K8s环境下Docker容器中git-sync无法连接Slack Webhook问题求助
Let's tackle your two problems one by one—they're both fixable with a few targeted adjustments to your configuration:
1. Why the Native Slack Webhook Returns a 400 Error
Git-sync's built-in GIT_SYNC_WEBHOOK_URL sends a default JSON payload that looks something like this (simplified):
{ "hash": "c04e7f7a4d20aa8ad4535425568ce4147f641cfc", "repo": "your-repo-url", "branch": "master" }
Slack's Incoming Webhooks don't recognize this format—they require a payload with a text (or blocks) field to display messages. That mismatch is exactly why you're getting a 400 Bad Request response.
2. Why the Curl Exechook Fails with "No Such File or Directory"
The k8s.gcr.io/git-sync/git-sync:v3.4.0 image is built on a minimal base image (likely distroless or stripped-down Alpine) that doesn't include curl by default. When you try to run the curl command directly, the container can't locate the executable.
Solution: Use Exechook with Tools Present in the Image
You have two reliable options here, depending on what's available in your git-sync container:
Option 1: Use wget (Most Likely Preinstalled)
Update your GIT_SYNC_EXECHOOK_COMMAND to use wget (a common tool in minimal images) and format the payload correctly for Slack. Make sure to escape quotes properly for your container config:
{ name: "GIT_SYNC_EXECHOOK_COMMAND", value: "/bin/sh -c 'wget --header=\"Content-Type: application/json\" --post-data=\"{\\\"text\\\":\\\"Git sync completed: Updated to hash $GIT_SYNC_HASH on branch $GIT_SYNC_BRANCH\\\"}\" $GIT_SYNC_WEBHOOK_URL'" }
This uses /bin/sh to handle auto-populated git-sync variables ($GIT_SYNC_HASH and $GIT_SYNC_BRANCH) and constructs a Slack-compatible message payload.
Option 2: Use busybox curl (If Busybox Is Included)
If your image includes Busybox, you can use its built-in curl instead:
{ name: "GIT_SYNC_EXECHOOK_COMMAND", value: "/bin/sh -c 'busybox curl -X POST -H \"Content-type: application/json\" --data \"{\\\"text\\\":\\\"Git sync updated to commit: $GIT_SYNC_HASH\\\"}\" $GIT_SYNC_WEBHOOK_URL'" }
How to Verify Tools in Your Container
To confirm which tools are available, exec into a running git-sync container:
docker exec -it <your-container-name> sh
Then run:
which wgetto check if wget existsbusybox --listto see if curl is included in Busybox
Final Notes
- Remove the
GIT_SYNC_WEBHOOK_URLenv var since we're using exechook instead - Your existing AWS SSM parameter config for the webhook URL looks correct—keep that in place
- Test the command manually inside the container first to debug any payload formatting issues
内容的提问来源于stack exchange,提问作者mrc

