You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自托管Runner上Sonar问题:无法同时使用npm覆盖率与Docker

自托管Runner上GitHub Actions执行SonarQube扫描遇Docker权限问题的解决建议

问题场景

在自托管Runner上执行GitHub Actions流程时,依次执行actions/setup-node、actions/checkout、npm install、npm run coverage后,运行SonarQube扫描动作出现Docker错误:

docker: Error response from daemon: pull access denied for 6cd1db, repository does not exist or may require 'docker login': denied: requested access to the resource is denied.

移除checkout和npm相关命令后,流程可正常运行。涉及的build.yml配置如下:

name: Build

on:
  push:
    branches:
      - main
  pull_request:
    types: [opened, synchronize, reopened]
jobs:
  build:
    name: Sonar Scan
    runs-on:
      - self-hosted
    steps:
      - uses: actions/setup-node@v3
        with:
          node-version: 16.15.0
      - uses: actions/checkout@v2
        with:
          fetch-depth: 0  # Shallow clones should be disabled for a better relevancy of analysis
      - run: npm install
      - run: npm run coverage
      - uses: sonarsource/sonarqube-scan-action@master
        env:
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
          SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
      # If you wish to fail your job when the Quality Gate is red, uncomment the
      # following lines. This would typically be used to fail a deployment.
      # We do not recommend to use this in a pull request. Prefer using pull request
      # decoration instead.
      - uses: sonarsource/sonarqube-quality-gate-action@master
        timeout-minutes: 5
        env:
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

解决建议

  • 检查自托管Runner的Docker权限与上下文
    代码checkout后工作目录切换至仓库路径,可能导致Docker镜像拉取的上下文被干扰。确认Runner用户拥有Docker操作权限,必要时在Sonar扫描步骤前重新登录Docker(若使用私有镜像仓库):

    docker login <私有镜像仓库地址> --username ${{ secrets.DOCKER_USERNAME }} --password ${{ secrets.DOCKER_PASSWORD }}
    

    同时检查仓库目录下是否存在.docker/config.json等文件,若有则删除以避免覆盖Runner的Docker配置:

    rm -rf .docker || true
    
  • 锁定SonarQube Action的稳定版本
    当前使用的master分支属于开发分支,可能存在兼容性问题。替换为指定的稳定版本,例如:

    - uses: sonarsource/sonarqube-scan-action@v1.1.0
      env:
        SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
        SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
    - uses: sonarsource/sonarqube-quality-gate-action@v1.0.0
      timeout-minutes: 5
      env:
        SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
    
  • 排查npm脚本对环境变量的影响
    npm run coverage可能修改了PATH或其他环境变量,导致Docker命令执行路径异常。在Sonar扫描步骤前重置环境变量或显式指定Docker绝对路径:

    export PATH=/usr/bin:$PATH # 根据Runner实际Docker路径调整
    
  • 清理工作目录的Docker相关配置文件
    若仓库中存在docker-compose.yml或其他Docker配置文件,可能导致Sonar Action误读镜像配置。在Sonar扫描前添加清理命令:

    rm -f docker-compose.yml dockerfile || true
    

内容的提问来源于stack exchange,提问作者Guilherme Cruz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 20:25:54