Docker环境中Poetry安装私有包突然失败问题排查
问题背景
最小可复现示例:私有GitLab仓库项目
我一直使用Poetry构建Docker镜像,安装内部PyPI源的Python包。由于项目在私有GitLab仓库,且内部包并非绝密,我将Poetry凭据直接存储在pyproject.toml的源URL中。
在2022-08-24,所有Docker构建在安装内部包时突然失败,报错如下:
• Installing til-bigquery (0.3.4) HTTPError 401 Client Error: Unauthorized for url: https://gitlab.com/api/v4/projects/38869805/packages/pypi/files/7a4731d831d4b37262481002271e359f96017570e9480ef16c89489e0b41252f/til_bigquery-0.3.4-py3-none-any.whl#sha256=7a4731d831d4b37262481002271e359f96017570e9480ef16c89489e0b41252f at /usr/local/lib/python3.9/site-packages/requests/models.py:1021 in raise_for_status 1017│ f"{self.status_code} Server Error: {reason} for url: {self.url}" 1018│ ) 1019│ 1020│ if http_error_msg: → 1021│ raise HTTPError(http_error_msg, response=self) 1022│ 1023│ def close(self): 1024│ 1025│ called the underlying ``raw`` object must not be accessed again.
异常点
- 重试之前成功过的部署任务,Docker构建仍失败。
- 怀疑是Docker基础镜像
python:3.7-slim或Poetry的未固定小版本导致,使用旧版本后问题依旧。 - 对比成功构建日志
build_success.log(2022-08-22 15:00)与失败日志build_fail.log(2022-08-24 06:00),发现两者使用相同的Poetry包poetry-1.1.15-py2.py3-none-any.whl。
本地正常但Docker中失败
- 移除仓库URL中的凭据后,本地也无法正常工作,确认凭据未存储在其他位置(如~/.netrc)。
复现步骤:
- 本地环境 - 正常
git clone <私有GitLab仓库地址> poetry install
- Docker环境 - 失败
git clone <私有GitLab仓库地址> docker build .
我可以通过在Dockerfile中显式配置凭据解决问题:
RUN pip install poetry --no-cache-dir && \ poetry config virtualenvs.create false && \ poetry config repositories.my_private_repo https://gitlab.com/api/v4/projects/21870843/packages/pypi/simple && \ poetry config http-basic.my_private_repo __token__ glpat-mkEPJ4Rsy2peTCrH23pG
但这无法解释为何相同镜像的构建突然失败,以及为何本地环境仍能正常工作。
有人知道可能的变化点吗?对比build_success.log和build_fail.log也未发现差异。
内容的提问来源于stack exchange,提问作者Hynek Blaha
相关产品推荐
相关产品推荐

