You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Google Cloud运行Tekton Pipeline遇Git权限拒绝问题求助

解决Tekton Pipeline Git Clone时的权限拒绝问题

问题场景

在Google Cloud上运行Tekton Pipeline时,git-clone任务报错无法创建.git目录,报错核心信息:

/workspace/output/.git: Permission denied

相关配置

PipelineRun配置

apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
  name: ft-common-run
  namespace: fetebird-tekton
spec:
  pipelineRef:
    name: ft-common
  workspaces:
    - name: shared-data
      persistentVolumeClaim:
        claimName: fetebird-common-pvc
  params:
    - name: repo-url
      value: git@bitbucket.org:anandjaisy/common.git
    - name: GRADLE_IMAGE
      value: docker.io/library/gradle:jdk17-alpine@sha256:e80d3108c319eaeef966eefdfd075fdaa44201c8fb6730532a16555426c61dbd
  taskRunSpecs:
    - pipelineTaskName: git-clone
      taskServiceAccountName: git-service-account
    - pipelineTaskName: clean-build-publish
      taskServiceAccountName: gcp-service-account

ClusterRoleBinding配置

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: file-system-access-binding
subjects:
  - kind: ServiceAccount
    name: gcp-service-account
    namespace: fetebird-tekton
  - kind: ServiceAccount
    name: git-service-account
    namespace: fetebird-tekton
roleRef:
  kind: ClusterRole
  name: file-system-access
  apiGroup: rbac.authorization.k8s.io

ClusterRole配置

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: file-system-access
rules:
  - apiGroups:
      - ""
    resources:
      - pods
    verbs: ["get", "list", "exec"]

问题根源

报错是文件系统权限不匹配,而非Kubernetes RBAC权限问题。当前配置的file-system-access ClusterRole针对的是Pod资源的操作权限,和PVC挂载目录的写入权限完全无关。问题出在:PVC挂载到Pod后,目录的所有者/组权限与容器内运行git-init进程的用户不匹配,导致无法创建.git目录。

解决方案

1. 为git-clone任务添加SecurityContext

在PipelineRun的taskRunSpecs中为git-clone任务配置podTemplate,设置fsGroup让容器进程拥有挂载目录的写入权限:

taskRunSpecs:
  - pipelineTaskName: git-clone
    taskServiceAccountName: git-service-account
    podTemplate:
      securityContext:
        fsGroup: 1000 # 多数Tekton git-init容器默认用1000用户组,可根据实际调整

如果是自定义git-clone Task,也可以直接在Task的steps里配置:

steps:
  - name: git-clone
    securityContext:
      runAsUser: 1000
      runAsGroup: 1000
    image: gcr.io/tekton-releases/github.com/tektoncd/pipeline/cmd/git-init:v0.44.0
    args: [...]

2. 验证PVC的访问模式

确保PVC的访问模式支持当前场景:

  • 如果多个Pod需要同时读写,用ReadWriteMany
  • 单Pod场景用ReadWriteOnce

查看PVC配置:

kubectl get pvc fetebird-common-pvc -n fetebird-tekton -o yaml

3. 移除无关的RBAC配置

当前的file-system-access ClusterRole和ClusterRoleBinding与文件系统权限无关,属于过度授权,可删除:

kubectl delete clusterrole file-system-access
kubectl delete clusterrolebinding file-system-access-binding

4. 手动验证目录权限(可选)

如果问题仍存在,进入git-clone的Pod检查目录权限:

kubectl exec -it <git-clone-pod-name> -n fetebird-tekton -- ls -ld /workspace/output

确认目录的组权限包含容器运行用户的组(比如1000),否则需要调整fsGroup的值。

内容的提问来源于stack exchange,提问作者San Jaisy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 16:34:54