Jenkins Pipeline执行Git克隆时报“git: command not found”,如何安装Git?
解决Jenkins Kubernetes Agent中Git命令缺失的问题
首先纠正一个语法错误
你在sh脚本中写的git branch: 'main', credentialsId: 'system-id', url: 'xxx'是Jenkins Pipeline步骤语法,不是Shell命令,即使安装了Git也会执行失败。需要替换为Shell原生的Git克隆命令,或者使用Jenkins内置的checkout步骤。
方案1:在aws-cli容器内静默安装Git(快速临时解决)
aws-cli镜像基于Amazon Linux,可直接用yum静默安装Git,添加在Git命令执行前即可:
修改Sending the files to S3 bucket阶段的代码:
stage('Sending the files to S3 bucket') { withCredentials([usernamePassword(credentialsId: 'system-id', usernameVariable: 'GIT_USER', passwordVariable: 'GIT_PASS')]) { container('aws-cli') { sh ''' JOB_TITLE=`echo ${JOB_BASE_NAME} | sed 's/ /_/g'` set +x AWS_CRED=aws.cred export AWS_ACCESS_KEY_ID=$( awk '/access_key / {print $2}' $AWS_CRED ) export AWS_SECRET_ACCESS_KEY=$( awk '/secret_key / {print $2}' $AWS_CRED ) export AWS_SESSION_TOKEN=$( awk '/security_token / {print $2}' $AWS_CRED ) env | grep AWS set -x # 静默安装Git(Amazon Linux环境,自动确认所有提示) yum install -y git # 用Shell命令克隆代码(替换为你的仓库地址) git clone https://${GIT_USER}:${GIT_PASS}@gitlab.xxx/AMAZON_myaccount/myproject.git cd myproject git checkout main if [ "$sourceEnv" == "UAT_PCI" ] then echo "copying the file to the UAT USE1 bucket" aws s3 cp 7day_rate/pfm_data.json s3://uatpci-pfm-data/data/test2/ echo "copying the file to the UAT USW2 bucket" aws s3 cp 7day_rate/pfm_data.json s3://uatpci-pfm-data-usw2/data/test/ fi ''' } } }
说明:
yum install -y git实现静默安装,-y参数自动跳过确认环节- 用
withCredentials安全获取Git凭证,避免明文暴露密码 - 替换为Shell原生的Git命令,适配容器内的Shell环境
方案2:构建带Git的自定义AWS CLI镜像(长期最优解)
每次安装Git会增加构建时间,建议构建包含Git的自定义aws-cli镜像,推送到你的Artifactory仓库:
- 创建
Dockerfile:
FROM artifactory.xxx/amazon/aws-cli:2.2.32 # 安装Git并清理yum缓存减小镜像体积 RUN yum install -y git && yum clean all && rm -rf /var/cache/yum
- 构建并推送镜像:
docker build -t artifactory.xxx/amazon/aws-cli-with-git:2.2.32 . docker push artifactory.xxx/amazon/aws-cli-with-git:2.2.32
- 修改Pipeline中的
podTemplate,替换为自定义镜像:
containerTemplate(name: 'aws-cli', image: 'artifactory.xxx/amazon/aws-cli-with-git:2.2.32', ttyEnabled: true, command: 'cat'),
之后Pod启动时就自带Git,无需每次重复安装。
方案3:添加独立的Git容器(隔离职责)
在PodTemplate中新增一个专门的Git容器用于代码拉取,通过共享卷让aws-cli容器访问代码:
- 修改
podTemplates配置,添加Git容器和共享卷:
podTemplates( label: agent, containers: [ containerTemplate(name: 'aws-cli', image: 'artifactory.xxx/amazon/aws-cli:2.2.32', ttyEnabled: true, command: 'cat'), containerTemplate(name: 'vault', image: 'artifactory.xxx/ease/hashicorp-vault:latest', ttyEnabled: true, command: 'cat'), containerTemplate(name: 'git', image: 'alpine/git:latest', ttyEnabled: true, command: 'cat') // 新增Git容器 ], volumes: [ hostPathVolume(hostPath: '/var/run/docker.sock', mountPath: '/var/run/docker.sock'), emptyDirVolume(mountPath: '/workspace', memory: false) // 共享卷,用于存储代码 ], imagePullSecrets: ['xxx'] )
- 在
Checkout Code阶段使用Git容器拉取代码:
stage("Checkout Code") { container('git') { // 使用Jenkins内置的checkout步骤,自动处理凭证 checkout([ $class: 'GitSCM', branches: [[name: 'main']], userRemoteConfigs: [[url: 'https://gitlab.xxx/AMAZON_myaccount/myproject.git', credentialsId: 'system-id']] ]) } }
- 修改
Sending the files to S3 bucket阶段,直接从共享卷访问代码:
stage('Sending the files to S3 bucket') { container('aws-cli') { sh ''' JOB_TITLE=`echo ${JOB_BASE_NAME} | sed 's/ /_/g'` set +x AWS_CRED=aws.cred export AWS_ACCESS_KEY_ID=$( awk '/access_key / {print $2}' $AWS_CRED ) export AWS_SECRET_ACCESS_KEY=$( awk '/secret_key / {print $2}' $AWS_CRED ) export AWS_SESSION_TOKEN=$( awk '/security_token / {print $2}' $AWS_CRED ) env | grep AWS set -x if [ "$sourceEnv" == "UAT_PCI" ] then echo "copying the file to the UAT USE1 bucket" aws s3 cp /workspace/7day_rate/pfm_data.json s3://uatpci-pfm-data/data/test2/ echo "copying the file to the UAT USW2 bucket" aws s3 cp /workspace/7day_rate/pfm_data.json s3://uatpci-pfm-data-usw2/data/test/ fi ''' } }
说明:
- 用轻量的
alpine/git镜像拉取代码,避免在aws-cli容器中安装额外工具 - 共享卷
/workspace在所有容器间共享,aws-cli容器可直接访问拉取的代码
内容的提问来源于stack exchange,提问作者sutterhome1976
相关产品推荐
相关产品推荐

