Azure流水线推送镜像至AWS ECR时遇sourceImageId必填错误求助
关于Azure流水线推送AWS ECR时出现
sourceImageId必填错误的问题 运行Azure流水线推送镜像至AWS ECR环节时,触发如下错误:##[error]Error: Input required: sourceImageId
已排查配置但未定位根源,以下是环境配置详情:
azure-pipelines.yml 配置
trigger: - Development resources: - repo: self pool: vmImage: ubuntu-latest variables: - group: Development stages: - template: templates/buildAndPush_identityapi.yml - template: templates/buildAndPush_administrationapi.yml
buildAndPush_identityapi.yml 配置
错误发生在ECRPushImage@1任务环节:
stages: - stage: Docker_Identity_API displayName: 'Build and Push Identity API image to AWS ECR' jobs: - job: Build_and_Push displayName: 'Build and push docker image' steps: - task: Docker@2 displayName: 'Build an Image' inputs: command: build dockerfile: '$(IDENTITY_API_PATH)/Dockerfile' buildContext: '$(Build.SourcesDirectory)' repository: $(DOCKER_REPOSITORY) - task: ECRPushImage@1 inputs: awsCredentails: $(aws_ecr_service_connection) regionName: $(AWS_REGION) imageSource: 'gajisoftidentityapi' sourceImageName: '$(DOCKER_REPOSITORY)' sourceImageTag: $(Build.BuildId) pushTag: latest repositoryName: $(DOCKER_REPOSITORY_NAME)
ECR用户权限配置
{ "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "ecr:PutImageTagMutability", "ecr:GetDownloadUrlForLayer", "ecr:ListTagsForResource", "ecr:UploadLayerPart", "ecr:ListImages", "ecr:PutImage", "ecr:BatchGetImage", "ecr:CompleteLayerUpload", "ecr:DescribeImages", "ecr:TagResource", "ecr:DescribeRepositories", "ecr:InitiateLayerUpload", "ecr:BatchCheckLayerAvailability", "ecr:GetRepositoryPolicy" ], "Resource": "arn:aws:ecr:eu-north-1:xxxxxx:repository/xxxxx-xxx" }, { "Sid": "VisualEditor1", "Effect": "Allow", "Action": [ "ecr:CreateRepository", "ecr:DescribeRegistry", "ecr:GetAuthorizationToken" ], "Resource": "*" } ] }
问题原因及解决步骤
imageSource参数配置错误:ECRPushImage@1任务的imageSource仅支持预设值(docker、imageid、ecr),你当前设置为自定义值gajisoftidentityapi,导致任务无法识别镜像来源方式,进而触发sourceImageId必填提示。
由于你是从本地Docker构建的镜像推送,需将imageSource修改为docker:imageSource: 'docker'修复拼写错误:
任务中的awsCredentails存在拼写错误,正确应为awsCredentials(缺少字母l),修正后才能正常读取AWS服务连接配置:awsCredentials: $(aws_ecr_service_connection)
完成以上修改后,重新运行流水线即可解决该错误。
内容的提问来源于stack exchange,提问作者Programmer In The Making
相关产品推荐
相关产品推荐

