GitLab Runner拉取代码时触发403 Forbidden错误求助
GitLab流水线拉取源代码阶段始终返回403 Forbidden(所有项目,无论公开私有)
所有项目(无论公开或私有)创建并运行GitLab流水线时,均在拉取仓库源代码阶段触发403 Forbidden错误,该错误发生在流水线配置执行之前。已尝试更换不同Runner、调整「Job token permissions」开关状态,问题仍未解决。
流水线配置
stages: - build - step1 - step2 variables: REGISTRY: "https://index.docker.io/v1/" VERSION: value: "" description: "Введите tag (версию) контейнера. Пример: v0.0.1" .build: &build_def stage: build image: name: gcr.io/kaniko-project/executor:v1.11.0-debug entrypoint: [""] before_script: - | if [ -z $VERSION ]; then echo "Please select a container version" exit 1 fi - echo ${PROJECT_DIR} - echo ${CONTAINER_NAME} - echo "{\"auths\":{\"${REGISTRY}\":{\"auth\":\"$(printf \"%s:%s\" \"${REGISTRY_USER}\" \"${REGISTRY_PASSWORD}\" | base64 | tr -d '\n')\"}}}" > /kaniko/.docker/config.json script: - echo "Build container..." - /kaniko/executor --context $PROJECT_DIR --dockerfile $PROJECT_DIR/Dockerfile --destination ${CONTAINER_NAME} tags: - stage when: manual only: - web application1: <<: *build_def variables: CONTAINER_NAME: bigkaa/gitlab-application1:${VERSION} PROJECT_DIR: ${CI_PROJECT_DIR}/application1 application2: <<: *build_def variables: CONTAINER_NAME: bigkaa/gitlab-application2:${VERSION} PROJECT_DIR: ${CI_PROJECT_DIR}/application2 step1: stage: step1 cache: key: test-cache paths: - some_path/ script: - mkdir some_path - echo "Hello from step1" > some_path/hello.txt tags: - stage when: manual only: - web step2: stage: step2 cache: key: test-cache paths: - some_path/ script: - cat some_path/hello.txt tags: - stage when: manual only: - web
Runner配置(Kubernetes部署)
imagePullPolicy: IfNotPresent revisionHistoryLimit: 3 gitlabUrl: "https://gitlab.syntaxjuggler.com/" terminationGracePeriodSeconds: 3600 # Количество раннеров concurrent: 5 checkInterval: 30 logLevel: info logFormat: json sessionServer: enabled: false rbac: create: true rules: - resources: ["pods", "secrets", "configmaps"] verbs: ["get", "list", "watch", "create", "patch", "delete", "update"] - apiGroups: [""] resources: ["pods/exec", "pods/attach"] verbs: ["create", "patch", "delete"] clusterWideAccess: true podSecurityPolicy: enabled: false resourceNames: - gitlab-runner metrics: enabled: true portName: metrics port: 9252 serviceMonitor: enabled: false service: enabled: true runners: config: | # log_level = "debug" [[runners]] output_limit = 10000 [runners.kubernetes] image = "ubuntu:22.04" # helper_image = "if use custom helper" [runners.cache] Type = "s3" Path = "runner" Shared = true [runners.cache.s3] ServerAddress = "gitlab-minio.gitlab.svc.cluster.local:9000" BucketName = "runner-cache" BucketLocation = "nbg1" Insecure = false AuthenticationType = "access-key" cache: secretName: gitlab-runner executor: kubernetes secret: gitlab-runner securityContext: runAsUser: 100 # runAsGroup: 65533 fsGroup: 65533 # supplementalGroups: [65533] resources: limits: memory: 256Mi cpu: 200m requests: memory: 128Mi cpu: 100m
错误日志
Running with gitlab-runner 17.2.1 (9882d9c7) on gitlab-runner-848474899d-2hxfg ZCLbfgpyE, system ID: r_5D9FZv9JrMxM Preparing the "kubernetes" executor 00:00 Using Kubernetes namespace: gitlab Using Kubernetes executor with image ubuntu:22.04 ... Using attach strategy to execute scripts... Preparing environment 00:04 Using FF_USE_POD_ACTIVE_DEADLINE_SECONDS, the Pod activeDeadlineSeconds will be set to the job timeout: 1h0m0s... Waiting for pod gitlab/runner-zclbfgpye-project-2-concurrent-0-aquc04fn to be running, status is Pending Running on runner-zclbfgpye-project-2-concurrent-0-aquc04fn via gitlab-runner-848474899d-2hxfg... Getting source from Git repository 00:00 Fetching changes with git depth set to 20... Initialized empty Git repository in /builds/root/test2/.git/ Created fresh repository. fatal: unable to access 'https://gitlab.syntaxjuggler.com/root/test2.git/': The requested URL returned error: 403 Cleaning up project directory and file based variables 00:01 ERROR: Job failed: command terminated with exit code 1
排查与解决步骤
验证Runner注册权限与有效性
- 检查Runner注册token:实例级Runner需确认实例设置中允许其运行所有项目;项目级Runner需确认token未过期且绑定正确项目。
- 测试网络连通性:在Runner pod内执行
curl -v https://gitlab.syntaxjuggler.com,确认无网络策略、防火墙拦截GitLab访问。
确认Job Token权限配置
- 项目级设置:进入项目→
设置→CI/CD→流水线→Job token权限,确保勾选「允许作业访问本项目」;公开项目也需确认该选项未被禁用。 - 实例级设置:检查GitLab全局CI/CD配置,确认未对Job Token的仓库访问权限做全局限制。
- 项目级设置:进入项目→
修复Helper镜像版本匹配问题
当前Runner版本为17.2.1,需指定对应版本的helper镜像,避免版本不兼容导致认证失败:[[runners]] [runners.kubernetes] image = "ubuntu:22.04" helper_image = "gitlab/gitlab-runner-helper:17.2.1"检查GitLab证书与仓库URL
- 若GitLab使用自签名证书,需将CA证书添加到Runner pod信任列表,或在Runner配置中指定
tls-ca-file参数。 - 移除仓库URL末尾斜杠:日志中URL为
https://gitlab.syntaxjuggler.com/root/test2.git/,去掉末尾斜杠可避免git解析异常。
- 若GitLab使用自签名证书,需将CA证书添加到Runner pod信任列表,或在Runner配置中指定
排除缓存配置干扰
暂时注释Runner的S3缓存配置,重新部署后测试流水线,确认是否因缓存配置导致间接认证问题。
内容的提问来源于stack exchange,提问作者SyntaxJuggler
相关产品推荐
相关产品推荐

