You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在GitLab/OpenShift存储配置文件并每2小时调度证书检查脚本

过期证书检测脚本的GitLab/OpenShift部署与定时执行方案

脚本优化提示

你的脚本中数组定义存在问题,当前写法会把整个字符串作为单个元素处理,修正为:

files=("ppsit" "ppdev" "ppdev2" "ppuat")
# 遍历数组时改用以下写法,避免空格拆分问题
for file in "${files[@]}"
do
  # 原有逻辑
done

GitLab 实现方案

1. 配置文件与脚本存储

  • 创建一个GitLab项目,用于存放检测脚本和配置文件
  • 将修正后的检测脚本(命名为cert-check.sh)和ppsit、ppdev、ppdev2、ppuat配置文件提交到仓库
  • 敏感信息处理:配置文件中的password等敏感字段不要明文存储,改用GitLab CI/CD变量管理:
    • 进入项目「Settings」→「CI/CD」→「Variables」,添加对应环境的敏感变量(如PPSIT_PASSWORD、PPDEV_PATH)
    • 修改脚本,用环境变量替代配置文件中的明文敏感值,例如将配置文件里的password=$PPSIT_PASSWORD改为直接读取环境变量

2. 每2小时定时调度

在项目根目录创建.gitlab-ci.yml文件,定义定时任务:

stages:
  - check_certs

check_expired_certs:
  stage: check_certs
  script:
    - chmod +x cert-check.sh
    - ./cert-check.sh
  schedule:
    interval: "2 hours"
    timezone: Asia/Shanghai # 根据实际时区调整
  tags:
    - shell # 需确保GitLab Runner支持Shell执行,或使用包含JDK的Docker镜像(keytool依赖JDK)

提交文件后,进入项目「CI/CD」→「Schedules」即可查看并管理定时任务,也可手动触发测试运行。


OpenShift 实现方案

1. 配置文件与敏感信息存储

  • 非敏感配置:用ConfigMap存储ppsit等配置文件:
oc create configmap cert-configs --from-file=ppsit --from-file=ppdev --from-file=ppdev2 --from-file=ppuat
  • 敏感信息:用Secret存储密码等敏感内容:
oc create secret generic cert-secrets --from-literal=ppsit_password=your_ppsit_pass --from-literal=ppdev_password=your_ppdev_pass
  • 脚本存储:将检测脚本存入ConfigMap并赋予执行权限:
oc create configmap cert-script --from-file=cert-check.sh --default-mode=0755

2. 每2小时定时运行(CronJob)

创建cert-cronjob.yaml配置文件:

apiVersion: batch/v1
kind: CronJob
metadata:
  name: expired-cert-check
spec:
  schedule: "0 */2 * * *" # 每2小时整点运行
  jobTemplate:
    spec:
      template:
        spec:
          containers:
          - name: cert-check
            image: openjdk:8-jre-alpine # 选择包含keytool的JRE/JDK镜像
            command: ["/bin/bash", "-c"]
            args:
            - |
              # 将配置文件复制到工作目录
              cp /configs/* /workdir/
              # 加载敏感环境变量
              export PPSIT_PASSWORD=$(cat /secrets/ppsit_password)
              export PPDEV_PASSWORD=$(cat /secrets/ppdev_password)
              # 其他环境变量同理设置
              cd /workdir
              ./cert-check.sh
            volumeMounts:
            - name: config-volume
              mountPath: /configs
            - name: secret-volume
              mountPath: /secrets
            - name: script-volume
              mountPath: /workdir
          volumes:
          - name: config-volume
            configMap:
              name: cert-configs
          - name: secret-volume
            secret:
              secretName: cert-secrets
          - name: script-volume
            configMap:
              name: cert-script
          restartPolicy: OnFailure

应用配置文件:

oc apply -f cert-cronjob.yaml

如需测试,可手动触发任务:

oc create job --from=cronjob/expired-cert-check test-cert-job

内容的提问来源于stack exchange,提问作者Fareed Beig

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 04:20:31