GitLab Actions配置信任Maven服务器SSL证书分步指南
解决GitLab Actions中Maven PKIX证书错误的分步指南
背景
已在pom.xml中配置企业Maven仓库:
</build> <repositories> <repository> <id>profile-releases</id> <url>https://enterprise.com.uy/repository</url> </repository> </repositories> </project>
在GitLab Actions执行mvn clean install时出现PKIX证书错误:
[ERROR] Failed to execute goal on project web-user-test: Could not resolve dependencies for project uy.com.enterprise:web-user-test:jar:1.0.0: Failed to collect dependencies at uy.com.enterprise.ProxyISSO:jar:3.0.0: Failed to read artifact descriptor for uy.com.enterprise.ProxyISSO:jar:3.0.0: Could not transfer artifact uy.com.enterprise:ProxyISSO:pom:3.0.0 from/to desaint-releases (https://enterprise.com.uy/enterprise/repo): transfer failed for ...: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target -> [Help 1]
当前使用镜像为maven:3.8.1-jdk-11,本地持有cert001.crt证书,以下是无需环境变量的证书配置分步方案:
分步操作
1. 将证书上传至GitLab仓库
- 在项目根目录创建
certs文件夹 - 将本地的
cert001.crt文件放入该文件夹,提交并推送到GitLab仓库
2. 修改.gitlab-ci.yml配置
在Maven构建步骤前添加证书导入逻辑,示例配置如下:
build: image: maven:3.8.1-jdk-11 script: # 导入证书到JDK信任库,默认密码为changeit - keytool -importcert -file ./certs/cert001.crt -alias enterprise-repo-cert -keystore /usr/local/openjdk-11/lib/security/cacerts -storepass changeit -noprompt # 执行Maven构建 - mvn clean install
3. 关键说明
maven:3.8.1-jdk-11镜像中JDK信任库的固定路径为/usr/local/openjdk-11/lib/security/cacerts-noprompt参数用于跳过证书确认步骤,适配CI/CD自动化场景alias可自定义,只需保证在信任库中唯一即可
内容的提问来源于stack exchange,提问作者y.z
相关产品推荐
相关产品推荐

