Bitbucket Webhook触发Jenkins构建时出现403 ERR_ACCESS_DENIED问题求助
问题场景
在AWS EKS中部署Jenkins服务器,运行于私有子网的EC2实例上,前端由内部ALB提供服务。ALB安全组已允许公司VPN流量及Bitbucket官方白名单IP访问:
- 手动点击「立即构建」可正常运行
- 通过Bitbucket推送触发构建时,返回
ERR_ACCESS_DENIED 0错误,错误信息如下:
--></style>
</head><body id=ERR_ACCESS_DENIED>
<div id="titles">
<h1>ERROR</h1>
<h2>The requested URL could not be retrieved</h2>
</div>
<hr><div id="content">
<p>The following error was encountered while trying to retrieve the URL: <a href="https://jenkins-url/">https://<jenkins-url>/</a></p><blockquote id="error">
<p><b>Access Denied.</b></p>
</blockquote><p>Access control configuration prevents your request from being allowed at this time. Please contact your service provider if you feel this is incorrect.</p>
<p>Your cache administrator is <a href="mailto:webmaster">webmaster</a></p>
<br>
</div>
已完成的验证:
- 在Bitbucket创建应用密码,添加至Jenkins凭据并在Bitbucket源配置中使用;
- 检查ALB访问日志,确认源IP在白名单内且日志显示
forward = 200; - 已将Bitbucket IP入站规则添加至EC2节点、EKS集群及ALB安全组;
- 复制请求头和体在Postman发送POST请求,返回200 OK。
排查建议
1. 检查ALB与Jenkins的路径转发配置
确认ALB目标组是否将Bitbucket webhook请求的路径(如/bitbucket-hook/,取决于Jenkins Bitbucket插件配置)正确转发到Jenkins服务的对应端口(通常为8080),避免路径重写或遗漏导致的404/权限拦截。
2. 验证Jenkins Bitbucket插件及项目配置
- 检查Jenkins安装的Bitbucket插件版本是否兼容当前Jenkins版本,过时插件可能存在webhook处理逻辑异常;
- 确认Jenkins项目的Bitbucket源配置中,已勾选「Build when a change is pushed to Bitbucket」选项,且填写的webhook URL与Bitbucket仓库中配置的完全一致;
- 查看Jenkins系统日志(可通过UI的「系统日志」或服务器路径
/var/log/jenkins/jenkins.log),检查webhook请求到达后的具体错误信息,比如权限验证失败、路径不存在等。
3. 核对Bitbucket仓库的webhook细节
- 确认Bitbucket仓库中配置的webhook URL完整,包含正确的协议(https)、域名和路径;
- 检查webhook触发事件是否设置为「Repository push」或所需的触发类型;
- 查看Bitbucket的webhook历史记录(仓库设置→Webhooks→详情),获取请求的状态码、响应内容,定位更具体的错误原因。
4. 排查AWS内部额外访问控制组件
- 检查是否有AWS WAF关联到ALB,WAF规则可能误判Bitbucket请求为恶意流量并拦截;
- 确认私有子网路由表是否允许Bitbucket IP到Jenkins EC2实例的流量,避免子网内路由限制导致请求无法到达;
- 检查Jenkins所在EC2实例的本地防火墙(iptables/ufw),确认没有额外的入站规则拦截请求。
5. 对比Postman与Bitbucket请求的差异
即使Postman请求返回200,需确认:
- Postman是否使用了与Bitbucket完全一致的请求头(如
User-Agent、X-Event-Key等),Jenkins插件可能依赖这些头信息识别合法请求; - Postman是否正确传递了身份验证信息(如果Jenkins webhook需要验证),确保与Bitbucket使用的应用密码配置一致。
内容的提问来源于stack exchange,提问作者user2051904

