GitLab CI/CD中Ubuntu仓库apt-get update出现GPG签名错误求助
GitLab CI/CD Ubuntu镜像apt-get update GPG签名错误排查与解决
问题背景
维护的GitLab CI/CD流水线使用Ubuntu Docker镜像,此前运行正常,近期在apt-get update步骤出现GPG签名错误,无法验证Ubuntu仓库的签名。相关CI配置及错误信息如下:
相关.gitlab-ci.yml片段
manage-releases: stage: manage-releases needs: - job: release_job image: ubuntu # 也曾尝试ubuntu:latest或特定版本,无变化 before_script: - apt-get clean # 已添加此步骤但未解决问题 - apt-get -qq update - apt-get install -y jq curl script: - sh manage_releases.sh # 执行依赖jq包的脚本
错误信息
$ apt-get clean $ apt-get -qq update W: GPG error: http://archive.ubuntu.com/ubuntu jammy InRelease: At least one invalid signature was encountered. E: The repository 'http://archive.ubuntu.com/ubuntu jammy InRelease' is not signed. W: GPG error: http://archive.ubuntu.com/ubuntu jammy-updates InRelease: At least one invalid signature was encountered. E: The repository 'http://archive.ubuntu.com/ubuntu jammy-updates InRelease' is not signed. W: GPG error: http://archive.ubuntu.com/ubuntu jammy-backports InRelease: At least one invalid signature was encountered. E: The repository 'http://archive.ubuntu.com/ubuntu jammy-backports InRelease' is not signed. W: GPG error: http://security.ubuntu.com/ubuntu jammy-security InRelease: At least one invalid signature was encountered. E: The repository 'http://security.ubuntu.com/ubuntu jammy-security InRelease' is not signed.
排查思路
- 网络环境检查:确认GitLab Runner是否存在代理、防火墙拦截,导致仓库的InRelease文件下载不完整;或DNS解析错误,请求到了错误的仓库节点。
- 镜像完整性验证:Runner可能缓存了损坏的Ubuntu镜像,尝试强制拉取最新官方镜像,而非使用本地缓存。
- 系统时间校验:GPG签名验证依赖系统时间,若容器内时间与实际时间偏差过大,会导致签名过期/未生效的判定。
- 签名本身问题:临时跳过签名验证(仅限测试),确认是否为签名文件本身的问题,而非本地验证环节错误。
解决建议
1. 同步容器系统时间
在before_script中添加时间同步步骤,修复时间偏差导致的签名验证失败:
apt-get install -y --no-install-recommends ntpdate ntpdate pool.ntp.org
2. 重新导入Ubuntu官方GPG密钥
部分情况下,镜像内的GPG密钥可能损坏或过期,手动导入对应版本的密钥:
apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 871920D1991BC93C
(上述密钥对应Ubuntu 22.04 Jammy版本的官方仓库)
3. 更换Ubuntu镜像源
官方源网络波动可能导致文件下载不完整,替换为国内稳定镜像源(如阿里云):
sed -i 's/http:\/\/archive.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list sed -i 's/http:\/\/security.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list
4. 强制拉取最新镜像
在CI配置中添加pull_policy: always,避免Runner使用缓存的损坏镜像:
image: ubuntu:jammy pull_policy: always
修改后的完整CI配置示例
manage-releases: stage: manage-releases needs: - job: release_job image: ubuntu:jammy pull_policy: always before_script: - apt-get clean - # 同步系统时间 - apt-get install -y --no-install-recommends ntpdate - ntpdate pool.ntp.org - # 导入GPG密钥 - apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 3B4FE6ACC0B21F32 871920D1991BC93C - # 更换国内镜像源(可选) - sed -i 's/http:\/\/archive.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list - sed -i 's/http:\/\/security.ubuntu.com\/ubuntu/http:\/\/mirrors.aliyun.com\/ubuntu/g' /etc/apt/sources.list - apt-get -qq update - apt-get install -y jq curl script: - sh manage_releases.sh
内容的提问来源于stack exchange,提问作者Highnoon
相关产品推荐
相关产品推荐

