Jenkins pipeline中docker.withRegistry执行失败求助
问题:Jenkins流水线Docker推送阶段失败
环境信息
OS: MacOS Ventura 13.0.1 Jenkins LTS 2.361.3(通过Homebrew安装,运行于本地MacOS主机) Docker 20.10.20(来自Docker Desktop)
流水线配置(Jenkinsfile)
pipeline { agent any // polling by schedular // triggers { // pollSCM('*/3 * * * *') // } environment { registry = 'my-docker-repository-name' registryCredential = 'my-jenkins-credential-for-dockerhub' dockerImage = '' } stages { stage('Echo') { agent any steps { echo 'from github repository' echo 'build number is ' + "${env.BUILD_NUMBER}" } } // stage for cloning your github repository stage('Prepare') { agent any steps { echo 'Cloning Repository' git url: 'my-github-repository-url', branch: 'master', credentialsId: 'jenkins-credential-for-github' } post { failure { error 'This pipeline stops here...' } } } // gradle build stage('Bulid Gradle') { agent any steps { echo 'Bulid Gradle' dir ('.'){ sh './gradlew clean build' } } post { failure { error 'This pipeline stops here...' } } } // docker build stage('Bulid Docker') { agent any steps { echo 'Bulid Docker' script { dockerImage = docker.build registry } } post { failure { error 'This pipeline stops here...' } } } // docker push stage('Push Docker') { agent any steps { echo 'Push Docker' script { docker.withRegistry('https://registry.hub.docker.com', registryCredential) { dockerImage.push("${env.BUILD_NUMBER}") dockerImage.push('latest') } } } post { failure { error 'This pipeline stops here...' } } } } }
错误信息
Using the existing docker config file.Removing blacklisted property: authsRemoving blacklisted property: credsStore$ docker login -u me -p me https://registry.hub.docker.com Current context "desktop-linux" is not found on the file system, please check your config file at /Users/me/.jenkins/workspace/ci-pipeline@2@tmp/6e9fd8bf-aa3e-4654-b7b6-54b6138478df/config.json
注:当
Push Docker阶段使用docker.withRegistry('')(不指定URL和Docker Hub凭证)时,镜像推送可成功。
其他相关配置
Dockerfile
FROM openjdk:11-jdk LABEL maintainer="email" ARG JAR_FILE=build/libs/me-0.0.1-SNAPSHOT.jar ADD ${JAR_FILE} me.jar ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/docker-springboot.jar"]
.docker/config.json
{ "auths": { "https://index.docker.io/v1/": {}, "registry.hub.docker.com": {} }, "credsStore": "desktop", "currentContext": "desktop-linux" }
Jenkins plist配置(/opt/homebrew/Cellar/jenkins-lts/2.361.3)
<?xml version="1.0" encoding="UTF-8"?> <plist version="1.0"> <dict> <key>Label</key> <string>Aqua</string> <string>Background</string> <string>LoginWindow</string> <string>StandardIO</string> <string>System</string> </array> <key>ProgramArguments</key> <array> <string>/opt/homebrew/opt/openjdk@17/bin/java</string> <string>-Dmail.smtp.starttls.enable=true</string> <string>-jar</string> <string>/opt/homebrew/opt/jenkins-lts/libexec/jenkins.war</string> <string>--httpListenAddress=127.0.0.1</string> <string>--httpPort=8888</string> </array> <key>RunAtLoad</key> <true/> <key>EnvironmentVariables</key> <dict> <key>PATH</key> <string>/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/Docker.app/Contents/Resources/bin/:/Users/me/Library/Group\ Containers/group.com.docker</string> </dict> </dict> </plist>
问题分析与解决方法
核心问题
- Docker Hub地址错误:
https://registry.hub.docker.com不是Docker Hub的标准API地址,正确地址为https://index.docker.io/v1/,或可直接留空(Jenkins Docker插件会自动识别Docker Hub)。 - 凭证存储权限问题:
.docker/config.json中credsStore设为desktop,凭证存储在Docker Desktop的加密存储中,但Jenkins作为后台服务无权限访问桌面级存储。 - Docker上下文不匹配:错误提示的
desktop-linux是Docker Desktop专属上下文,Jenkins运行环境无法加载该上下文文件。
解决步骤
1. 修正Docker Registry地址
修改Push Docker阶段的docker.withRegistry配置,使用正确地址或省略URL:
// 使用标准Docker Hub地址 docker.withRegistry('https://index.docker.io/v1/', registryCredential) { dockerImage.push("${env.BUILD_NUMBER}") dockerImage.push('latest') } // 或直接省略URL(插件自动处理Docker Hub) docker.withRegistry('', registryCredential) { dockerImage.push("${env.BUILD_NUMBER}") dockerImage.push('latest') }
2. 更改Docker凭证存储方式
将凭证存储改为文件模式(仅适合本地开发环境,注意安全性):
- 执行命令:
docker config set credsStore "" - 重新登录Docker Hub:
docker login,此时~/.docker/config.json会生成明文auth字段。
3. 确保Jenkins用户有权限访问Docker配置
Homebrew安装的Jenkins默认以jenkins用户运行,需赋予其Docker访问权限:
- 将
jenkins加入docker组:sudo dscl . append /Groups/docker GroupMembership jenkins - 复制个人Docker配置到Jenkins用户目录:
sudo cp ~/.docker/config.json /Users/jenkins/.docker/ - 修改文件权限:
sudo chown -R jenkins:staff /Users/jenkins/.docker/
4. 移除无效Docker上下文配置
编辑~/.docker/config.json,删除currentContext字段:
{ "auths": { "https://index.docker.io/v1/": {}, "registry.hub.docker.com": {} }, "credsStore": "file" }
验证
完成上述修改后,重新运行Jenkins流水线,Push Docker阶段即可正常推送镜像至Docker Hub。
内容的提问来源于stack exchange,提问作者shoukou-lee
相关产品推荐
相关产品推荐

