You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab CI执行Makefile时wget报操作不允许的原因及解决方法

问题原因与解决方案

原因分析

在GitLab CI的docker:20.10(基于alpine)环境中,make执行命令时会为每条指令单独启动一个/bin/sh(ash)子进程,该子进程的系统调用权限受CI环境的seccomp安全策略限制,导致无法执行wget这类网络操作。但直接在CI脚本的shell会话中执行命令时,权限不受此限制,因此能正常运行。

解决方案(避免逻辑重复)

以下几种方法均可解决问题,无需重复编写命令:

1. 使用绝对路径调用wget

修改Makefile,直接指定wget的绝对路径(alpine中默认路径为/usr/bin/wget),绕过shell环境的权限限制:

docker-compose.yml:
    /usr/bin/wget https://gitlab.com/dependabot-gitlab/dependabot/-/raw/v0.34.0/docker-compose.yml
    docker run --rm -v ${PWD}:${PWD} -w ${PWD} mikefarah/yq:3 yq delete -i docker-compose.yml 'services[*].ports'

2. 指定make使用的Shell

在CI中安装bash,并让make使用bash执行命令(bash的权限限制更宽松):

  • 修改CI配置的before_script:
before_script:
  - apk add make wget bash
  - make docker-compose.yml
  • 在Makefile开头添加Shell配置:
SHELL := /bin/bash
docker-compose.yml:
    wget https://gitlab.com/dependabot-gitlab/dependabot/-/raw/v0.34.0/docker-compose.yml
    docker run --rm -v ${PWD}:${PWD} -w ${PWD} mikefarah/yq:3 yq delete -i docker-compose.yml 'services[*].ports'

3. 显式设置PATH环境变量

在Makefile中强制指定PATH,确保wget能被正确找到并执行:

export PATH := /usr/bin:$(PATH)
docker-compose.yml:
    wget https://gitlab.com/dependabot-gitlab/dependabot/-/raw/v0.34.0/docker-compose.yml
    docker run --rm -v ${PWD}:${PWD} -w ${PWD} mikefarah/yq:3 yq delete -i docker-compose.yml 'services[*].ports'

内容的提问来源于stack exchange,提问作者Soullivaneuh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 13:20:28