使用Github Actions推送Spring Boot构建的Docker镜像遇权限拒绝问题
问题
使用Github Actions自动化推送Spring Boot Maven插件(mvn spring-boot:build-image)生成的Docker镜像时,收到Maven权限拒绝错误:
Caused by: org.apache.maven.plugin.PluginExecutionException: Execution default-cli of goal org.springframework.boot:spring-boot-maven-plugin:3.0.0:build-image failed: Error response received when pushing image: denied: requested access to the resource is denied
当前使用的Github Actions配置如下:
- name: Build image & push run: | cd myFolder mvn -X spring-boot:build-image \ --batch-mode --no-transfer-progress \ -Dspring-boot.build-image.publish=true \ -Dspring-boot.build-image.imageName="MY_USER/demo-ms:0.1.0" \ -DCI_REGISTRY=https://index.docker.io/v1 \ -DCI_REGISTRY_USER=${{ secrets.DOCKERHUB_USERNAME }} \ -DCI_REGISTRY_PASSWORD=${{ secrets.DOCKERHUB_TOKEN }}
解决方法
核心问题是误用了GitLab CI的环境变量命名,Spring Boot Maven插件的Docker认证有专属参数规则,修正步骤如下:
- 替换认证参数名称
Spring Boot插件对应的正确Docker认证参数为:
-Dspring-boot.build-image.docker.registry:指定镜像仓库地址-Dspring-boot.build-image.docker.username:仓库用户名-Dspring-boot.build-image.docker.password:仓库访问令牌/密码
- 简化Docker Hub仓库地址
Docker Hub的仓库地址可直接写docker.io,无需带完整的https://index.docker.io/v1路径。
修正后的Github Actions配置:
- name: Build image & push run: | cd myFolder mvn -X spring-boot:build-image \ --batch-mode --no-transfer-progress \ -Dspring-boot.build-image.publish=true \ -Dspring-boot.build-image.imageName="MY_USER/demo-ms:0.1.0" \ -Dspring-boot.build-image.docker.registry=docker.io \ -Dspring-boot.build-image.docker.username=${{ secrets.DOCKERHUB_USERNAME }} \ -Dspring-boot.build-image.docker.password=${{ secrets.DOCKERHUB_TOKEN }}
- 额外验证项
- 确认
MY_USER是Docker Hub的真实用户名,且该用户对demo-ms镜像仓库拥有推送权限(私有仓库需提前创建) - 确认Github Secrets中的
DOCKERHUB_TOKEN是有效的Docker Hub访问令牌,且令牌已开启write权限
内容的提问来源于stack exchange,提问作者jabrena
相关产品推荐
相关产品推荐

