Cloud Build通过内网IP经SCP传输文件至Compute Engine失败求助
问题:Cloud Build通过内网IP经SCP传输文件至Compute Engine实例失败
当前场景
我使用Cloud Build在代码推送到GitHub指定仓库时构建HTML和JavaScript代码,构建完成后通过SCP将文件传输至分配了静态内网IP(10.0.0.2)的Compute Engine实例。
期望目标
实现Cloud Build通过内网IP经SCP传输文件至Compute Engine实例,以便在VPC防火墙中限制SSH端口(22端口)的源IP范围。
已尝试操作
为Cloud Build创建私有构建池,并配置通过VPC对等连接访问Compute Engine实例所属的VPC网络。
详细信息
- Compute Engine实例内网IP:10.0.0.2
- 私有构建池内网IP段:192.168.0.0/24
- 私有构建池已分配公网IP(用于构建过程中拉取GitHub源码,无此配置则会因无网络报错)
验证结果
通过Cloud Build使用curl访问目标Compute Engine实例的内网IP时,服务器访问日志确认来自私有构建池内网IP段的访问成功。但执行SCP传输文件至该实例内网IP时,出现如下错误:
ERROR: gcloud crashed (UnboundLocalError): cannot access local variable 'instance' where it is not associated with a value
代码
cloudbuild.yaml
steps: - id: "Delete unnecessary files" name: "ubuntu" entrypoint: "bash" args: ["./build.sh"] - id: "Transfer all files with scp" name: "gcr.io/google.com/cloudsdktool/cloud-sdk" entrypoint: "gcloud" args: [ "compute", "scp", "--project", "test-project", "--region", "asia-northeast1", "--zone", "asia-northeast1-a", "--network", "test-vpc", "--port", "22", "--recurse", "./test", "test-user@target-vm:/home/app/build-test", "--internal-ip", ] options: pool: name: projects/test-project/locations/asia-northeast1/workerPools/test-private-pool timeout: 1800s
build.sh
#!/bin/bash if [ -e "README.md" ] then rm README.md fi mkdir test GLOBIGNORE="test:cloudbuild.yaml:build.sh:.git:.gitignore:.vscode" mv * ./test unset GLOBIGNORE
解决方案探讨
- 是否应采用remote-builder方案?
- 或是需通过代理VM配置Cloud Build使用静态公网IP?
注:目前私有构建池的静态公网IP段暂未得到官方支持。
内容的提问来源于stack exchange,提问作者tipotto
相关产品推荐
相关产品推荐

