GitLab Runner因自签名TLS证书无法完成注册
解决Helm部署GitLab Runner时自签名TLS证书导致的注册失败问题
问题场景
通过Helm部署GitLab Runner后,因GitLab实例使用自签名TLS证书,Runner注册过程中无法通过证书验证,最终注册失败,日志中出现x509: certificate signed by unknown authority类错误(日志内容见下方)。
解决方案
方法一:让Runner信任自签名证书(推荐生产环境)
获取GitLab自签名证书
从GitLab服务器导出证书,或通过浏览器访问GitLab地址后下载证书文件(保存为gitlab.labo.bi.crt)。创建Kubernetes Secret存储证书
在Runner部署的命名空间下创建Secret:kubectl create secret generic gitlab-runner-certs --from-file=gitlab.labo.bi.crt=/本地证书路径/gitlab.labo.bi.crt -n <你的命名空间>修改Helm values配置
更新values.yaml,添加证书挂载和相关配置:runners: config: | [[runners]] [runners.kubernetes] [runners.cache] [runners.cache.s3] [runners.cache.gcs] [runners.cache.azure] # 指定证书Secret tls: ca: gitlab-runner-certs:gitlab.labo.bi.crt env: - name: GITLAB_SERVER_URL value: "https://gitlab.labo.bi" - name: REGISTRATION_TOKEN value: "<你的GitLab注册令牌>"重新部署Runner
helm upgrade --install gitlab-runner gitlab/gitlab-runner -n <你的命名空间> -f values.yaml
方法二:临时跳过TLS证书验证(仅测试环境用)
如果是测试场景,可直接配置Runner跳过证书验证:
修改values.yaml:
runners: config: | [[runners]] [runners.kubernetes] [runners.cache] [runners.cache.s3] [runners.cache.gcs] [runners.cache.azure] # 开启不安全模式跳过验证 [runners.tls] insecure = true env: - name: GITLAB_SERVER_URL value: "https://gitlab.labo.bi" - name: REGISTRATION_TOKEN value: "<你的GitLab注册令牌>"
执行重新部署命令即可。
错误日志
│ ERROR: Registering runner... failed runner=Ucz-6Xdm status=couldn't execute POST against https://gitlab.labo.bi/api/v4/runners: Post "https://gitlab.labo.bi/api/v4/runners": tls: failed to verify certificate: x509: cer │ │ PANIC: Failed to register the runner. │ │ Registration attempt 30 of 30 │ │ Runtime platform arch=amd64 os=linux pid=881 revision=8ec04662 version=16.3.0 │ │ WARNING: Running in user-mode. │ │ WARNING: The user-mode requires you to manually start builds processing: │ │ WARNING: $ gitlab-runner run │ │ WARNING: Use sudo for system-mode: │ │ WARNING: $ sudo gitlab-runner... │ │ │ │ Created missing unique system ID system_id=r_Mm32Us39x7mz │ │ WARNING: Couldn't save new system ID on state file. In order to reliably identify this runner in jobs with a known identifier, │ │ please ensure there is a text file at the location specified in `state_file` with the contents of `system_id`. Example: echo "r_Mm32Us39x7mz" > "/nonexistent/.gitlab-runner/.runner_system_id" │ │ state_file=/nonexistent/.gitlab-runner/.runner_system_id system_id=r_Mm32Us39x7mz │ │ Merging configuration from template file "/configmaps/config.template.toml" │ │ WARNING: Support for registration tokens and runner parameters in the 'register' command has been deprecated in GitLab Runner 15.6 and will be replaced with support for authentication tokens. For more information, see https://gitlab.c │ │ ERROR: Registering runner... failed runner=Ucz-6Xdm status=couldn't execute POST against https://gitlab.labo.bi/api/v4/runners: Post "https://gitlab.labo.bi/api/v4/runners": tls: failed to verify certificate: x509: cer │ │ PANIC: Failed to register the runner.
内容的提问来源于stack exchange,提问作者Guillaume
相关产品推荐
相关产品推荐

