You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab CI/CD中Ubuntu仓库apt-get update出现GPG签名错误求助

GitLab CI/CD Ubuntu镜像apt-get update GPG签名错误排查与解决

问题背景

维护的GitLab CI/CD流水线使用Ubuntu Docker镜像,此前运行正常,近期在apt-get update步骤出现GPG签名错误,无法验证Ubuntu仓库的签名。相关CI配置及错误信息如下:

相关.gitlab-ci.yml片段

manage-releases:
  stage: manage-releases
  needs:
    - job: release_job
  image: ubuntu # 也曾尝试ubuntu:latest或特定版本,无变化
  before_script:
    - apt-get clean # 已添加此步骤但未解决问题
    - apt-get -qq update
    - apt-get install -y jq curl
  script:
    - sh manage_releases.sh # 执行依赖jq包的脚本

错误信息

$ apt-get clean
$ apt-get -qq update
W: GPG error: http://archive.ubuntu.com/ubuntu jammy InRelease: At least one invalid signature was encountered.
E: The repository 'http://archive.ubuntu.com/ubuntu jammy InRelease' is not signed.
W: GPG error: http://archive.ubuntu.com/ubuntu jammy-updates InRelease: At least one invalid signature was encountered.
E: The repository 'http://archive.ubuntu.com/ubuntu jammy-updates InRelease' is not signed.
W: GPG error: http://archive.ubuntu.com/ubuntu jammy-backports InRelease: At least one invalid signature was encountered.
E: The repository 'http://archive.ubuntu.com/ubuntu jammy-backports InRelease' is not signed.
W: GPG error: http://security.ubuntu.com/ubuntu jammy-security InRelease: At least one invalid signature was encountered.
E: The repository 'http://security.ubuntu.com/ubuntu jammy-security InRelease' is not signed.

排查思路

  • 网络环境检查:确认GitLab Runner是否存在代理、防火墙拦截,导致仓库的InRelease文件下载不完整;或DNS解析错误,请求到了错误的仓库节点。
  • 镜像完整性验证:Runner可能缓存了损坏的Ubuntu镜像,尝试强制拉取最新官方镜像,而非使用本地缓存。
  • 系统时间校验:GPG签名验证依赖系统时间,若容器内时间与实际时间偏差过大,会导致签名过期/未生效的判定。
  • 签名本身问题:临时跳过签名验证(仅限测试),确认是否为签名文件本身的问题,而非本地验证环节错误。

解决建议

1. 同步容器系统时间

在before_script中添加时间同步步骤,修复时间偏差导致的签名验证失败:

apt-get install -y --no-install-recommends ntpdate
ntpdate pool.ntp.org

2. 重新导入Ubuntu官方GPG密钥

部分情况下,镜像内的GPG密钥可能损坏或过期,手动导入对应版本的密钥:

apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 871920D1991BC93C

(上述密钥对应Ubuntu 22.04 Jammy版本的官方仓库)

3. 更换Ubuntu镜像源

官方源网络波动可能导致文件下载不完整,替换为国内稳定镜像源(如阿里云):

sed -i 's/http:\/\/archive.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list
sed -i 's/http:\/\/security.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list

4. 强制拉取最新镜像

在CI配置中添加pull_policy: always,避免Runner使用缓存的损坏镜像:

image: ubuntu:jammy
pull_policy: always

修改后的完整CI配置示例

manage-releases:
  stage: manage-releases
  needs:
    - job: release_job
  image: ubuntu:jammy
  pull_policy: always
  before_script:
    - apt-get clean
    - # 同步系统时间
    - apt-get install -y --no-install-recommends ntpdate
    - ntpdate pool.ntp.org
    - # 导入GPG密钥
    - apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 871920D1991BC93C
    - # 更换国内镜像源(可选)
    - sed -i 's/http:\/\/archive.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list
    - sed -i 's/http:\/\/security.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list
    - apt-get -qq update
    - apt-get install -y jq curl
  script:
    - sh manage_releases.sh

内容的提问来源于stack exchange,提问作者Highnoon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 02:22:47