GitLab搭建IaC扫描流水线遇系统问题求助
问题:GitLab IaC扫描(KICS)执行失败,报错exit status 2
尝试使用GitLab的Infrastructure as Code (IaC)扫描工具检测配置文件中的已知漏洞,参照官方文档配置后,流水线执行过程中出现系统错误,日志如下:
[DEBU] [kics] [2022-11-11T03:55:29Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command@v1.9.2/run.go:256] ▶ SAST_EXCLUDED_PATHS=spec,test,tests,tmp39 [INFO] [kics] [2022-11-11T03:55:29Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command@v1.9.2/run.go:131] ▶ Detecting project [INFO] [kics] [2022-11-11T03:55:29Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command@v1.9.2/run.go:153] ▶ Analyzer will attempt to analyze all projects in the repository41 [INFO] [kics] [2022-11-11T03:55:29Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command@v1.9.2/run.go:165] ▶ Running analyzer42 [DEBU] [kics] [2022-11-11T03:55:29Z] [/go/src/app/analyze.go:48] ▶ custom rulesets not enabled [INFO] [kics] [2022-11-11T03:55:29Z] [/go/src/app/analyze.go:67] ▶ path /builds/leo/tcf [ERRO] [kics] [2022-11-11T03:55:38Z] [/go/src/app/analyze.go:87] ▶ Encountered a system problem; status code: 2, error: exit status 2, detail: [FATA] [kics] [2022-11-11T03:55:38Z] [/go/src/app/main.go:30] ▶ kics scanner failure: exit status 2 Uploading artifacts for failed job00:0048Uploading artifacts... WARNING: gl-sast-report.json: no matching files. Ensure that the artifact path is relative to the working directory ERROR: No files to upload Cleaning up project directory and file based variables00:0154ERROR: Job failed: exit code 1
解决方案建议
- 检查扫描路径权限:确认流水线runner进程对
/builds/leo/tcf目录拥有读取权限,若权限不足需调整目录权限或runner配置。 - 验证IaC文件语法:exit status 2通常因配置文件(如Terraform
.tf、CloudFormation.yaml)存在语法错误导致,手动检查目录下所有IaC文件的语法有效性。 - 修正排除路径配置:当前
SAST_EXCLUDED_PATHS包含tmp39,检查是否为拼写错误;可临时清空该变量,排除路径配置错误引发的扫描异常。 - 升级分析器版本:当前使用的analyzer版本为v1.9.2,旧版本可能存在已知bug,可通过设置CI变量
SAST_ANALYZER_IMAGE_TAG为最新稳定版本来升级。 - 启用调试日志:在流水线变量中添加
SAST_DEBUG: "true",获取更详细的扫描过程日志,定位具体出错的文件或规则。
内容的提问来源于stack exchange,提问作者lam
相关产品推荐
相关产品推荐

