GitLab Container Scanning扫描失败:4类错误排查求助
GitLab容器扫描失败问题排查与解决
问题概述
使用GitLab container_scanning功能时出现四类错误:无法连接Docker daemon、无法初始化Podman客户端、未找到containerd套接字、镜像仓库认证失败。尝试配置CS_REGISTRY_USER/CS_REGISTRY_PASSWORD变量及自定义Trivy扫描配置后,问题仍未解决。
错误日志
.... trivy image --vuln-type os --no-progress --offline-scan --skip-update --security-checks vuln --format template --template @/usr/local/bundle/gems/gcs-5.2.7/lib/template/trivy.tpl --output tmp.json registry.gitlab.com/xxxx/temp:1442 00:04 [DEBUG] [2023-02-22 16:39:59 +0000] [container-scanning] > trivy image --vuln-type os --no-progress --offline-scan --skip-update --security-checks vuln --format template --template @/usr/local/bundle/gems/gcs-5.2.7/lib/template/trivy.tpl --output tmp.json registry.gitlab.com/xxxx/temp:1442 [DEBUG] [2023-02-22 16:40:03 +0000] [container-scanning] > 2023-02-22T16:39:59.813Z DEBUG Severities: ["UNKNOWN" "LOW" "MEDIUM" "HIGH" "CRITICAL"] 2023-02-22T16:39:59.820Z DEBUG cache dir: /home/gitlab/.cache/trivy/ce 2023-02-22T16:39:59.820Z DEBUG Skipping DB update... 2023-02-22T16:39:59.820Z DEBUG DB Schema: 2, UpdatedAt: 2023-02-21 12:07:46.494248011 +0000 UTC, NextUpdate: 2023-02-21 18:07:46.494247711 +0000 UTC, DownloadedAt: 0001-01-01 00:00:00 +0000 UTC 2023-02-22T16:40:02.898Z INFO Vulnerability scanning is enabled 2023-02-22T16:40:02.898Z DEBUG Vulnerability type: [os] 2023-02-22T16:40:03.337Z FATAL image scan error: github.com/aquasecurity/trivy/pkg/commands/artifact.Run /home/runner/work/trivy/trivy/pkg/commands/artifact/run.go:397 - scan error: github.com/aquasecurity/trivy/pkg/commands/artifact.(*runner).scanArtifact /home/runner/work/trivy/trivy/pkg/commands/artifact/run.go:257 - unable to initialize a scanner: github.com/aquasecurity/trivy/pkg/commands/artifact.scan /home/runner/work/trivy/trivy/pkg/commands/artifact/run.go:582 - unable to initialize a docker scanner: github.com/aquasecurity/trivy/pkg/commands/artifact.imageStandaloneScanner /home/runner/work/trivy/trivy/pkg/commands/artifact/scanner.go:22 - 4 errors occurred: * unable to inspect the image (registry.gitlab.com/xxxx/temp:1442): Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running? * unable to initialize Podman client: no podman socket found: stat podman/podman.sock: no such file or directory * containerd socket not found: /run/containerd/containerd.sock * GET https://registry.gitlab.com/v2/xxxx/temp/manifests/1442: UNAUTHORIZED: authentication required; [map[Action:pull Class: Name:xxxx/temp Type:repository]] [DEBUG] [2023-02-22 16:40:03 +0000] [container-scanning] > [INFO] [2023-02-22 16:40:03 +0000] [container-scanning] > Scan failed. Use `SECURE_LOG_LEVEL=debug` to see more details. [ERROR] [2023-02-22 16:40:03 +0000] [container-scanning] > The credentials set in CS_REGISTRY_USER and CS_REGISTRY_PASSWORD are either empty or not valid. Please set valid credentials. ....
