AWS ECS Fargate部署Jenkins遇Git SCM Error 128问题求助
现象
在AWS ECS上部署官方Jenkins Docker镜像,ECS代理运行正常,但流水线拉取GitHub仓库脚本时持续返回Error 128。HTTPS和SSH凭证均验证通过,直接在容器内克隆仓库可成功,排除网络问题。
Jenkins执行流水线时,会在主节点工作目录下创建trigger-gitlab-deploy@script目录,其中包含随机ID命名的子目录(如42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9),该子目录内的.git文件夹无配置文件。此前在Kubernetes集群部署同类Jenkins按需代理可正常运行,提升日志级别后仍未定位原因。
错误日志
Started by user user-admin Checking out git https://github.com/project/project-jenkins.git/ into /var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9 to read jobs/trigger-gitlab-deploy/Jenkinsfile Selected Git installation does not exist. Using Default The recommended git tool is: NONE using credential toto-ci-github Cloning the remote Git repository Cloning repository https://github.com/totonow/toto-jenkins.git/ > git init /var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9 # timeout=10 Fetching upstream changes from https://github.com/totonow/toto-jenkins.git/ > git --version # timeout=10 > git --version # 'git version 2.30.2' using GIT_ASKPASS to set credentials Credentials use to pull jenkinsfile from github > git fetch --tags --force --progress -- https://github.com/totonow/toto-jenkins.git/ +refs/heads/*:refs/remotes/origin/* # timeout=10 ERROR: Error cloning remote repo 'origin' hudson.plugins.git.GitException: Command "git fetch --tags --force --progress -- https://github.com/totonow/toto-jenkins.git/ +refs/heads/*:refs/remotes/origin/*" returned status code 128: stdout: stderr: fatal: detected dubious ownership in repository at '/var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9' To add an exception for this directory, call: git config --global --add safe.directory /var/jenkins_home/workspace/trigger-gitlab-deploy@script/42b7b18e861df0b75ee35873b425e5868cf680207c5d0c9a900960ef6bc6fcb9 at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandIn(CliGitAPIImpl.java:2842) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandWithCredentials(CliGitAPIImpl.java:2185) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:635) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$2.execute(CliGitAPIImpl.java:871) at hudson.plugins.git.GitSCM.retrieveChanges(GitSCM.java:1222) at hudson.plugins.git.GitSCM.checkout(GitSCM.java:1305) at org.jenkinsci.plugins.workflow.steps.scm.SCMStep.checkout(SCMStep.java:129) at org.jenkinsci.plugins.workflow.cps.CpsScmFlowDefinition.create(CpsScmFlowDefinition.java:159) at org.jenkinsci.plugins.workflow.cps.CpsScmFlowDefinition.create(CpsScmFlowDefinition.java:70) at org.jenkinsci.plugins.workflow.job.WorkflowRun.run(WorkflowRun.java:312) at hudson.model.ResourceController.execute(ResourceController.java:101) at hudson.model.Executor.run(Executor.java:442) ERROR: Error cloning remote repo 'origin' ERROR: Maximum checkout retry attempts reached, aborting Finished: FAILURE
已尝试操作
- 执行
git config --global --add safe.directory '*',问题依旧
排查方向与解决方案
1. 确认Git全局配置的生效范围
执行git config --global --add safe.directory '*'后,需确保Jenkins进程使用的用户(通常是jenkins用户)能读取该配置。可通过ECS exec进入容器,切换到jenkins用户再执行该命令:
su - jenkins git config --global --add safe.directory '*'
2. 修改Jenkins全局Git配置
在Jenkins管理界面中,进入Manage Jenkins > Global Tool Configuration > Git,在"Additional behaviour"中添加自定义Git配置项:
- 键:
safe.directory - 值:
*
3. 调整容器内目录权限
Jenkins工作目录/var/jenkins_home的所有权需为jenkins:jenkins,可在ECS任务定义的启动命令中添加初始化逻辑:
chown -R jenkins:jenkins /var/jenkins_home && exec /usr/local/bin/jenkins.sh
4. 升级Git版本
当前使用的Git版本为2.30.2,该版本对可疑所有权的检测逻辑较严格。可尝试升级容器内的Git版本,或在Jenkins中配置使用更高版本的Git工具。
5. 配置Jenkins流水线的SCM行为
在流水线的SCM配置中,添加"Advanced clone behaviours",调整克隆策略(如启用浅克隆),避免Git触发所有权检测机制。
内容的提问来源于stack exchange,提问作者obasso99

