You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Google Cloud Build中访问GitHub私有Maven制品包

问题描述

我有一个用于构建Spring Boot应用的Google Cloud Build触发器,现在需要使用GitHub私有Maven仓库中的jar包,因此需要为构建流程提供settings.xml文件来访问该包。

我的Cloud Build配置如下:

steps:
  - name: maven
    args:
      - clean
    id: Clean
    entrypoint: mvn
  - name: maven
    args:
      - install
      - '-Pdev'
    id: Install
    entrypoint: mvn
options:
  substitutionOption: ALLOW_LOOSE
  logging: CLOUD_LOGGING_ONLY

用于访问Maven仓库的示例settings.xml文件如下:

<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0"
          xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
          xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0
                      http://maven.apache.org/xsd/settings-1.0.0.xsd">

    <activeProfiles>
        <activeProfile>github</activeProfile>
    </activeProfiles>
    <profiles>
        <profile>
            <id>github</id>
            <repositories>
                <repository>
                    <id>central</id>
                    <url>https://repo1.maven.org/maven2</url>
                </repository>
                <repository>
                    <id>github</id>
                    <url>https://maven.pkg.github.com/OWNER/REPO</url>
                    <snapshots>
                        <enabled>true</enabled>
                    </snapshots>
                </repository>
            </repositories>
        </profile>
    </profiles>
    <servers>
        <server>
            <id>github</id>
            <username>$_GITHUB_USERNAME</username>
            <password>$_GITHUB_TOKEN</password>
        </server>
    </servers>
</settings>

我需要配置该settings.xml并填入凭证,请问是否有优雅的实现方式?


优雅实现方式

方法1:结合Cloud Build变量替换+Secret Manager存储凭证(推荐)

这是符合安全最佳实践的方案,完全避免凭证暴露:

  1. 存储凭证到Secret Manager
    在Google Cloud Console中创建两个Secret:

    • github-maven-username:存入你的GitHub用户名
    • github-maven-token:存入有私有仓库访问权限的GitHub个人访问令牌(PAT)
  2. 更新Cloud Build配置
    修改cloudbuild.yaml,添加Secret访问步骤、动态生成settings.xml,并确保Maven步骤使用该配置:

    substitutions:
      _GITHUB_REPO_URL: "https://maven.pkg.github.com/OWNER/REPO"
      _GITHUB_USERNAME_SECRET: "github-maven-username"
      _GITHUB_TOKEN_SECRET: "github-maven-token"
    options:
      substitutionOption: ALLOW_LOOSE
      logging: CLOUD_LOGGING_ONLY
    steps:
      # 拉取GitHub用户名凭证
      - name: 'gcr.io/cloud-builders/gcloud'
        args:
          - secrets
          - versions
          - access
          - latest
          - --secret=${_GITHUB_USERNAME_SECRET}
        id: FetchUsername
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
      # 拉取GitHub令牌凭证
      - name: 'gcr.io/cloud-builders/gcloud'
        args:
          - secrets
          - versions
          - access
          - latest
          - --secret=${_GITHUB_TOKEN_SECRET}
        id: FetchToken
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
      # 生成settings.xml文件
      - name: 'ubuntu'
        args:
          - bash
          - '-c'
          - |
            cat > /builder/home/.m2/settings.xml << 'EOF'
            <settings xmlns="http://maven.apache.org/SETTINGS/1.0.0"
                      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                      xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0
                                  http://maven.apache.org/xsd/settings-1.0.0.xsd">
                <activeProfiles>
                    <activeProfile>github</activeProfile>
                </activeProfiles>
                <profiles>
                    <profile>
                        <id>github</id>
                        <repositories>
                            <repository>
                                <id>central</id>
                                <url>https://repo1.maven.org/maven2</url>
                            </repository>
                            <repository>
                                <id>github</id>
                                <url>${_GITHUB_REPO_URL}</url>
                                <snapshots>
                                    <enabled>true</enabled>
                                </snapshots>
                            </repository>
                        </repositories>
                    </profile>
                </profiles>
                <servers>
                    <server>
                        <id>github</id>
                        <username>$(cat /builder/home/.m2/${_GITHUB_USERNAME_SECRET})</username>
                        <password>$(cat /builder/home/.m2/${_GITHUB_TOKEN_SECRET})</password>
                    </server>
                </servers>
            </settings>
            EOF
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
        id: GenerateSettings
      # Maven清理步骤
      - name: maven
        args:
          - clean
        id: Clean
        entrypoint: mvn
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
      # Maven安装步骤
      - name: maven
        args:
          - install
          - '-Pdev'
        id: Install
        entrypoint: mvn
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
    
