You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Jenkins的options块中为withAWS注入环境变量

问题

尝试在Jenkins Pipeline的options块中为withAWS注入环境变量,但第二个阶段使用环境变量时无法获取AWS凭证,导致访问Secrets Manager失败。以下是Pipeline代码:

pipeline {
    agent {
        docker {
            image 'myimage'
        }
    }
    environment {
        ROLE = 'pipeline'
        ACCOUNT = '1111111111' 
    }

    stages {

        stage('Test aws') {
            options {
                withAWS(region: 'us-east-1', role: 'pipeline' , roleAccount: '1111111111')
            }
            steps {
                sh 'env | grep AWS'
            }
        }

        stage('Build TypeScript') {
            options {
                withAWS(region: 'us-east-1', role: env.ROLE, roleAccount: "${env.ACCOUNT}")
            }
            steps {
                sh 'env | grep AWS'
                sh 'env | grep ROLE'
                sh 'env | grep ACCOUNT'
                sh 'npm run create-db-schemas'
                sh 'npm run build'
            }
        }

    }
}

执行日志显示:

[Pipeline] { (Test aws)
[Pipeline] withAWS
Setting AWS region us-east-1 
 Requesting assume role
Assuming role ARN is arn:aws:iam::1111111111:role/pipelineAssumed role arn:aws:sts::1111111111:assumed-role/pipeline/Jenkins-PoC-credit-app-
 [Pipeline] {
[Pipeline] sh
+ grep AWS
+ env
AWS_DEFAULT_REGION=us-east-1
AWS_SESSION_TOKEN=**********
AWS_REGION=us-east-1
AWS_ACCESS_KEY_ID=**********
AWS_SECRET_ACCESS_KEY=**********
[Pipeline] }
[Pipeline] // withAWS
[Pipeline] }
[Pipeline] // stage
[Pipeline] stage
[Pipeline] { (Build TypeScript)
Retrieving credentials from node.
[Pipeline] withAWS
Setting AWS region us-east-1 
 [Pipeline] {
[Pipeline] sh
+ grep AWS
+ env
AWS_DEFAULT_REGION=us-east-1
AWS_REGION=us-east-1
[Pipeline] sh
+ grep ROLE
+ env
ROLE=pipeline
[Pipeline] sh
+ env
+ grep ACCOUNT
ACCOUNT=523572232308
[Pipeline] sh
+ npm run create-db-schemas

{"level":"ERROR","message":"Problem getting secret with name domain_gateway_rds_root: Secrets Manager can't find the specified secret.","metadata":{},"timestamp":"2024-01-11T02:41:12.300Z"}
/tmp/jenkins-85bb3fbc/workspace/C_credit-app_foo/node_modules/@aws-sdk/client-secrets-manager/dist-cjs/protocols/Aws_json1_1.js:1240
    const exception = new models_0_1.ResourceNotFoundException({
                      ^


ResourceNotFoundException: Secrets Manager can't find the specified secret.

分析:

  • 硬编码角色和账号的阶段能正常获取AWS凭证;
  • 使用环境变量注入的阶段未获取到AWS凭证,导致访问Secrets Manager失败。

解决方案

核心原因

Jenkins声明式Pipeline中,stage的options块执行时机早于environment块的变量初始化流程,导致withAWS无法正确解析环境变量的值,进而未执行IAM角色Assume操作,没有生成有效AWS凭证。

正确实现方式

将withAWS从options块移至steps块内,确保环境变量已完全加载后再执行AWS角色切换:

pipeline {
    agent {
        docker {
            image 'myimage'
        }
    }
    environment {
        ROLE = 'pipeline'
        ACCOUNT = '1111111111' 
    }

    stages {
        stage('Test aws') {
            steps {
                withAWS(region: 'us-east-1', role: 'pipeline', roleAccount: '1111111111') {
                    sh 'env | grep AWS'
                }
            }
        }

        stage('Build TypeScript') {
            steps {
                withAWS(region: 'us-east-1', role: env.ROLE, roleAccount: env.ACCOUNT) {
                    sh 'env | grep AWS'
                    sh 'env | grep ROLE'
                    sh 'env | grep ACCOUNT'
                    sh 'npm run create-db-schemas'
                    sh 'npm run build'
                }
            }
        }
    }
}

替代方案(需在options块配置时)

如果必须在options块中使用AWS配置,可改用**全局参数(params)**替代environment块变量。params在Pipeline启动时即完成初始化,能被options块正确解析:

pipeline {
    agent {
        docker {
            image 'myimage'
        }
    }
    parameters {
        string(name: 'ROLE', defaultValue: 'pipeline', description: 'AWS IAM Role名称')
        string(name: 'ACCOUNT', defaultValue: '1111111111', description: 'AWS账号ID')
    }

    stages {
        stage('Build TypeScript') {
            options {
                withAWS(region: 'us-east-1', role: params.ROLE, roleAccount: params.ACCOUNT)
            }
            steps {
                sh 'env | grep AWS'
                sh 'npm run create-db-schemas'
                sh 'npm run build'
            }
        }
    }
}

内容的提问来源于stack exchange,提问作者Christian Bongiorno

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 09:05:41