You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab-CI中Buildah构建镜像后Trivy扫描失败如何排查修复?

问题分析与修复:GitLab-CI中Buildah构建镜像后Trivy扫描失败

问题场景

使用buildah:v3.1镜像运行GitLab-CI流水线,实现从Dockerfile构建镜像、Trivy扫描后推送到私有镜像仓库。拉取已有镜像扫描推送正常,但自定义构建的镜像扫描时出错。

原脚本

if gcloud artifacts docker images list $DOCKER_REGISTRY/$image --include-tags | grep -q $version; then
    echo "Image $image:$version already exists in the repository. Skipping build and push."
else
  cd $path;
  buildah build -t $DOCKER_REGISTRY/$image:$version .;
  echo "Image : $DOCKER_REGISTRY/$image:$version"

  # Scan the image with Trivy and set exit code 1 for critical vulnerabilities
  trivy image --severity CRITICAL --exit-code 1 --no-progress $DOCKER_REGISTRY/$image:$version

  if [ $? -eq 0 ]; then
    # Push the image to the Docker registry using Buildah
    buildah push "$DOCKER_REGISTRY/$repository:$tag"
    echo "buildah push "$DOCKER_REGISTRY/$image:$version""

    echo "Image $image:$version has been pushed to the artifact registry"
  else
    echo "Image $image:$version contains critical vulnerabilities. Skipping build and push."
  fi
fi

报错信息

2023-09-19T05:35:27.513Z    INFO    Need to update DB
2023-09-19T05:35:27.514Z    INFO    Downloading DB...
2023-09-19T05:35:32.992Z    FATAL   scan error: unable to initialize a scanner: unable to initialize a docker scanner: 3 errors occurred:
* unable to inspect the image (asia-west-docker.pkg.dev/v2/project-circles/dataplatform/buildah-image:1.0.1): Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
* unable to initialize Podman client: no podman socket found: stat podman/podman.sock: no such file or directory
* GET https://asia-west-docker.pkg.dev/v2/project-circles/dataplatform/buildah-image/manifests/1.0.1: MANIFEST_UNKNOWN: Failed to fetch "1.0.1"

报错原因分析

  1. Docker/Podman环境缺失:buildah:v3.1镜像未内置Docker daemon或Podman,Trivy默认尝试通过这两种方式读取镜像,自然失败。
  2. 镜像未推送至远程仓库:Buildah构建的镜像仅保存在本地容器存储中,尚未推送至私有仓库,Trivy尝试远程拉取时找不到对应镜像。
  3. 脚本变量错误:推送命令中使用了未定义的$repository:$tag变量,与构建时的$image:$version不匹配,会导致推送失败。

修复方案

1. 让Trivy直接扫描Buildah本地存储的镜像

添加--storage buildah参数,指定Trivy使用Buildah存储驱动读取本地构建的镜像:

trivy image --severity CRITICAL --exit-code 1 --no-progress --storage buildah $DOCKER_REGISTRY/$image:$version

2. 修正推送命令的变量错误

将推送命令中的变量统一为$image:$version:

buildah push "$DOCKER_REGISTRY/$image:$version"

完整修复后的脚本

if gcloud artifacts docker images list $DOCKER_REGISTRY/$image --include-tags | grep -q $version; then
    echo "Image $image:$version already exists in the repository. Skipping build and push."
else
  cd $path;
  buildah build -t $DOCKER_REGISTRY/$image:$version .;
  echo "Image : $DOCKER_REGISTRY/$image:$version"

  # Scan the image with Trivy using Buildah storage driver
  trivy image --severity CRITICAL --exit-code 1 --no-progress --storage buildah $DOCKER_REGISTRY/$image:$version

  if [ $? -eq 0 ]; then
    # Push the image to the Docker registry using Buildah
    buildah push "$DOCKER_REGISTRY/$image:$version"
    echo "Pushed image: $DOCKER_REGISTRY/$image:$version"

    echo "Image $image:$version has been pushed to the artifact registry"
  else
    echo "Image $image:$version contains critical vulnerabilities. Skipping push."
  fi
fi

内容的提问来源于stack exchange,提问作者LARA

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 15:10:20