如何在GitLab/OpenShift存储配置文件并每2小时调度证书检查脚本
过期证书检测脚本的GitLab/OpenShift部署与定时执行方案
脚本优化提示
你的脚本中数组定义存在问题,当前写法会把整个字符串作为单个元素处理,修正为:
files=("ppsit" "ppdev" "ppdev2" "ppuat") # 遍历数组时改用以下写法,避免空格拆分问题 for file in "${files[@]}" do # 原有逻辑 done
GitLab 实现方案
1. 配置文件与脚本存储
- 创建一个GitLab项目,用于存放检测脚本和配置文件
- 将修正后的检测脚本(命名为
cert-check.sh)和ppsit、ppdev、ppdev2、ppuat配置文件提交到仓库 - 敏感信息处理:配置文件中的
password等敏感字段不要明文存储,改用GitLab CI/CD变量管理:- 进入项目「Settings」→「CI/CD」→「Variables」,添加对应环境的敏感变量(如
PPSIT_PASSWORD、PPDEV_PATH) - 修改脚本,用环境变量替代配置文件中的明文敏感值,例如将配置文件里的
password=$PPSIT_PASSWORD改为直接读取环境变量
- 进入项目「Settings」→「CI/CD」→「Variables」,添加对应环境的敏感变量(如
2. 每2小时定时调度
在项目根目录创建.gitlab-ci.yml文件,定义定时任务:
stages: - check_certs check_expired_certs: stage: check_certs script: - chmod +x cert-check.sh - ./cert-check.sh schedule: interval: "2 hours" timezone: Asia/Shanghai # 根据实际时区调整 tags: - shell # 需确保GitLab Runner支持Shell执行,或使用包含JDK的Docker镜像(keytool依赖JDK)
提交文件后,进入项目「CI/CD」→「Schedules」即可查看并管理定时任务,也可手动触发测试运行。
OpenShift 实现方案
1. 配置文件与敏感信息存储
- 非敏感配置:用
ConfigMap存储ppsit等配置文件:
oc create configmap cert-configs --from-file=ppsit --from-file=ppdev --from-file=ppdev2 --from-file=ppuat
- 敏感信息:用
Secret存储密码等敏感内容:
oc create secret generic cert-secrets --from-literal=ppsit_password=your_ppsit_pass --from-literal=ppdev_password=your_ppdev_pass
- 脚本存储:将检测脚本存入
ConfigMap并赋予执行权限:
oc create configmap cert-script --from-file=cert-check.sh --default-mode=0755
2. 每2小时定时运行(CronJob)
创建cert-cronjob.yaml配置文件:
apiVersion: batch/v1 kind: CronJob metadata: name: expired-cert-check spec: schedule: "0 */2 * * *" # 每2小时整点运行 jobTemplate: spec: template: spec: containers: - name: cert-check image: openjdk:8-jre-alpine # 选择包含keytool的JRE/JDK镜像 command: ["/bin/bash", "-c"] args: - | # 将配置文件复制到工作目录 cp /configs/* /workdir/ # 加载敏感环境变量 export PPSIT_PASSWORD=$(cat /secrets/ppsit_password) export PPDEV_PASSWORD=$(cat /secrets/ppdev_password) # 其他环境变量同理设置 cd /workdir ./cert-check.sh volumeMounts: - name: config-volume mountPath: /configs - name: secret-volume mountPath: /secrets - name: script-volume mountPath: /workdir volumes: - name: config-volume configMap: name: cert-configs - name: secret-volume secret: secretName: cert-secrets - name: script-volume configMap: name: cert-script restartPolicy: OnFailure
应用配置文件:
oc apply -f cert-cronjob.yaml
如需测试,可手动触发任务:
oc create job --from=cronjob/expired-cert-check test-cert-job
内容的提问来源于stack exchange,提问作者Fareed Beig
相关产品推荐
相关产品推荐

