GitLab-CI中Buildah构建镜像后Trivy扫描失败如何排查修复?
问题分析与修复:GitLab-CI中Buildah构建镜像后Trivy扫描失败
问题场景
使用buildah:v3.1镜像运行GitLab-CI流水线,实现从Dockerfile构建镜像、Trivy扫描后推送到私有镜像仓库。拉取已有镜像扫描推送正常,但自定义构建的镜像扫描时出错。
原脚本
if gcloud artifacts docker images list $DOCKER_REGISTRY/$image --include-tags | grep -q $version; then echo "Image $image:$version already exists in the repository. Skipping build and push." else cd $path; buildah build -t $DOCKER_REGISTRY/$image:$version .; echo "Image : $DOCKER_REGISTRY/$image:$version" # Scan the image with Trivy and set exit code 1 for critical vulnerabilities trivy image --severity CRITICAL --exit-code 1 --no-progress $DOCKER_REGISTRY/$image:$version if [ $? -eq 0 ]; then # Push the image to the Docker registry using Buildah buildah push "$DOCKER_REGISTRY/$repository:$tag" echo "buildah push "$DOCKER_REGISTRY/$image:$version"" echo "Image $image:$version has been pushed to the artifact registry" else echo "Image $image:$version contains critical vulnerabilities. Skipping build and push." fi fi
报错信息
2023-09-19T05:35:27.513Z INFO Need to update DB 2023-09-19T05:35:27.514Z INFO Downloading DB... 2023-09-19T05:35:32.992Z FATAL scan error: unable to initialize a scanner: unable to initialize a docker scanner: 3 errors occurred: * unable to inspect the image (asia-west-docker.pkg.dev/v2/project-circles/dataplatform/buildah-image:1.0.1): Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running? * unable to initialize Podman client: no podman socket found: stat podman/podman.sock: no such file or directory * GET https://asia-west-docker.pkg.dev/v2/project-circles/dataplatform/buildah-image/manifests/1.0.1: MANIFEST_UNKNOWN: Failed to fetch "1.0.1"
报错原因分析
- Docker/Podman环境缺失:
buildah:v3.1镜像未内置Docker daemon或Podman,Trivy默认尝试通过这两种方式读取镜像,自然失败。 - 镜像未推送至远程仓库:Buildah构建的镜像仅保存在本地容器存储中,尚未推送至私有仓库,Trivy尝试远程拉取时找不到对应镜像。
- 脚本变量错误:推送命令中使用了未定义的
$repository:$tag变量,与构建时的$image:$version不匹配,会导致推送失败。
修复方案
1. 让Trivy直接扫描Buildah本地存储的镜像
添加--storage buildah参数,指定Trivy使用Buildah存储驱动读取本地构建的镜像:
trivy image --severity CRITICAL --exit-code 1 --no-progress --storage buildah $DOCKER_REGISTRY/$image:$version
2. 修正推送命令的变量错误
将推送命令中的变量统一为$image:$version:
buildah push "$DOCKER_REGISTRY/$image:$version"
完整修复后的脚本
if gcloud artifacts docker images list $DOCKER_REGISTRY/$image --include-tags | grep -q $version; then echo "Image $image:$version already exists in the repository. Skipping build and push." else cd $path; buildah build -t $DOCKER_REGISTRY/$image:$version .; echo "Image : $DOCKER_REGISTRY/$image:$version" # Scan the image with Trivy using Buildah storage driver trivy image --severity CRITICAL --exit-code 1 --no-progress --storage buildah $DOCKER_REGISTRY/$image:$version if [ $? -eq 0 ]; then # Push the image to the Docker registry using Buildah buildah push "$DOCKER_REGISTRY/$image:$version" echo "Pushed image: $DOCKER_REGISTRY/$image:$version" echo "Image $image:$version has been pushed to the artifact registry" else echo "Image $image:$version contains critical vulnerabilities. Skipping push." fi fi
内容的提问来源于stack exchange,提问作者LARA
相关产品推荐
相关产品推荐