原GitLab CI配置
include: - template: Jobs/Container-Scanning.gitlab-ci.yml stages: - Build Image - test Build_Docker: tags: - xxxx-runner image: name: amazon/aws-cli entrypoint: [""] services: - docker:18-dind stage: Build Image variables: APP_NAME: xxxx/temp before_script: - amazon-linux-extras install docker - aws --version - docker --version script: - docker build -f xxxx/Dockerfile -t $DOCKER_REGISTRY/$APP_NAME:$CI_PIPELINE_IID . - docker login -u $CI_REGISTRY_USER -p $CI_JOB_TOKEN $CI_REGISTRY - docker push $DOCKER_REGISTRY/$APP_NAME:$CI_PIPELINE_IID rules: - !reference [.rules_script, rules] container_scanning: image: "$CS_ANALYZER_IMAGE$CS_IMAGE_SUFFIX" stage: test needs: ["Build_Docker"] variables: APP_NAME: xxxx/temp GIT_STRATEGY: none SECURE_LOG_LEVEL: 'debug' CI_GITLAB_FIPS_MODE: "false" CS_IMAGE: $CI_REGISTRY_IMAGE/$APP_NAME:$CI_PIPELINE_IID CS_REGISTRY_USER: "xxxx" CS_REGISTRY_PASSWORD: "$xxxxx"
自定义Trivy扫描配置
container_scanning: extends: .job_aws stage: test needs: ["Build_Docker"] variables: GIT_STRATEGY: none TRIVY_USERNAME: "$CI_REGISTRY_USER" TRIVY_PASSWORD: "$TrivyPassword" TRIVY_AUTH_URL: "$CI_REGISTRY" FULL_IMAGE_NAME: $CI_REGISTRY_IMAGE/$APP_NAME:$CI_PIPELINE_IID DOCKER_TLS_CERTDIR: '' before_script: - !reference [.before_script.docker, before_script] - yum install -y gettext - yum install -y tar gzip - docker login -u $CI_REGISTRY_USER -p $CI_JOB_TOKEN $CI_REGISTRY script: - curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin - trivy --version - time trivy image --clear-cache - time trivy image --download-db-only --no-progress --cache-dir .trivycache/ # Builds report and puts it in the default workdir $CI_PROJECT_DIR, so `artifacts:` can take it from there - time trivy image --exit-code 0 --debug --cache-dir .trivycache/ --no-progress --format template --template "@/contrib/gitlab.tpl" --output "$CI_PROJECT_DIR/gl-container-scanning-report.json" "$FULL_IMAGE_NAME" # - time trivy image --exit-code 0 --debug --cache-dir .trivycache/ --no-progress --output "$CI_PROJECT_DIR/gl-container-scanning-report.json" "$FULL_IMAGE_NAME" # # Fail on critical vulnerabilities # - time trivy image --exit-code 1 --debug --cache-dir .trivycache/ --no-progress --severity CRITICAL "$FULL_IMAGE_NAME" cache: paths: - .trivycache/ artifacts: when: always reports: container_scanning: gl-container-scanning-report.json
解决方案建议
1. 修复镜像仓库认证问题
- 官方模板配置:替换自定义的
CS_REGISTRY_USER和CS_REGISTRY_PASSWORD为GitLab内置变量,CI_REGISTRY_USER和CI_JOB_TOKEN是GitLab自动生成的临时凭证,拥有当前项目镜像的拉取权限,无需额外配置:container_scanning: # ... 其他配置不变 variables: # ... 其他变量不变 CS_REGISTRY_USER: "$CI_REGISTRY_USER" CS_REGISTRY_PASSWORD: "$CI_JOB_TOKEN" - 自定义Trivy配置:将
TRIVY_PASSWORD替换为$CI_JOB_TOKEN,无需单独维护TrivyPassword变量,同时确保TRIVY_AUTH_URL与镜像仓库地址一致:variables: TRIVY_USERNAME: "$CI_REGISTRY_USER" TRIVY_PASSWORD: "$CI_JOB_TOKEN" TRIVY_AUTH_URL: "$CI_REGISTRY" - 检查镜像路径一致性:确认
CS_IMAGE(官方模板)或FULL_IMAGE_NAME(自定义配置)与Build阶段推送的镜像路径完全一致,即$DOCKER_REGISTRY/$APP_NAME:$CI_PIPELINE_IID和$CI_REGISTRY_IMAGE/$APP_NAME:$CI_PIPELINE_IID是否指向同一镜像。
2. 解决容器运行时依赖问题
Trivy优先尝试通过本地容器运行时(Docker/Podman/containerd)拉取镜像,若环境中没有这些服务,会直接通过Registry API拉取,但需要确保认证正确。如果要保留容器运行时方式:
- 官方模板:为
container_scanning任务添加Docker服务,并配置相关变量:container_scanning: # ... 其他配置不变 services: - docker:dind variables: DOCKER_TLS_CERTDIR: '' DOCKER_HOST: tcp://docker:2375 - 自定义Trivy配置:同样添加Docker服务,确保任务能访问到Docker daemon。
3. 优化自定义Trivy配置
- 简化认证步骤:删除
before_script中的docker login步骤,Trivy会自动使用TRIVY_USERNAME和TRIVY_PASSWORD完成认证。 - 修复模板路径:
@/contrib/gitlab.tpl路径在容器中不存在,需提前拉取模板文件:
然后修改扫描命令中的模板参数:curl -o gitlab.tpl https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/gitlab.tpltrivy image --exit-code 0 --debug --cache-dir .trivycache/ --no-progress --format template --template "@gitlab.tpl" \ --output "$CI_PROJECT_DIR/gl-container-scanning-report.json" "$FULL_IMAGE_NAME" - 离线环境适配:如果是离线环境,确保漏洞库缓存已正确下载,或者添加
--skip-db-update参数避免更新漏洞库。
4. 检查Runner环境
- 确保运行扫描任务的Runner支持Docker-in-Docker(DinD)模式,或者是Shell Runner且本地Docker daemon已启动并正常运行。
- 若使用DinD,Runner需要配置
privileged: true权限(在Runner配置中设置)。
内容的提问来源于stack exchange,提问作者xfusion
相关产品推荐
相关产品推荐