    • 最后给Cloud Build服务账号授予roles/secretmanager.secretAccessor权限,确保能访问Secret Manager中的凭证。

方法2:模板文件+Cloud Build变量替换(不推荐生产用)

如果暂时不想用Secret Manager,可以把settings.xml模板存入代码库,用Cloud Build变量替换凭证:

  1. 添加settings.xml.template到代码库

    <settings xmlns="http://maven.apache.org/SETTINGS/1.0.0"
              xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
              xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0
                          http://maven.apache.org/xsd/settings-1.0.0.xsd">
        <activeProfiles>
            <activeProfile>github</activeProfile>
        </activeProfiles>
        <profiles>
            <profile>
                <id>github</id>
                <repositories>
                    <repository>
                        <id>central</id>
                        <url>https://repo1.maven.org/maven2</url>
                    </repository>
                    <repository>
                        <id>github</id>
                        <url>${_GITHUB_REPO_URL}</url>
                        <snapshots>
                            <enabled>true</enabled>
                        </snapshots>
                    </repository>
                </repositories>
            </profile>
        </profiles>
        <servers>
            <server>
                <id>github</id>
                <username>${_GITHUB_USERNAME}</username>
                <password>${_GITHUB_TOKEN}</password>
            </server>
        </servers>
    </settings>
    
  2. 更新Cloud Build配置

    substitutions:
      _GITHUB_REPO_URL: "https://maven.pkg.github.com/OWNER/REPO"
      _GITHUB_USERNAME: "你的GitHub用户名"
      _GITHUB_TOKEN: "你的GitHub PAT"
    options:
      substitutionOption: ALLOW_LOOSE
      logging: CLOUD_LOGGING_ONLY
    steps:
      # 生成settings.xml
      - name: 'ubuntu'
        args:
          - bash
          - '-c'
          - 'envsubst < settings.xml.template > /builder/home/.m2/settings.xml'
        id: GenerateSettings
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
      # Maven清理
      - name: maven
        args:
          - clean
        id: Clean
        entrypoint: mvn
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
      # Maven安装
      - name: maven
        args:
          - install
          - '-Pdev'
        id: Install
        entrypoint: mvn
        volumes:
          - name: 'maven-settings'
            path: '/builder/home/.m2'
    
    • 注意:此方式中凭证会作为Cloud Build变量存储,存在一定暴露风险,仅适合测试环境使用。

方法3:直接指定settings.xml路径(不推荐)

如果你的settings.xml已包含硬编码凭证(强烈不建议),可以将其存入代码库,然后在Maven命令中指定路径:

steps:
  - name: maven
    args:
      - clean
      - '-s'
      - './settings.xml'
    id: Clean
    entrypoint: mvn
  - name: maven
    args:
      - install
      - '-Pdev'
      - '-s'
      - './settings.xml'
    id: Install
    entrypoint: mvn
options:
  substitutionOption: ALLOW_LOOSE
  logging: CLOUD_LOGGING_ONLY
  • 风险:凭证明文存储在代码库中,极易泄露,绝对禁止在生产环境使用。

内容的提问来源于stack exchange,提问作者Gismat Kazimli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 07:24:58