如何在Jenkins的options块中为withAWS注入环境变量
问题
尝试在Jenkins Pipeline的options块中为withAWS注入环境变量,但第二个阶段使用环境变量时无法获取AWS凭证,导致访问Secrets Manager失败。以下是Pipeline代码:
pipeline { agent { docker { image 'myimage' } } environment { ROLE = 'pipeline' ACCOUNT = '1111111111' } stages { stage('Test aws') { options { withAWS(region: 'us-east-1', role: 'pipeline' , roleAccount: '1111111111') } steps { sh 'env | grep AWS' } } stage('Build TypeScript') { options { withAWS(region: 'us-east-1', role: env.ROLE, roleAccount: "${env.ACCOUNT}") } steps { sh 'env | grep AWS' sh 'env | grep ROLE' sh 'env | grep ACCOUNT' sh 'npm run create-db-schemas' sh 'npm run build' } } } }
执行日志显示:
[Pipeline] { (Test aws) [Pipeline] withAWS Setting AWS region us-east-1 Requesting assume role Assuming role ARN is arn:aws:iam::1111111111:role/pipelineAssumed role arn:aws:sts::1111111111:assumed-role/pipeline/Jenkins-PoC-credit-app- [Pipeline] { [Pipeline] sh + grep AWS + env AWS_DEFAULT_REGION=us-east-1 AWS_SESSION_TOKEN=********** AWS_REGION=us-east-1 AWS_ACCESS_KEY_ID=********** AWS_SECRET_ACCESS_KEY=********** [Pipeline] } [Pipeline] // withAWS [Pipeline] } [Pipeline] // stage [Pipeline] stage [Pipeline] { (Build TypeScript) Retrieving credentials from node. [Pipeline] withAWS Setting AWS region us-east-1 [Pipeline] { [Pipeline] sh + grep AWS + env AWS_DEFAULT_REGION=us-east-1 AWS_REGION=us-east-1 [Pipeline] sh + grep ROLE + env ROLE=pipeline [Pipeline] sh + env + grep ACCOUNT ACCOUNT=523572232308 [Pipeline] sh + npm run create-db-schemas {"level":"ERROR","message":"Problem getting secret with name domain_gateway_rds_root: Secrets Manager can't find the specified secret.","metadata":{},"timestamp":"2024-01-11T02:41:12.300Z"} /tmp/jenkins-85bb3fbc/workspace/C_credit-app_foo/node_modules/@aws-sdk/client-secrets-manager/dist-cjs/protocols/Aws_json1_1.js:1240 const exception = new models_0_1.ResourceNotFoundException({ ^ ResourceNotFoundException: Secrets Manager can't find the specified secret.
分析:
- 硬编码角色和账号的阶段能正常获取AWS凭证;
- 使用环境变量注入的阶段未获取到AWS凭证,导致访问Secrets Manager失败。
解决方案
核心原因
Jenkins声明式Pipeline中,stage的options块执行时机早于environment块的变量初始化流程,导致withAWS无法正确解析环境变量的值,进而未执行IAM角色Assume操作,没有生成有效AWS凭证。
正确实现方式
将withAWS从options块移至steps块内,确保环境变量已完全加载后再执行AWS角色切换:
pipeline { agent { docker { image 'myimage' } } environment { ROLE = 'pipeline' ACCOUNT = '1111111111' } stages { stage('Test aws') { steps { withAWS(region: 'us-east-1', role: 'pipeline', roleAccount: '1111111111') { sh 'env | grep AWS' } } } stage('Build TypeScript') { steps { withAWS(region: 'us-east-1', role: env.ROLE, roleAccount: env.ACCOUNT) { sh 'env | grep AWS' sh 'env | grep ROLE' sh 'env | grep ACCOUNT' sh 'npm run create-db-schemas' sh 'npm run build' } } } } }
替代方案(需在options块配置时)
如果必须在options块中使用AWS配置,可改用**全局参数(params)**替代environment块变量。params在Pipeline启动时即完成初始化,能被options块正确解析:
pipeline { agent { docker { image 'myimage' } } parameters { string(name: 'ROLE', defaultValue: 'pipeline', description: 'AWS IAM Role名称') string(name: 'ACCOUNT', defaultValue: '1111111111', description: 'AWS账号ID') } stages { stage('Build TypeScript') { options { withAWS(region: 'us-east-1', role: params.ROLE, roleAccount: params.ACCOUNT) } steps { sh 'env | grep AWS' sh 'npm run create-db-schemas' sh 'npm run build' } } } }
内容的提问来源于stack exchange,提问作者Christian Bongiorno
相关产品推荐
相关产品推荐

