%s:%s\" \"${REGISTRY_USER}\" \"${REGISTRY_PASSWORD}\" | base64 | tr -d '\n')\"}}}" > /kaniko/.docker/config.json
  script:
    - echo "Build container..."
    - /kaniko/executor 
      --context $PROJECT_DIR 
      --dockerfile $PROJECT_DIR/Dockerfile 
      --destination ${CONTAINER_NAME}
  tags:
    - stage
  when: manual
  only:
    - web

application1: 
  <<: *build_def
  variables:
    CONTAINER_NAME: bigkaa/gitlab-application1:${VERSION}
    PROJECT_DIR: ${CI_PROJECT_DIR}/application1

application2: 
  <<: *build_def
  variables:
    CONTAINER_NAME: bigkaa/gitlab-application2:${VERSION}
    PROJECT_DIR: ${CI_PROJECT_DIR}/application2

step1:
  stage: step1 
  cache:
    key: test-cache
    paths:
      - some_path/
  script:
    - mkdir some_path
    - echo "Hello from step1" > some_path/hello.txt 
  tags:
    - stage
  when: manual
  only:
    - web

step2:
  stage: step2 
  cache:
    key: test-cache
    paths:
      - some_path/
  script:
    - cat some_path/hello.txt
  tags:
    - stage
  when: manual
  only:
    - web

Runner配置(Kubernetes部署)

imagePullPolicy: IfNotPresent
revisionHistoryLimit: 3
gitlabUrl: "https://gitlab.syntaxjuggler.com/"
terminationGracePeriodSeconds: 3600
# Количество раннеров
concurrent: 5
checkInterval: 30
logLevel: info
logFormat: json
sessionServer:
  enabled: false
rbac:
  create: true
  rules:
  - resources: ["pods", "secrets", "configmaps"]
    verbs: ["get", "list", "watch", "create", "patch", "delete", "update"]
  - apiGroups: [""]
    resources: ["pods/exec", "pods/attach"]
    verbs: ["create", "patch", "delete"]
  clusterWideAccess: true
  podSecurityPolicy:
    enabled: false
    resourceNames:
    - gitlab-runner
metrics:
  enabled: true
  portName: metrics
  port: 9252
  serviceMonitor:
    enabled: false
service:
  enabled: true
runners:
  config: |
    # log_level = "debug"
    [[runners]]
      output_limit = 10000
      [runners.kubernetes]
        image = "ubuntu:22.04"
        # helper_image = "if use custom helper"
      [runners.cache]
        Type = "s3"
        Path = "runner"
        Shared = true
        [runners.cache.s3]
          ServerAddress = "gitlab-minio.gitlab.svc.cluster.local:9000"
          BucketName = "runner-cache"
          BucketLocation = "nbg1"
          Insecure = false
          AuthenticationType = "access-key"
  cache:
    secretName: gitlab-runner
  executor: kubernetes
  secret: gitlab-runner
securityContext:
  runAsUser: 100
  # runAsGroup: 65533
  fsGroup: 65533
  # supplementalGroups: [65533]
resources:
  limits:
    memory: 256Mi
    cpu: 200m
  requests:
    memory: 128Mi
    cpu: 100m

错误日志

Running with gitlab-runner 17.2.1 (9882d9c7)
  on gitlab-runner-848474899d-2hxfg ZCLbfgpyE, system ID: r_5D9FZv9JrMxM
Preparing the "kubernetes" executor
00:00
Using Kubernetes namespace: gitlab
Using Kubernetes executor with image ubuntu:22.04 ...
Using attach strategy to execute scripts...
Preparing environment
00:04
Using FF_USE_POD_ACTIVE_DEADLINE_SECONDS, the Pod activeDeadlineSeconds will be set to the job timeout: 1h0m0s...
Waiting for pod gitlab/runner-zclbfgpye-project-2-concurrent-0-aquc04fn to be running, status is Pending
Running on runner-zclbfgpye-project-2-concurrent-0-aquc04fn via gitlab-runner-848474899d-2hxfg...
Getting source from Git repository
00:00
Fetching changes with git depth set to 20...
Initialized empty Git repository in /builds/root/test2/.git/
Created fresh repository.
fatal: unable to access 'https://gitlab.syntaxjuggler.com/root/test2.git/': The requested URL returned error: 403
Cleaning up project directory and file based variables
00:01
ERROR: Job failed: command terminated with exit code 1

排查与解决步骤

  1. 验证Runner注册权限与有效性

    • 检查Runner注册token:实例级Runner需确认实例设置中允许其运行所有项目;项目级Runner需确认token未过期且绑定正确项目。
    • 测试网络连通性:在Runner pod内执行curl -v https://gitlab.syntaxjuggler.com,确认无网络策略、防火墙拦截GitLab访问。
  2. 确认Job Token权限配置

    • 项目级设置:进入项目→设置→CI/CD→流水线→Job token权限,确保勾选「允许作业访问本项目」;公开项目也需确认该选项未被禁用。
    • 实例级设置:检查GitLab全局CI/CD配置,确认未对Job Token的仓库访问权限做全局限制。
  3. 修复Helper镜像版本匹配问题
    当前Runner版本为17.2.1,需指定对应版本的helper镜像,避免版本不兼容导致认证失败:

    [[runners]]
      [runners.kubernetes]
        image = "ubuntu:22.04"
        helper_image = "gitlab/gitlab-runner-helper:17.2.1"
    
  4. 检查GitLab证书与仓库URL

    • 若GitLab使用自签名证书,需将CA证书添加到Runner pod信任列表,或在Runner配置中指定tls-ca-file参数。
    • 移除仓库URL末尾斜杠:日志中URL为https://gitlab.syntaxjuggler.com/root/test2.git/,去掉末尾斜杠可避免git解析异常。
  5. 排除缓存配置干扰
    暂时注释Runner的S3缓存配置,重新部署后测试流水线,确认是否因缓存配置导致间接认证问题。

内容的提问来源于stack exchange,提问作者SyntaxJuggler

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 09:15:54