You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins pipeline中docker.withRegistry执行失败求助

问题:Jenkins流水线Docker推送阶段失败

环境信息

OS: MacOS Ventura 13.0.1
Jenkins LTS 2.361.3(通过Homebrew安装,运行于本地MacOS主机)
Docker 20.10.20(来自Docker Desktop)

流水线配置(Jenkinsfile)

pipeline {
    agent any

    // polling by schedular
    // triggers {
    //     pollSCM('*/3 * * * *')
    // }

    environment {
        registry = 'my-docker-repository-name'
        registryCredential = 'my-jenkins-credential-for-dockerhub'
        dockerImage = ''
    }

    stages {
        stage('Echo') {
            agent any
            steps {
                echo 'from github repository'
                echo 'build number is ' + "${env.BUILD_NUMBER}"
            }
        }
        // stage for cloning your github repository
        stage('Prepare') {
            agent any
            steps {
                echo 'Cloning Repository'
                git url: 'my-github-repository-url',
                branch: 'master',
                credentialsId: 'jenkins-credential-for-github' 
            }
            post {
                failure {
                    error 'This pipeline stops here...'
                }
            }
        }

        // gradle build
        stage('Bulid Gradle') {
            agent any
            steps {
                echo 'Bulid Gradle'
                dir ('.'){
                  sh './gradlew clean build'
                }
            }
            post {
                failure {
                    error 'This pipeline stops here...'
                }
            }
        }

        // docker build
        stage('Bulid Docker') {
            agent any
            steps {
                echo 'Bulid Docker'
                script {
                    dockerImage = docker.build registry
                }
            }
            post {
                failure {
                  error 'This pipeline stops here...'
                }
            }
        }

        // docker push
        stage('Push Docker') {
            agent any
            steps {
                echo 'Push Docker'
                script {
                    docker.withRegistry('https://registry.hub.docker.com', registryCredential) {
                        dockerImage.push("${env.BUILD_NUMBER}") 
                        dockerImage.push('latest')
                    }
                }
            }
            post {
                failure {
                    error 'This pipeline stops here...'
                }
            }
        }
    }
}

错误信息

Using the existing docker config file.Removing blacklisted property: authsRemoving blacklisted property: credsStore$ docker login -u me -p me https://registry.hub.docker.com
Current context "desktop-linux" is not found on the file system, please check your config file at /Users/me/.jenkins/workspace/ci-pipeline@2@tmp/6e9fd8bf-aa3e-4654-b7b6-54b6138478df/config.json

注:当Push Docker阶段使用docker.withRegistry('')(不指定URL和Docker Hub凭证)时,镜像推送可成功。

其他相关配置

Dockerfile

FROM openjdk:11-jdk
LABEL maintainer="email"
ARG JAR_FILE=build/libs/me-0.0.1-SNAPSHOT.jar
ADD ${JAR_FILE} me.jar
ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/docker-springboot.jar"]

.docker/config.json

{
        "auths": {
                "https://index.docker.io/v1/": {},
                "registry.hub.docker.com": {}
        },
        "credsStore": "desktop",
        "currentContext": "desktop-linux"
}

Jenkins plist配置(/opt/homebrew/Cellar/jenkins-lts/2.361.3)

<?xml version="1.0" encoding="UTF-8"?>
<plist version="1.0">
<dict>
        <key>Label</key>
                <string>Aqua</string>
                <string>Background</string>
                <string>LoginWindow</string>
                <string>StandardIO</string>
                <string>System</string>
        </array>
        <key>ProgramArguments</key>
        <array>
                <string>/opt/homebrew/opt/openjdk@17/bin/java</string>
                <string>-Dmail.smtp.starttls.enable=true</string>
                <string>-jar</string>
                <string>/opt/homebrew/opt/jenkins-lts/libexec/jenkins.war</string>
                <string>--httpListenAddress=127.0.0.1</string>
                <string>--httpPort=8888</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>EnvironmentVariables</key>
        <dict>
                <key>PATH</key>
                <string>/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/Docker.app/Contents/Resources/bin/:/Users/me/Library/Group\ Containers/group.com.docker</string>
        </dict>
</dict>
</plist>

问题分析与解决方法

核心问题

  1. Docker Hub地址错误:https://registry.hub.docker.com不是Docker Hub的标准API地址,正确地址为https://index.docker.io/v1/,或可直接留空(Jenkins Docker插件会自动识别Docker Hub)。
  2. 凭证存储权限问题:.docker/config.json中credsStore设为desktop,凭证存储在Docker Desktop的加密存储中,但Jenkins作为后台服务无权限访问桌面级存储。
  3. Docker上下文不匹配:错误提示的desktop-linux是Docker Desktop专属上下文,Jenkins运行环境无法加载该上下文文件。

解决步骤

1. 修正Docker Registry地址

修改Push Docker阶段的docker.withRegistry配置,使用正确地址或省略URL:

// 使用标准Docker Hub地址
docker.withRegistry('https://index.docker.io/v1/', registryCredential) {
    dockerImage.push("${env.BUILD_NUMBER}") 
    dockerImage.push('latest')
}

// 或直接省略URL(插件自动处理Docker Hub)
docker.withRegistry('', registryCredential) {
    dockerImage.push("${env.BUILD_NUMBER}") 
    dockerImage.push('latest')
}

2. 更改Docker凭证存储方式

将凭证存储改为文件模式(仅适合本地开发环境,注意安全性):

  • 执行命令:docker config set credsStore ""
  • 重新登录Docker Hub:docker login,此时~/.docker/config.json会生成明文auth字段。

3. 确保Jenkins用户有权限访问Docker配置

Homebrew安装的Jenkins默认以jenkins用户运行,需赋予其Docker访问权限:

  • 将jenkins加入docker组:sudo dscl . append /Groups/docker GroupMembership jenkins
  • 复制个人Docker配置到Jenkins用户目录:sudo cp ~/.docker/config.json /Users/jenkins/.docker/
  • 修改文件权限:sudo chown -R jenkins:staff /Users/jenkins/.docker/

4. 移除无效Docker上下文配置

编辑~/.docker/config.json,删除currentContext字段:

{
        "auths": {
                "https://index.docker.io/v1/": {},
                "registry.hub.docker.com": {}
        },
        "credsStore": "file"
}

验证

完成上述修改后,重新运行Jenkins流水线,Push Docker阶段即可正常推送镜像至Docker Hub。


内容的提问来源于stack exchange,提问作者shoukou-lee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 11:37:02