You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在OpenShift中能否用ConfigMap替代Pipeline参数管理SSH连接信息?

可以实现,具体方案如下

这种方式能大幅简化Pipeline的参数表单,日常运行无需手动输入固定的SSH连接信息,仅在更换VM时更新配置或临时覆盖即可。

1. 拆分存储:ConfigMap存非敏感信息,Secret存敏感凭证

把SSH连接里的非敏感数据(比如VM主机IP、端口)存在ConfigMap,敏感数据(用户名、密码/私钥)存在Secret,避免敏感信息泄露。

创建ConfigMap

apiVersion: v1
kind: ConfigMap
metadata:
  name: windows-ssh-config
  namespace: 你的命名空间  # 替换成实际命名空间
data:
  ssh-host: "192.168.1.100"  # Windows VM的IP或主机名
  ssh-port: "22"  # SSH端口,Windows默认可能是22或自定义端口

创建Secret

注意:Secret的value需要用Base64编码,或者用命令直接创建(自动编码)。
用命令快速创建密码认证的Secret:

kubectl create secret generic windows-ssh-secret \
  --namespace=你的命名空间 \
  --from-literal=ssh-user=你的用户名 \
  --from-literal=ssh-pass=你的密码

如果用私钥认证,把私钥文件内容传入:

kubectl create secret generic windows-ssh-secret \
  --namespace=你的命名空间 \
  --from-file=ssh-privatekey=./id_rsa  # 私钥文件路径

2. 在Pipeline模板中引用配置

以K8s生态的Tekton Pipeline为例,有两种常用引用方式:

方式一:通过环境变量直接注入(最简单)

在Task定义里,通过env字段从ConfigMap/Secret读取值,无需额外传递参数:

apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: ssh-windows-task
  namespace: 你的命名空间
spec:
  steps:
    - name: execute-ssh-command
      image: alpine/ssh  # 带sshpass的镜像,用于密码认证;如果用私钥,换带ssh的镜像即可
      env:
        # 从ConfigMap取非敏感配置
        - name: SSH_HOST
          valueFrom:
            configMapKeyRef:
              name: windows-ssh-config
              key: ssh-host
        - name: SSH_PORT
          valueFrom:
            configMapKeyRef:
              name: windows-ssh-config
              key: ssh-port
        # 从Secret取敏感凭证
        - name: SSH_USER
          valueFrom:
            secretKeyRef:
              name: windows-ssh-secret
              key: ssh-user
        - name: SSH_PASS
          valueFrom:
            secretKeyRef:
              name: windows-ssh-secret
              key: ssh-pass
      script: |
        #!/bin/sh
        # 执行Windows Powershell命令示例
        sshpass -p "$SSH_PASS" ssh -p $SSH_PORT -o StrictHostKeyChecking=no $SSH_USER@$SSH_HOST "powershell Get-ChildItem C:\"

如果用私钥认证,需要把Secret里的私钥挂载到容器目录,修改后的Task:

apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: ssh-windows-task
  namespace: 你的命名空间
spec:
  workspaces:
    - name: ssh-key
      description: 挂载SSH私钥的Workspace
  steps:
    - name: execute-ssh-command
      image: alpine/ssh
      env:
        - name: SSH_HOST
          valueFrom:
            configMapKeyRef:
              name: windows-ssh-config
              key: ssh-host
        - name: SSH_PORT
          valueFrom:
            configMapKeyRef:
              name: windows-ssh-config
              key: ssh-port
        - name: SSH_USER
          valueFrom:
            secretKeyRef:
              name: windows-ssh-secret
              key: ssh-user
      volumeMounts:
        - name: ssh-key
          mountPath: /tekton/home/.ssh
          readOnly: true
      script: |
        #!/bin/sh
        chmod 600 /tekton/home/.ssh/ssh-privatekey
        ssh -i /tekton/home/.ssh/ssh-privatekey -p $SSH_PORT -o StrictHostKeyChecking=no $SSH_USER@$SSH_HOST "powershell Get-ChildItem C:\"

对应的PipelineRun需要关联Workspace:

apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
  generateName: windows-ssh-run-
  namespace: 你的命名空间
spec:
  pipelineRef:
    name: 你的Pipeline名称
  workspaces:
    - name: ssh-key
      secret:
        secretName: windows-ssh-secret

