在Google Cloud运行Tekton Pipeline遇Git权限拒绝问题求助
解决Tekton Pipeline Git Clone时的权限拒绝问题
问题场景
在Google Cloud上运行Tekton Pipeline时,git-clone任务报错无法创建.git目录,报错核心信息:
/workspace/output/.git: Permission denied
相关配置
PipelineRun配置
apiVersion: tekton.dev/v1beta1 kind: PipelineRun metadata: name: ft-common-run namespace: fetebird-tekton spec: pipelineRef: name: ft-common workspaces: - name: shared-data persistentVolumeClaim: claimName: fetebird-common-pvc params: - name: repo-url value: git@bitbucket.org:anandjaisy/common.git - name: GRADLE_IMAGE value: docker.io/library/gradle:jdk17-alpine@sha256:e80d3108c319eaeef966eefdfd075fdaa44201c8fb6730532a16555426c61dbd taskRunSpecs: - pipelineTaskName: git-clone taskServiceAccountName: git-service-account - pipelineTaskName: clean-build-publish taskServiceAccountName: gcp-service-account
ClusterRoleBinding配置
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: file-system-access-binding subjects: - kind: ServiceAccount name: gcp-service-account namespace: fetebird-tekton - kind: ServiceAccount name: git-service-account namespace: fetebird-tekton roleRef: kind: ClusterRole name: file-system-access apiGroup: rbac.authorization.k8s.io
ClusterRole配置
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: file-system-access rules: - apiGroups: - "" resources: - pods verbs: ["get", "list", "exec"]
问题根源
报错是文件系统权限不匹配,而非Kubernetes RBAC权限问题。当前配置的file-system-access ClusterRole针对的是Pod资源的操作权限,和PVC挂载目录的写入权限完全无关。问题出在:PVC挂载到Pod后,目录的所有者/组权限与容器内运行git-init进程的用户不匹配,导致无法创建.git目录。
解决方案
1. 为git-clone任务添加SecurityContext
在PipelineRun的taskRunSpecs中为git-clone任务配置podTemplate,设置fsGroup让容器进程拥有挂载目录的写入权限:
taskRunSpecs: - pipelineTaskName: git-clone taskServiceAccountName: git-service-account podTemplate: securityContext: fsGroup: 1000 # 多数Tekton git-init容器默认用1000用户组,可根据实际调整
如果是自定义git-clone Task,也可以直接在Task的steps里配置:
steps: - name: git-clone securityContext: runAsUser: 1000 runAsGroup: 1000 image: gcr.io/tekton-releases/github.com/tektoncd/pipeline/cmd/git-init:v0.44.0 args: [...]
2. 验证PVC的访问模式
确保PVC的访问模式支持当前场景:
- 如果多个Pod需要同时读写,用
ReadWriteMany - 单Pod场景用
ReadWriteOnce
查看PVC配置:
kubectl get pvc fetebird-common-pvc -n fetebird-tekton -o yaml
3. 移除无关的RBAC配置
当前的file-system-access ClusterRole和ClusterRoleBinding与文件系统权限无关,属于过度授权,可删除:
kubectl delete clusterrole file-system-access kubectl delete clusterrolebinding file-system-access-binding
4. 手动验证目录权限(可选)
如果问题仍存在,进入git-clone的Pod检查目录权限:
kubectl exec -it <git-clone-pod-name> -n fetebird-tekton -- ls -ld /workspace/output
确认目录的组权限包含容器运行用户的组(比如1000),否则需要调整fsGroup的值。
内容的提问来源于stack exchange,提问作者San Jaisy
相关产品推荐
相关产品推荐

