You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Compute Engine实例安装Jenkins插件遇HTTP 401未授权问题

问题描述

我创建了GCP VM实例并可通过SSH访问。

miki@devsecops-cloud:~/kubernetes-devops-security/setup/jenkins-plugins$ ls -la
total 16
drwxrwxr-x 2 miki miki 4096 Sep 20 10:36 .
drwxrwxr-x 6 miki miki 4096 Sep 20 10:36 ..
-rw-rw-r-- 1 miki miki 1100 Sep 20 10:36 plugin-installer.sh
-rw-rw-r-- 1 miki miki  171 Sep 20 10:36 plugins.txt

下一步尝试通过bash脚本安装Jenkins插件,运行报错:

sudo bash plugin-installer.sh 
parse error: Invalid numeric literal at line 2, column 0
parse error: Invalid numeric literal at line 2, column 0
http://localhost:8080


........Installing performance@3.18 ..
<html>
<head>
<meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1"/>
<title>Error 401 Unauthorized</title>
</head>
<body><h2>HTTP ERROR 401 Unauthorized</h2>
<table>
<tr><th>URI:</th><td>/pluginManager/installNecessaryPlugins</td></tr>
<tr><th>STATUS:</th><td>401</td></tr>
<tr><th>MESSAGE:</th><td>Unauthorized</td></tr>
<tr><th>SERVLET:</th><td>Stapler</td></tr>
</table>
<hr/><a href="https://eclipse.org/jetty">Powered by Jetty:// 10.0.11</a><hr/>

曾猜测和GCP凭证有关,主机和VM的账号配置如下:

  • 主机账号列表:
gcloud auth list
       Credentialed Accounts
ACTIVE  ACCOUNT
*       johnholmes@gmail.com

To set the active account, run:
    $ gcloud config set account `ACCOUNT
  • VM实例账号列表:
gcloud auth list
                  Credentialed Accounts
ACTIVE  ACCOUNT
*       931909916149-compute@developer.gserviceaccount.com

To set the active account, run:
    $ gcloud config set account `ACCOUNT`

已在VM上登录个人账号,但问题依旧:

gcloud auth login
Your credentials may be visible to others with access to this
virtual machine. Are you sure you want to authenticate with
your personal account?

Do you want to continue (Y/n)?  y

Go to the following link in your browser:

    https://accounts.google.com/o/oauth2/auth?response_type=code&client_id=32312940559.apps.googleusercontent.com&redirect_uri=https%3A%2F%2Fsdk.cloud.google.com%2Fauthcode.html&scope=openid+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fuserinfo.email+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fcloud-platform+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fappengine.admin+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fsqlservice.login+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fcompute+https%3A%2F%2Fwww.googleapis.com%2Fauth%2Faccounts.reauth&state=emNPFQkW7AHLJG97s6QGUqRSvvpCVV&prompt=consent&access_type=offline&code_challenge=LtH3n7LWTG8SZfOBT8jKZTrkb-fWECYekLVKNn2REBo&code_challenge_method=S256

Enter authorization code: 4/0ARtbsJrLZR41bqLkT2--0J9vOllonBoA2NU2l7NcI7nMGD0nbjFiRFSRkj2Cr7mjlADhHw

You are now logged in as [johnholmes@gmail.com].
解决方案

首先明确:这个401错误和GCP凭证完全无关,是Jenkins自身的认证机制导致的——新安装的Jenkins需要初始化密码,或者脚本没有正确传递Jenkins的认证信息。

步骤1:获取Jenkins初始化密码

新安装的Jenkins默认会生成一个初始化密码,路径通常是:

sudo cat /var/lib/jenkins/secrets/initialAdminPassword

复制这个密码,后续脚本需要用到。

步骤2:修改插件安装脚本,添加Jenkins认证信息

你的plugin-installer.sh脚本没有传递Jenkins的用户名和密码(或者初始化密码),导致访问/pluginManager/installNecessaryPlugins时被拒绝。需要修改脚本,在调用Jenkins API时携带认证信息:

如果脚本用curl调用API,需加上--user参数:

# 替换成你的Jenkins初始化密码(或已创建的管理员密码)
JENKINS_PASSWORD="你的初始化密码"
curl --user admin:$JENKINS_PASSWORD http://localhost:8080/pluginManager/installNecessaryPlugins ...

如果脚本用Jenkins CLI,需先获取cli.jar并携带认证:

curl -O http://localhost:8080/jnlpJars/jenkins-cli.jar
java -jar jenkins-cli.jar -s http://localhost:8080/ install-plugin < plugins.txt --username admin --password $JENKINS_PASSWORD

步骤3:处理脚本中的解析错误

脚本开头的parse error: Invalid numeric literal错误,大概率是脚本编码问题(比如包含Windows换行符),或者第一行shebang写错了。检查脚本第一行是否为:

#!/bin/bash

如果是Windows编辑的脚本,用dos2unix转换格式:

sudo apt install dos2unix -y
dos2unix plugin-installer.sh

额外提醒:避免使用sudo运行Jenkins脚本

Jenkins默认以jenkins用户运行,用sudo执行脚本会导致文件权限问题,建议切换到jenkins用户执行:

sudo su - jenkins
bash /home/miki/kubernetes-devops-security/setup/jenkins-plugins/plugin-installer.sh

内容的提问来源于stack exchange,提问作者Richard Rublev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 01:50:36