Jenkins Pipeline中Shell脚本执行失败,请求排查指引
Jenkins Pipeline Shell脚本执行失败排查思路
问题背景
尝试了多个在线教程仍无法定位Jenkins Pipeline中Shell脚本执行失败的原因,请求排查思路。
Pipeline配置
pipeline { options { buildDiscarder( logRotator( artifactDaysToKeepStr: '15', artifactNumToKeepStr: '15', daysToKeepStr: '15', numToKeepStr: '15')) disableConcurrentBuilds() skipDefaultCheckout true timeout(time: 30, unit: 'MINUTES') ansiColor('xterm') } parameters { booleanParam( name: 'Refresh', defaultValue: false, description: 'Reload job from the Jenkinsfile and then exit') } agent { label 'built-in' } triggers { cron '0 8 * * *' } stages { stage('Build') { when { expression { !params.Refresh } } steps { script { sh ''' set +x apt-get update && apt install dnsutils -y nslookup git.github-private.com | grep \"Non-authoritative answer\" -A 3 git_av_url=$(nslookup git.github-private.com | grep \"Non-authoritative answer\" -A 3 | grep git | awk \'{print $2}\') git_av_ip=$(nslookup git.github-private.com | grep \"Non-authoritative answer\" -A 3 | grep Address | awk \'{print $2}\') echo $git_av_ip echo $git_av_ip $git_av_url >> /etc/hosts cat /etc/hosts''' } } } } }
执行输出
09:28:53 [Pipeline] stage 09:28:53 [Pipeline] { (Build) 09:28:53 [Pipeline] script 09:28:53 [Pipeline] { 09:28:53 [Pipeline] sh 09:28:53 + set -ex 09:28:53 + apt-get update 09:28:53 Hit:1 http://security.debian.org/debian-security bullseye-security InRelease 09:28:53 Hit:2 http://deb.debian.org/debian bullseye InRelease 09:28:53 Hit:3 http://deb.debian.org/debian bullseye-updates InRelease 09:28:54 Reading package lists... 09:28:54 + apt install dnsutils -y 09:28:54 09:28:54 WARNING: apt does not have a stable CLI interface. Use with caution in scripts. 09:28:54 09:28:55 Reading package lists... 09:28:55 Building dependency tree... 09:28:55 Reading state information... 09:28:55 dnsutils is already the newest version (1:9.16.33-1~deb11u1). 09:28:55 0 upgraded, 0 newly installed, 0 to remove and 43 not upgraded. 09:28:55 + nslookup git.github-private.com 09:28:55 + grep Non-authoritative answer -A 3 09:28:55 [Pipeline] } 09:28:55 [Pipeline] // script 09:28:55 [Pipeline] } 09:28:55 [Pipeline] // stage 09:28:55 [Pipeline] } 09:28:55 09:28:55 [Pipeline] // ansiColor 09:28:55 [Pipeline] } 09:28:55 [Pipeline] // timeout 09:28:55 [Pipeline] } 09:28:56 [Pipeline] // node 09:28:56 [Pipeline] End of Pipeline 09:28:56 ERROR: script returned exit code 1 09:28:56 Finished: FAILURE
排查步骤
1. 锁定失败的具体命令
从执行日志看,脚本执行到nslookup git.github-private.com | grep "Non-authoritative answer" -A 3后直接退出,返回码1。核心原因是Jenkins的sh步骤默认启用set -e(脚本里的set +x仅关闭命令打印,不影响set -e),而grep未匹配到内容时会返回非0退出码,触发set -e导致整个脚本终止。
2. 查看nslookup完整输出
当前脚本仅过滤部分结果,无法确认解析是否正常。修改脚本先打印nslookup全部输出:
sh ''' set +x apt-get update && apt install dnsutils -y # 先打印完整解析结果 nslookup git.github-private.com # 后续操作保留但忽略grep退出码 nslookup git.github-private.com | grep \"Non-authoritative answer\" -A 3 || true ... '''
通过完整输出可明确域名是否解析成功,以及结果中是否包含Non-authoritative answer字符串。
3. 处理grep退出码问题
如果允许grep无匹配的情况,添加|| true忽略其退出码,避免脚本终止:
nslookup git.github-private.com | grep \"Non-authoritative answer\" -A 3 || true
更健壮的方式是先捕获nslookup结果,再从中提取信息,避免重复执行解析:
nslookup_output=$(nslookup git.github-private.com) echo "$nslookup_output" git_av_url=$(echo "$nslookup_output" | grep \"Non-authoritative answer\" -A 3 | grep git | awk \'{print $2}\') git_av_ip=$(echo "$nslookup_output" | grep \"Non-authoritative answer\" -A 3 | grep Address | awk \'{print $2}\')
4. 提前检查权限问题
后续脚本需要写入/etc/hosts,若Jenkins agent未以root用户运行,会出现权限拒绝错误。可提前在写入命令前添加sudo(若有权限),或确认agent用户具备写入权限。
5. 开启Shell调试模式
将脚本中的set +x改为set -x,强制打印每一条执行的命令及参数,便于清晰追踪脚本执行细节。
内容的提问来源于stack exchange,提问作者AhmFM
相关产品推荐
相关产品推荐

