从Jenkins部署Kubernetes遇SSL证书错误,如何跳过SSL验证?
Got it, let's fix that SSL handshake error you're facing when deploying to Kubernetes from Jenkins. Skipping TLS verification is a quick workaround to unblock your workflow, though I strongly recommend setting up proper certificate trust for production environments long-term. Here are the most common ways to implement this:
1. Disable SSL Check in Jenkins Kubernetes Cloud Configuration
If you've set up Kubernetes as a cloud in Jenkins, you can toggle this setting globally for that cluster:
- Navigate to Manage Jenkins > Configure System
- Scroll down to the Kubernetes cloud section (you might have named it something specific)
- Look for the checkbox labeled Disable SSL certificate check and tick it
- Save your configuration and retry the deployment
2. Update Your Kubeconfig File
If Jenkins uses a kubeconfig to connect to Kubernetes, modify the file to skip TLS verification for your cluster:
- Locate the kubeconfig Jenkins is using (this could be stored on the Jenkins server, or as a file credential in Jenkins)
- Find the
clustersblock for your target Kubernetes cluster, and addinsecure-skip-tls-verify: trueunder theclustersection:clusters: - cluster: server: https://your-k8s-api-server-url insecure-skip-tls-verify: true # Add this line to skip validation # Leave existing fields like certificate-authority-data if present name: your-cluster-name - If the kubeconfig is a Jenkins credential, re-upload the updated file and re-run your job
3. Skip Verification in Your Jenkinsfile (Pipeline)
If you're using a Jenkins Pipeline, you can add the skip flag directly in your deployment steps:
For kubectl commands
When running raw kubectl commands, append the --insecure-skip-tls-verify flag:
sh 'kubectl --insecure-skip-tls-verify apply -f ./deployment.yaml'
For Kubernetes Pipeline Plugin
If you're using the official Kubernetes Deploy plugin, include the insecureSkipTlsVerify parameter:
kubernetesDeploy( kubeconfigId: 'your-kubeconfig-credential-id', manifests: './deployment.yaml', insecureSkipTlsVerify: true )
Important Note
Remember that skipping SSL/TLS validation bypasses critical security checks—this should only be used in non-production environments or as a temporary fix. For production, you should add your Kubernetes cluster's CA certificate to Jenkins' JVM truststore so the connection is properly secured.
内容的提问来源于stack exchange,提问作者prabha vk

