Jenkins Maven部署至S3 Bucket失败求助:连接被拒绝
Hey there, let's walk through troubleshooting this S3 deployment failure step by step—since you've already confirmed IAM permissions and Jenkins S3 connection tests pass, the issue is likely tied to how Maven's S3 wagon is configured or communicating with AWS.
1. Fix Your S3 Bucket URL/Endpoint Format
The Connection refused error points to Maven being unable to reach your specified S3 endpoint. Your current URL (s3://panda.bucket.net/snapshot) has a couple of potential issues:
- If
panda.bucket.netis a custom domain pointing to S3: Ensure you've set up a CNAME record linking it to your bucket's official AWS endpoint, and enabled static website hosting on the bucket if required. Note that some S3 wagon implementations require explicit endpoint configuration for custom domains. - If this is an AWS-native bucket name: Use the correct regional endpoint format. For example:
- For
us-east-1(default):s3://s3.amazonaws.com/panda.bucket.net/snapshot - For other regions (e.g.,
us-west-2):s3://s3.us-west-2.amazonaws.com/panda.bucket.net/snapshot
- For
- Bucket names with multiple dots (like
panda.bucket.net) often hit SSL certificate validation issues with virtual-host-style URLs. Switch to path-style access (as shown in step 3) to avoid this.
2. Update to a Maintained S3 Wagon
Your current com.allogy.maven.wagon:maven-s3-wagon:1.2.0 is quite outdated (last updated in 2017) and may lack support for modern AWS S3 endpoints or signature mechanisms. Replace it with a actively maintained alternative in your pom.xml:
<build> <extensions> <extension> <groupId>io.github.micheljung</groupId> <artifactId>s3-wagon</artifactId> <version>2.0.0</version> </extension> </extensions> </build>
3. Explicitly Configure S3 Endpoint & Access Style
Add regional endpoint and path-style access settings to your Maven settings.xml to resolve connectivity and SSL issues:
<settings> <server> <id>s3.artifacts.release</id> <username>MY_ACCESS_KEY</username> <password>MY_SECRET</password> <configuration> <endpoint>s3.us-west-2.amazonaws.com</endpoint> <!-- Replace with your bucket's region endpoint --> <pathStyleAccess>true</pathStyleAccess> <!-- Critical for bucket names with dots --> </configuration> </server> <server> <id>s3.artifacts.snapshot</id> <username>MY_ACCESS_KEY</username> <password>MY_SECRET</password> <configuration> <endpoint>s3.us-west-2.amazonaws.com</endpoint> <pathStyleAccess>true</pathStyleAccess> </configuration> </server> </settings>
4. Verify Jenkins Agent Network Connectivity
The Jenkins agent running your pipeline might be blocked from accessing S3 by firewalls or security groups. Test connectivity directly on the agent:
- Run
telnet panda.bucket.net 443to check TCP connectivity to the endpoint - Run
curl -v https://panda.bucket.netto validate HTTP/HTTPS access
If these fail, work with your network team to allow outbound traffic to S3 (or your custom domain) from the Jenkins agent's network.
5. Confirm Maven Settings Are Loaded Correctly
Ensure Jenkins is using the correct settings.xml during the build. Add a quick check step to your Jenkinsfile to verify:
stage('Validate Maven Settings') { steps { bat 'mvn help:effective-settings' } }
Review the output to confirm your S3 server configurations are present in the effective settings.
6. Test Deployment via AWS CLI (Optional)
Rule out IAM permission edge cases by testing S3 uploads directly from the Jenkins agent using AWS CLI:
aws s3 cp target/panda-app-1.0-SNAPSHOT.jar s3://panda.bucket.net/snapshot/com/panda/panda-app/1.0-SNAPSHOT/
If this works, permissions are solid, and the issue is definitely in your Maven configuration.
内容的提问来源于stack exchange,提问作者Dinesh Narayan

