Jib-Maven-plugin+Jenkins脚本化流水线:私有Docker仓库登录失败排查
Let's break down your issues step by step, addressing both the private registry authentication problem and the unexpected Docker Hub error:
1. Core Issue: Incorrect Jenkins Credential Environment Variable Handling
Your initial assumption about environment variable delivery is spot-on, but the root cause is how you're using withEnv with Jenkins credentials:
- When you use
withEnv(["DOCKER_CREDS=credentials('myregistry-login')"]), Jenkins assigns the fullusername:passwordstring toDOCKER_CREDS, but it does NOT automatically create theDOCKER_CREDS_USRandDOCKER_CREDS_PSWvariables you're referencing in your pom.xml. Those suffix variables are only generated when you bind credentials directly to an environment variable via theenvironmentblock, not viawithEnv.
Fix for Jenkinsfile:
Replace your withEnv block with a credential binding that exposes the username and password as separate variables, and pass them directly to Maven via command-line arguments (more reliable than relying on pom.xml environment variable resolution):
def dockerImage stage('publish docker') { environment { // This automatically creates DOCKER_REGISTRY_CREDS_USR and DOCKER_REGISTRY_CREDS_PSW DOCKER_REGISTRY_CREDS = credentials('myregistry-login') } steps { sh "./mvnw -X -ntp jib:build \ -Djib.to.auth.username=${DOCKER_REGISTRY_CREDS_USR} \ -Djib.to.auth.password=${DOCKER_REGISTRY_CREDS_PSW}" } }
This bypasses any potential issues with Maven not picking up environment variables from the Jenkins context.
2. Jib Plugin Configuration Tweaks
Even if you fix the environment variables, a couple of your pom.xml settings might be causing issues:
- Remove the
<auth>block from your Jib configuration since you're now passing credentials via Maven command-line parameters. Having both can lead to conflicts or Jib prioritizing empty values if the environment variables weren't set correctly. - Simplify the image URL: Since HTTPS uses port 443 by default, you can omit the port from your
<image>value. Change:
To:<image>myregistry.mydomain.com:443/username/imagename</image>
Specifying the port unnecessarily can sometimes cause registry resolution issues with Jib.<image>myregistry.mydomain.com/username/imagename</image>
3. Why the registry-1.docker.io Error?
This is a secondary issue triggered by the primary failure. Jib pulls a base image (in your case, adoptopenjdk from Docker Hub) to build your application image. When the private registry push fails early, Jib may cancel the base image pull mid-operation, leading to the "Socket closed" error. Additionally:
- Your Jenkins server might have restricted outbound access to Docker Hub (firewall/proxy rules).
- If you're working in an air-gapped environment, you should mirror the
adoptopenjdkimage to your private registry and update Jib's<from>configuration to use the local mirror:<plugin> <groupId>com.google.cloud.tools</groupId> <artifactId>jib-maven-plugin</artifactId> <configuration> <from> <image>myregistry.mydomain.com/adoptopenjdk:11-jre-hotspot</image> </from> <!-- rest of your config --> </configuration> </plugin>
4. Verification Steps
To confirm fixes are working:
- Add a debug step in your Jenkins pipeline to print the credential variables:
(Don't print the password in production!)sh 'echo "Username: $DOCKER_REGISTRY_CREDS_USR"' - Test the Maven build locally with the same credentials to rule out registry-side issues:
./mvnw jib:build -Djib.to.auth.username=your-username -Djib.to.auth.password=your-password - Validate Jenkins node connectivity to both your private registry and Docker Hub (if needed):
curl https://myregistry.mydomain.com/v2/ curl https://registry-1.docker.io/v2/
内容的提问来源于stack exchange,提问作者Jochen Haßfurter

