如何在Kustomization中传递Helm Chart凭证?遇401未授权问题
问题描述
执行kustomize build . --enable-helm时触发权限错误:
Error: Error: looks like "https://jfrog-prod.debs.cloud/artifactory/helm-dev2-local/helm-sample/nginx-sample.tgz" is not a valid chart repository or cannot be reached: failed to fetch https://jfrog-prod.debs.cloud/artifactory/helm-dev2-local/helm-sample/nginx-sample.tgz/index.yaml : 401 Unauthorized.
当前kustomization.yaml配置如下:
apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization helmCharts: - name: minecraft includeCRDs: false valuesFile: values.yaml releaseName: moria version: 0.1.0 repo: https://jfrog-prod.debs.cloud/artifactory/helm-dev2-local/helm-sample/nginx-sample.tgz
目标是执行命令后输出deployment和service资源对象。
问题原因
- Repo配置错误:直接将单个chart的tgz包地址设为
repo字段值,Kustomize会尝试从该地址拉取仓库索引文件index.yaml,路径无效且触发私有仓库权限校验。 - 凭证未配置:私有Helm仓库需要身份验证,但未通过正确方式传递访问凭证。
解决步骤
1. 修正kustomization.yaml配置
将repo改为Helm仓库的根URL,同时修正name为仓库中实际存在的chart名称(示例中应为helm-sample/nginx-sample,而非minecraft):
apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization helmCharts: - name: helm-sample/nginx-sample includeCRDs: false valuesFile: values.yaml releaseName: moria version: 0.1.0 repo: https://jfrog-prod.debs.cloud/artifactory/helm-dev2-local
2. 配置私有仓库凭证
两种常用传递凭证的方式:
方式一:提前通过Helm命令持久化配置
执行以下命令添加私有仓库并保存凭证:
helm repo add helm-dev2-local https://jfrog-prod.debs.cloud/artifactory/helm-dev2-local --username <你的用户名> --password <你的密码> helm repo update
之后直接执行kustomize build . --enable-helm即可,Kustomize会自动复用Helm已配置的仓库凭证。
方式二:通过环境变量临时传递凭证
无需提前配置仓库,直接在执行Kustomize命令时通过环境变量传入凭证:
HELM_REPO_USERNAME=<你的用户名> HELM_REPO_PASSWORD=<你的密码> kustomize build . --enable-helm
3. 验证结果
执行修正后的命令,若配置正确,即可输出对应的deployment和service资源对象。
内容的提问来源于stack exchange,提问作者Vinay K

