Azure DevOps流水线拉取镜像失败:Invalid clientid or client secret
Azure DevOps流水线构建报错:Invalid clientid or client secret 排查求助
所有Azure DevOps流水线突发无法构建,无明显诱因。报错显示“Invalid clientid or client secret”,但无法定位错误指向对象。
错误日志
2023-07-18T13:20:47.8763131Z ##[debug]found: '/usr/bin/docker' 2023-07-18T13:20:47.8763506Z ##[debug]/usr/bin/docker arg: pull` 2023-07-18T13:20:47.8764166Z ##[debug]/usr/bin/docker arg: ***/php8-base:latest 2023-07-18T13:20:47.8764916Z ##[debug]exec tool: /usr/bin/docker 2023-07-18T13:20:47.8765285Z ##[debug]arguments: 2023-07-18T13:20:47.8765637Z ##[debug] pull 2023-07-18T13:20:47.8766055Z ##[debug] ***/php8-base:latest 2023-07-18T13:20:47.8766779Z [command]/usr/bin/docker pull ***/php8-base:latest 2023-07-18T13:20:53.4683424Z Error response from daemon: Head "https://***/v2/php8-base/manifests/latest": unauthorized: Invalid clientid or client secret. 2023-07-18T13:20:53.4707635Z ##[debug]An error was found pulling the image ***/php8-base:latest, the command output was Error response from daemon: Head "https://***/v2/php8-base/manifests/latest": unauthorized: Invalid clientid or client secret. 2023-07-18T13:20:53.4708257Z ##[debug]which '/usr/bin/docker' 2023-07-18T13:20:53.4709275Z ##[debug]found: '/usr/bin/docker' 2023-07-18T13:20:53.4709633Z ##[debug]/usr/bin/docker arg: inspect 2023-07-18T13:20:53.4710044Z ##[debug]/usr/bin/docker arg: ***/php8-base:latest 2023-07-18T13:20:53.4710414Z ##[debug]exec tool: /usr/bin/docker 2023-07-18T13:20:53.4710746Z ##[debug]arguments: 2023-07-18T13:20:53.4711066Z ##[debug] inspect 2023-07-18T13:20:53.4711449Z ##[debug] ***/php8-base:latest 2023-07-18T13:20:53.4712071Z [command]/usr/bin/docker inspect ***/php8-base:latest 2023-07-18T13:20:53.5095970Z Error: No such object: ***/php8-base:latest
流水线文件(怀疑SSH构建环节有问题,替换后仍报错)
# Docker # Build and push an image to Azure Container Registry # https://docs.microsoft.com/azure/devops/pipelines/languages/docker trigger: - develop resources: - repo: self variables: # Variable group definition for specific site - group: *******-dev # Container registry service connection established during pipeline creation - name: dockerRegistryServiceConnection value: '*********-****-****-****-***********' - name: imageRepository value: '$(IMAGE_NAME)' - name: containerRegistry value: '***********.azurecr.io' - name: dockerfilePath value: '$(Build.SourcesDirectory)/Dockerfile' - name: tag value: '$(Build.BuildId)' # Agent VM image name - name: vmImageName value: 'ubuntu-latest' - name: image value: '$(Build.BuildId)' # ---------------- # Build stage, dockerbuild and ACR tag/push # ---------------- stages: - stage: Build displayName: Build and push stage jobs: - job: Build displayName: Build variables: - group: *******-dev pool: vmImage: $(vmImageName) steps: # ---------------- # Stage ssh keys from securefiles # ---------------- - task: DownloadSecureFile@1 name: satis_id_rsa inputs: secureFile: satis_id_rsa # ---------------- # Setup ssh key from secure file used by dockerbuild for azure repo access, also used by satis for repo access # ---------------- - task: CmdLine@2 displayName: ssh key setup for dockerbuild inputs: script: | AZURE_ID_RSA=$(cat $(satis_id_rsa.secureFilePath) | base64 -w 0) echo "##vso[task.setvariable variable=AZURE_ID_RSA;issecret=true]$AZURE_ID_RSA" - task: Docker@2 displayName: Build container image from dockerfile inputs: command: build repository: $(imageRepository) dockerfile: $(dockerfilePath) containerRegistry: $(dockerRegistryServiceConnection) arguments: --build-arg COMPOSER_REPO_URL=$(COMPOSER_REPO_URL) --build-arg AZURE_ID_RSA=$(AZURE_ID_RSA) tags: | $(tag) latest - task: Docker@2 displayName: Push container image from dockerfile inputs: command: push repository: $(imageRepository) containerRegistry: $(dockerRegistryServiceConnection) tags: | $(tag) latest # ---------------- # Deploy stage, deploys to aks cluster # ---------------- - stage: Deploy_dev displayName: Deploy to dev jobs: - deployment: Deploy_dev displayName: Deploy_dev variables: - group: ******-dev pool: vmImage: $(vmImageName) environment: '******-dev' strategy: runOnce: deploy: steps: - checkout: self # ---------------- # task to replace vars in aks-*.yml files, based on site var group # ---------------- - task: qetza.replacetokens.replacetokens-task.replacetokens@3 displayName: 'Prepare aks-*.yaml manifest file' inputs: targetFiles: 'pipeline/aks-*.yml' tokenPrefix: ___ tokenSuffix: ___ # ---------------- # task to deploy site k8s config to aks cluster # ---------------- - task: Kubernetes@1 displayName: Deploy latest image to aks cluster inputs: connectionType: 'Kubernetes Service Connection' kubernetesServiceEndpoint: '**************************' namespace: '$(SITE_NAME)' command: 'apply' useConfigurationFile: true configuration: 'pipeline/aks-deployment.yml' secretType: 'dockerRegistry' containerRegistryType: 'Azure Container Registry'
排查情况
- 确认Azure Resource Manager服务连接有效并重新生成
- 替换了SSH密钥,问题仍未解决
恳请各位提供解决思路!
相关服务连接截图

内容的提问来源于stack exchange,提问作者SulllivanWorks
相关产品推荐
相关产品推荐

