如何在Jenkins控制台隐藏SSHCommand的执行命令日志
解决Jenkins流水线sshCommand日志暴露敏感参数的问题
核心原因
你看到的日志是Jenkins SSH插件的sshCommand步骤自身输出的命令内容,并非远程服务器执行命令的回显。set +x仅能控制远程shell的命令回显,管不到Jenkins步骤本身的日志输出,所以才会无效。
具体解决方案
方法1:关闭sshCommand的日志输出(最直接)
SSH插件的sshCommand步骤支持verbose参数,默认值为true,将其设为false后,就不会打印包含敏感参数的"Executing command on..."日志行。修改后的代码如下:
stage("Export schema") { println("====== Export Schema Stage Starting==========") try { remote.name = OriginOnPremSolrNode remote.host = OriginOnPremSolrNode remote.user = common_username remote.password = main_password remote.allowAnyHosts = true sshPut remote: remote, from: 'scripts/OnPrem_Azure_Solr_Migration/migration_export.sh', into: '.' // 添加verbose: false关闭步骤日志 sshCommand remote: remote, command: "chmod 755 migration_export.sh", verbose: false // 同时保留set +x避免远程shell的命令回显 sshCommand remote: remote, command: "set +x;./migration_export.sh ${OriginOnPremSolrNode} ${param1} '${param2}';set -x", verbose: false sshRemove remote: remote, path: 'migration_export.sh' } catch (Exception ex) { println("Error executing migration_export.sh script. We either failed to ssh into ${OriginOnPremSolrNode} or we failed for other reasons") throw ex } println("Completed the stage of collecting the schema") }
方法2:通过环境变量传递敏感参数(更安全)
把敏感参数放到远程服务器的环境变量中,让脚本从环境变量读取参数,而非直接通过命令行传递,这样即使日志意外暴露,也看不到敏感值:
- 修改远程脚本
migration_export.sh,改为从环境变量读取参数:
#!/bin/bash # 从环境变量获取参数 SOLR_NODE=$SOLR_NODE PARAM1=$PARAM1 PARAM2=$PARAM2 # 原脚本业务逻辑...
- 修改Jenkins流水线代码,先设置远程环境变量再执行脚本:
sshCommand remote: remote, command: "set +x; export SOLR_NODE=${OriginOnPremSolrNode}; export PARAM1=${param1}; export PARAM2='${param2}'; ./migration_export.sh; set -x", verbose: false
方法3:结合Jenkins凭据管理(终极安全方案)
如果param1/param2是敏感信息,建议将其存入Jenkins凭据库,通过withCredentials步骤读取,配合上述方法彻底避免硬编码或直接暴露:
stage("Export schema") { println("====== Export Schema Stage Starting==========") try { remote.name = OriginOnPremSolrNode remote.host = OriginOnPremSolrNode remote.user = common_username remote.password = main_password remote.allowAnyHosts = true sshPut remote: remote, from: 'scripts/OnPrem_Azure_Solr_Migration/migration_export.sh', into: '.' sshCommand remote: remote, command: "chmod 755 migration_export.sh", verbose: false // 从凭据库读取敏感参数 withCredentials([string(credentialsId: 'param1-cred', variable: 'PARAM1'), string(credentialsId: 'param2-cred', variable: 'PARAM2')]) { sshCommand remote: remote, command: "set +x; export SOLR_NODE=${OriginOnPremSolrNode}; export PARAM1=${PARAM1}; export PARAM2='${PARAM2}'; ./migration_export.sh; set -x", verbose: false } sshRemove remote: remote, path: 'migration_export.sh' } catch (Exception ex) { println("Error executing migration_export.sh script. We either failed to ssh into ${OriginOnPremSolrNode} or we failed for other reasons") throw ex } println("Completed the stage of collecting the schema") }
内容的提问来源于stack exchange,提问作者Kundan Das
相关产品推荐
相关产品推荐

