VSCode开发容器如何传递AWS CodeArtifact认证令牌以安装依赖?
解决VSCode Dev Container获取AWS CodeArtifact令牌的方案
以下几个实用方案可避免繁琐脚本,轻松将CodeArtifact令牌传入容器:
方案1:通过主机环境变量传递令牌
- 主机端先获取令牌并写入环境变量:
export CODEARTIFACT_AUTH_TOKEN=$(aws codeartifact get-authorization-token --domain <你的域名> --domain-owner <你的账户ID> --query authorizationToken --output text --profile dev) - 在
devcontainer.json中配置容器环境变量,引用主机的环境变量:"containerEnv": { "CODEARTIFACT_AUTH_TOKEN": "${localEnv:CODEARTIFACT_AUTH_TOKEN}" } - 容器内安装依赖时,直接用该环境变量配置pip:
pip install --extra-index-url https://aws:$CODEARTIFACT_AUTH_TOKEN@<你的CodeArtifact仓库地址>/simple/ <你的包名>
方案2:挂载主机AWS配置,容器内直接获取令牌
将主机的AWS配置目录挂载到容器,让容器复用主机的SSO会话,无需手动传令牌:
- 在
devcontainer.json中添加挂载配置:"mounts": [ "source=${env:HOME}/.aws,target=/root/.aws,type=bind" ] - 容器内直接通过AWS CLI获取令牌,或在
pip.conf中集成:- 临时使用:
pip install --extra-index-url https://aws:$(aws codeartifact get-authorization-token --domain <你的域名> --domain-owner <你的账户ID> --query authorizationToken --output text --profile dev)@<你的CodeArtifact仓库地址>/simple/ <你的包名> - 持久化配置(容器内创建
~/.config/pip/pip.conf):[global] extra-index-url = https://aws:$(aws codeartifact get-authorization-token --domain <你的域名> --domain-owner <你的账户ID> --query authorizationToken --output text --profile dev)@<你的CodeArtifact仓库地址>/simple/
- 临时使用:
方案3:初始化命令生成令牌文件,挂载到容器
用initializeCommand在主机生成令牌文件,再挂载到容器读取:
- 在
devcontainer.json中配置初始化命令和挂载:"initializeCommand": "aws codeartifact get-authorization-token --domain <你的域名> --domain-owner <你的账户ID> --query authorizationToken --output text --profile dev > /tmp/codeartifact-token", "mounts": [ "source=/tmp/codeartifact-token,target=/tmp/codeartifact-token,type=bind" ] - 容器内读取令牌并使用:
export CODEARTIFACT_AUTH_TOKEN=$(cat /tmp/codeartifact-token) pip install --extra-index-url https://aws:$CODEARTIFACT_AUTH_TOKEN@<你的CodeArtifact仓库地址>/simple/ <你的包名>
内容的提问来源于stack exchange,提问作者Gino
相关产品推荐
相关产品推荐

