You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS ECS Fargate部署Jenkins遇Git SCM Error 128问题求助

问题:AWS ECS上Jenkins拉取GitHub仓库报Error 128(可疑所有权)

现象

在AWS ECS上部署官方Jenkins Docker镜像,ECS代理运行正常,但流水线拉取GitHub仓库脚本时持续返回Error 128。HTTPS和SSH凭证均验证通过,直接在容器内克隆仓库可成功,排除网络问题。

Jenkins执行流水线时,会在主节点工作目录下创建trigger-gitlab-deploy@script目录,其中包含随机ID命名的子目录(如42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9),该子目录内的.git文件夹无配置文件。此前在Kubernetes集群部署同类Jenkins按需代理可正常运行,提升日志级别后仍未定位原因。

错误日志

Started by user user-admin
Checking out git https://github.com/project/project-jenkins.git/ into /var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9 to read jobs/trigger-gitlab-deploy/Jenkinsfile
Selected Git installation does not exist. Using Default
The recommended git tool is: NONE
using credential toto-ci-github
Cloning the remote Git repository
Cloning repository https://github.com/totonow/toto-jenkins.git/
 > git init /var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9 # timeout=10
Fetching upstream changes from https://github.com/totonow/toto-jenkins.git/
 > git --version # timeout=10
 > git --version # 'git version 2.30.2'
using GIT_ASKPASS to set credentials Credentials use to pull jenkinsfile from github
 > git fetch --tags --force --progress -- https://github.com/totonow/toto-jenkins.git/ +refs/heads/*:refs/remotes/origin/* # timeout=10
ERROR: Error cloning remote repo 'origin'
hudson.plugins.git.GitException: Command "git fetch --tags --force --progress -- https://github.com/totonow/toto-jenkins.git/ +refs/heads/*:refs/remotes/origin/*" returned status code 128:
stdout: 
stderr: fatal: detected dubious ownership in repository at '/var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9'
To add an exception for this directory, call:

    git config --global --add safe.directory /var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9

    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandIn(CliGitAPIImpl.java:2842)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandWithCredentials(CliGitAPIImpl.java:2185)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:635)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$2.execute(CliGitAPIImpl.java:871)
    at hudson.plugins.git.GitSCM.retrieveChanges(GitSCM.java:1222)
    at hudson.plugins.git.GitSCM.checkout(GitSCM.java:1305)
    at org.jenkinsci.plugins.workflow.steps.scm.SCMStep.checkout(SCMStep.java:129)
    at org.jenkinsci.plugins.workflow.cps.CpsScmFlowDefinition.create(CpsScmFlowDefinition.java:159)
    at org.jenkinsci.plugins.workflow.cps.CpsScmFlowDefinition.create(CpsScmFlowDefinition.java:70)
    at org.jenkinsci.plugins.workflow.job.WorkflowRun.run(WorkflowRun.java:312)
    at hudson.model.ResourceController.execute(ResourceController.java:101)
    at hudson.model.Executor.run(Executor.java:442)
ERROR: Error cloning remote repo 'origin'
ERROR: Maximum checkout retry attempts reached, aborting
Finished: FAILURE

已尝试操作

  • 执行git config --global --add safe.directory '*',问题依旧

排查方向与解决方案

1. 确认Git全局配置的生效范围

执行git config --global --add safe.directory '*'后,需确保Jenkins进程使用的用户(通常是jenkins用户)能读取该配置。可通过ECS exec进入容器,切换到jenkins用户再执行该命令:

su - jenkins
git config --global --add safe.directory '*'

2. 修改Jenkins全局Git配置

在Jenkins管理界面中,进入Manage Jenkins > Global Tool Configuration > Git,在"Additional behaviour"中添加自定义Git配置项:

  • 键:safe.directory
  • 值:*

3. 调整容器内目录权限

Jenkins工作目录/var/jenkins_home的所有权需为jenkins:jenkins,可在ECS任务定义的启动命令中添加初始化逻辑:

chown -R jenkins:jenkins /var/jenkins_home && exec /usr/local/bin/jenkins.sh

4. 升级Git版本

当前使用的Git版本为2.30.2,该版本对可疑所有权的检测逻辑较严格。可尝试升级容器内的Git版本,或在Jenkins中配置使用更高版本的Git工具。

5. 配置Jenkins流水线的SCM行为

在流水线的SCM配置中,添加"Advanced clone behaviours",调整克隆策略(如启用浅克隆),避免Git触发所有权检测机制。

内容的提问来源于stack exchange,提问作者obasso99

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 21:13:28