如何在Google Cloud Build中访问GitHub私有Maven制品包
问题描述
我有一个用于构建Spring Boot应用的Google Cloud Build触发器,现在需要使用GitHub私有Maven仓库中的jar包,因此需要为构建流程提供settings.xml文件来访问该包。
我的Cloud Build配置如下:
steps: - name: maven args: - clean id: Clean entrypoint: mvn - name: maven args: - install - '-Pdev' id: Install entrypoint: mvn options: substitutionOption: ALLOW_LOOSE logging: CLOUD_LOGGING_ONLY
用于访问Maven仓库的示例settings.xml文件如下:
<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 http://maven.apache.org/xsd/settings-1.0.0.xsd"> <activeProfiles> <activeProfile>github</activeProfile> </activeProfiles> <profiles> <profile> <id>github</id> <repositories> <repository> <id>central</id> <url>https://repo1.maven.org/maven2</url> </repository> <repository> <id>github</id> <url>https://maven.pkg.github.com/OWNER/REPO</url> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> </profile> </profiles> <servers> <server> <id>github</id> <username>$_GITHUB_USERNAME</username> <password>$_GITHUB_TOKEN</password> </server> </servers> </settings>
我需要配置该settings.xml并填入凭证,请问是否有优雅的实现方式?
优雅实现方式
方法1:结合Cloud Build变量替换+Secret Manager存储凭证(推荐)
这是符合安全最佳实践的方案,完全避免凭证暴露:
存储凭证到Secret Manager
在Google Cloud Console中创建两个Secret:github-maven-username:存入你的GitHub用户名github-maven-token:存入有私有仓库访问权限的GitHub个人访问令牌(PAT)
更新Cloud Build配置
修改cloudbuild.yaml,添加Secret访问步骤、动态生成settings.xml,并确保Maven步骤使用该配置:substitutions: _GITHUB_REPO_URL: "https://maven.pkg.github.com/OWNER/REPO" _GITHUB_USERNAME_SECRET: "github-maven-username" _GITHUB_TOKEN_SECRET: "github-maven-token" options: substitutionOption: ALLOW_LOOSE logging: CLOUD_LOGGING_ONLY steps: # 拉取GitHub用户名凭证 - name: 'gcr.io/cloud-builders/gcloud' args: - secrets - versions - access - latest - --secret=${_GITHUB_USERNAME_SECRET} id: FetchUsername volumes: - name: 'maven-settings' path: '/builder/home/.m2' # 拉取GitHub令牌凭证 - name: 'gcr.io/cloud-builders/gcloud' args: - secrets - versions - access - latest - --secret=${_GITHUB_TOKEN_SECRET} id: FetchToken volumes: - name: 'maven-settings' path: '/builder/home/.m2' # 生成settings.xml文件 - name: 'ubuntu' args: - bash - '-c' - | cat > /builder/home/.m2/settings.xml << 'EOF' <settings xmlns="http://maven.apache.org/SETTINGS/1.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 http://maven.apache.org/xsd/settings-1.0.0.xsd"> <activeProfiles> <activeProfile>github</activeProfile> </activeProfiles> <profiles> <profile> <id>github</id> <repositories> <repository> <id>central</id> <url>https://repo1.maven.org/maven2</url> </repository> <repository> <id>github</id> <url>${_GITHUB_REPO_URL}</url> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> </profile> </profiles> <servers> <server> <id>github</id> <username>$(cat /builder/home/.m2/${_GITHUB_USERNAME_SECRET})</username> <password>$(cat /builder/home/.m2/${_GITHUB_TOKEN_SECRET})</password> </server> </servers> </settings> EOF volumes: - name: 'maven-settings' path: '/builder/home/.m2' id: GenerateSettings # Maven清理步骤 - name: maven args: - clean id: Clean entrypoint: mvn volumes: - name: 'maven-settings' path: '/builder/home/.m2' # Maven安装步骤 - name: maven args: - install - '-Pdev' id: Install entrypoint: mvn volumes: - name: 'maven-settings' path: '/builder/home/.m2'- 最后给Cloud Build服务账号授予
roles/secretmanager.secretAccessor权限,确保能访问Secret Manager中的凭证。
- 最后给Cloud Build服务账号授予
方法2:模板文件+Cloud Build变量替换(不推荐生产用)
如果暂时不想用Secret Manager,可以把settings.xml模板存入代码库,用Cloud Build变量替换凭证:
添加settings.xml.template到代码库
<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 http://maven.apache.org/xsd/settings-1.0.0.xsd"> <activeProfiles> <activeProfile>github</activeProfile> </activeProfiles> <profiles> <profile> <id>github</id> <repositories> <repository> <id>central</id> <url>https://repo1.maven.org/maven2</url> </repository> <repository> <id>github</id> <url>${_GITHUB_REPO_URL}</url> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> </profile> </profiles> <servers> <server> <id>github</id> <username>${_GITHUB_USERNAME}</username> <password>${_GITHUB_TOKEN}</password> </server> </servers> </settings>更新Cloud Build配置
substitutions: _GITHUB_REPO_URL: "https://maven.pkg.github.com/OWNER/REPO" _GITHUB_USERNAME: "你的GitHub用户名" _GITHUB_TOKEN: "你的GitHub PAT" options: substitutionOption: ALLOW_LOOSE logging: CLOUD_LOGGING_ONLY steps: # 生成settings.xml - name: 'ubuntu' args: - bash - '-c' - 'envsubst < settings.xml.template > /builder/home/.m2/settings.xml' id: GenerateSettings volumes: - name: 'maven-settings' path: '/builder/home/.m2' # Maven清理 - name: maven args: - clean id: Clean entrypoint: mvn volumes: - name: 'maven-settings' path: '/builder/home/.m2' # Maven安装 - name: maven args: - install - '-Pdev' id: Install entrypoint: mvn volumes: - name: 'maven-settings' path: '/builder/home/.m2'- 注意:此方式中凭证会作为Cloud Build变量存储,存在一定暴露风险,仅适合测试环境使用。
方法3:直接指定settings.xml路径(不推荐)
如果你的settings.xml已包含硬编码凭证(强烈不建议),可以将其存入代码库,然后在Maven命令中指定路径:
steps: - name: maven args: - clean - '-s' - './settings.xml' id: Clean entrypoint: mvn - name: maven args: - install - '-Pdev' - '-s' - './settings.xml' id: Install entrypoint: mvn options: substitutionOption: ALLOW_LOOSE logging: CLOUD_LOGGING_ONLY
- 风险:凭证明文存储在代码库中,极易泄露,绝对禁止在生产环境使用。
内容的提问来源于stack exchange,提问作者Gismat Kazimli
相关产品推荐
相关产品推荐

