You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins访问GCP私有镜像仓库的认证问题排查

解决Jenkins K8s节点拉取GCR私有镜像的认证问题

问题核心:拉取私有镜像的认证是Kubernetes在创建Pod阶段完成的,你当前在容器启动后执行的gcloud auth操作,赶不上镜像拉取的时机,导致K8s无权限访问GCR私有仓库,触发"仓库不存在"的错误。

步骤1:创建GCR镜像拉取密钥(ImagePullSecret)

先在K8s集群中配置用于拉取GCR私有镜像的密钥:

  1. 准备好拥有storage.objectViewer或Artifact Registry Reader权限的GCP服务账号密钥文件(如gcp-sa-key.json)。
  2. 执行命令创建Secret:
kubectl create secret docker-registry gcr-secret \
  --docker-server=gcr.io \
  --docker-username=_json_key \
  --docker-password="$(cat gcp-sa-key.json)" \
  --docker-email=any@example.com
  1. 把该Secret关联到Jenkins使用的ServiceAccount(假设为jenkins),确保Jenkins创建的Pod自动继承密钥权限:
kubectl patch serviceaccount jenkins -p '{"imagePullSecrets": [{"name": "gcr-secret"}]}'

步骤2:修改Jenkins Pipeline配置

更新podTemplate添加镜像拉取密钥,同时修正容器内的认证命令错误:

podTemplate(
  containers: [
    containerTemplate(
      name: 'gcp', 
      image: 'gcr.io/my_project_id/my_image:latest',
      command: 'sleep',
      args: '99d'
    )
  ],
  imagePullSecrets: [secretName: 'gcr-secret'] // 新增:指定拉取镜像用的密钥
) {
  node(POD_LABEL) {
    stage('Testing access to GCP') {
      container('gcp') {
        withCredentials([file(credentialsId: 'gcp-sa-key', variable: 'GOOGLE_APPLICATION_CREDENTIALS')]) {
          stage('Shell Execution') {
            // 修正变量错误,直接用挂载的密钥文件激活账号
            sh 'gcloud auth activate-service-account --key-file "${GOOGLE_APPLICATION_CREDENTIALS}"'
            // 可选:添加GCR访问测试命令
            sh 'gcloud container images list --repository=gcr.io/my_project_id'
          }
        }
      }
    }
  }
}

额外注意事项

  • 如果使用区域GCR仓库(如eu.gcr.io),需将--docker-server改为对应区域地址。
  • 确认GCP服务账号的权限覆盖目标镜像所在的项目仓库。

内容的提问来源于stack exchange,提问作者marcus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 12:52:33