方式二:通过Workspace挂载配置文件

把ConfigMap和Secret挂载成容器内的文件,然后在脚本里读取文件内容:

apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: ssh-windows-task-workspace
  namespace: 你的命名空间
spec:
  workspaces:
    - name: ssh-config
      description: 挂载SSH配置的ConfigMap
    - name: ssh-secret
      description: 挂载SSH凭证的Secret
  steps:
    - name: execute-ssh-command
      image: alpine/ssh
      script: |
        #!/bin/sh
        SSH_HOST=$(cat $(workspaces.ssh-config.path)/ssh-host)
        SSH_PORT=$(cat $(workspaces.ssh-config.path)/ssh-port)
        SSH_USER=$(cat $(workspaces.ssh-secret.path)/ssh-user)
        SSH_PASS=$(cat $(workspaces.ssh-secret.path)/ssh-pass)
        
        sshpass -p "$SSH_PASS" ssh -p $SSH_PORT -o StrictHostKeyChecking=no $SSH_USER@$SSH_HOST "powershell Get-ChildItem C:\"

PipelineRun里关联对应的ConfigMap和Secret:

apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
  generateName: windows-ssh-run-
  namespace: 你的命名空间
spec:
  pipelineRef:
    name: 你的Pipeline名称
  workspaces:
    - name: ssh-config
      configMap:
        name: windows-ssh-config
    - name: ssh-secret
      secret:
        secretName: windows-ssh-secret

3. 更换VM时的操作

当需要切换到新的Windows VM时,只需要更新ConfigMap和Secret(如果凭证变化):

  • 更新ConfigMap:
kubectl edit configmap windows-ssh-config --namespace=你的命名空间

修改ssh-host和ssh-port的值即可。

  • 更新Secret:
    如果是密码认证:
kubectl create secret generic windows-ssh-secret --namespace=你的命名空间 --from-literal=ssh-user=新用户名 --from-literal=ssh-pass=新密码 --dry-run=client -o yaml | kubectl apply -f -

如果是私钥认证,重新上传新的私钥即可。

4. 可选:保留临时覆盖参数

如果需要偶尔临时用其他VM测试,可以在Task里添加可选参数,优先级高于ConfigMap/Secret的值:

apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: ssh-windows-task-override
  namespace: 你的命名空间
spec:
  params:
    - name: ssh-host
      type: string
      optional: true
    - name: ssh-port
      type: string
      optional: true
    - name: ssh-user
      type: string
      optional: true
    - name: ssh-pass
      type: string
      optional: true
  steps:
    - name: execute-ssh-command
      image: alpine/ssh
      env:
        - name: SSH_HOST_DEFAULT
          valueFrom:
            configMapKeyRef:
              name: windows-ssh-config
              key: ssh-host
        - name: SSH_PORT_DEFAULT
          valueFrom:
            configMapKeyRef:
              name: windows-ssh-config
              key: ssh-port
        - name: SSH_USER_DEFAULT
          valueFrom:
            secretKeyRef:
              name: windows-ssh-secret
              key: ssh-user
        - name: SSH_PASS_DEFAULT
          valueFrom:
            secretKeyRef:
              name: windows-ssh-secret
              key: ssh-pass
      script: |
        #!/bin/sh
        # 优先使用传入的参数,没有则用默认配置
        SSH_HOST=$(params.ssh-host || echo $SSH_HOST_DEFAULT)
        SSH_PORT=$(params.ssh-port || echo $SSH_PORT_DEFAULT)
        SSH_USER=$(params.ssh-user || echo $SSH_USER_DEFAULT)
        SSH_PASS=$(params.ssh-pass || echo $SSH_PASS_DEFAULT)
        
        sshpass -p "$SSH_PASS" ssh -p $SSH_PORT -o StrictHostKeyChecking=no $SSH_USER@$SSH_HOST "powershell Get-ChildItem C:\"

这样日常运行Pipeline不需要填任何参数,只有临时测试时才需要手动输入参数覆盖。

内容的提问来源于stack exchange,提问作者ibenedetto

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 08:33:13