You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins与Github间歇性认证失败问题求助

Jenkins 首次构建GitHub仓库认证失败,重试正常的问题排查

问题现象

代码托管在GitHub,使用Jenkins进行克隆与构建:

  • 首次启动构建立即失败,报错:
ERROR: Error cloning remote repo 'origin'
stderr: remote: Invalid username or password.
  • 重新运行任务则正常构建,后续95%的情况均可成功。

环境信息

  • Jenkins版本:2.332.2(从2.263.4升级后问题依旧)
  • 操作系统:MacOS Monterey 12.4(Big Sur系统下同样存在该问题)
  • 所有Git相关插件均已更新至最新版本

失败任务日志

Started by user d***
12:21:27 Connecting to https://api.github.com using github-app-***
Obtained Jenkinsfile_client from ***
Loading library c***shared-lib***@**shared***
Examining ***shared-lib***
Attempting to resolve **shared*** as a branch
Resolved **shared*** as branch **shared*** at revision ***cda***
The recommended git tool is: NONE
using credential github-app-***
 > git rev-parse --resolve-git-dir /var/jenkins_home/workspace/***_utils***_upm@libs/***167***/.git # timeout=10
Fetching changes from the remote Git repository
 > git config remote.origin.url https://github.com/***shared-lib***.git # timeout=10
Fetching without tags
Fetching upstream changes from https://github.com/***shared-lib***.git
 > git --version # timeout=10
 > git --version # 'git version 2.30.2'
using GIT_ASKPASS to set credentials 
 > git fetch --no-tags --force --progress -- https://github.com/***shared-lib***.git +refs/heads/**shared***:refs/remotes/origin/**shared*** # timeout=10
Checking out Revision ***cda*** (**shared***)
 > git config core.sparsecheckout # timeout=10
 > git checkout -f ***cda*** # timeout=10
Commit message: "updated ***"
[Pipeline] Start of Pipeline
[Pipeline] node
Running on Mac Server ABC (mm) in /Users/xxx/***_utils***_upm
[Pipeline] {
[Pipeline] stage
[Pipeline] { (Declarative: Checkout SCM)
[Pipeline] checkout
The recommended git tool is: NONE
using credential github-app-***
Cloning the remote Git repository
Cloning with configured refspecs honoured and without tags
Cloning repository https://github.com/***/utils***.git
 > git init /Users/xxx/***_utils***_upm # timeout=10
Fetching upstream changes from https://github.com/***/utils***.git
 > git --version # timeout=10
 > git --version # 'git version 2.30.1 (Apple Git-130)'
using GIT_ASKPASS to set credentials 
 > git fetch --no-tags --force --progress -- https://github.com/***/utils***.git +refs/heads/upm:refs/remotes/origin/upm # timeout=10
ERROR: Error cloning remote repo 'origin'
hudson.plugins.git.GitException: Command "git fetch --no-tags --force --progress -- https://github.com/***/utils***.git +refs/heads/upm:refs/remotes/origin/upm" returned status code 128:
stdout: 
stderr: remote: Invalid username or password.
fatal: Authentication failed for 'https://github.com/***/utils***.git/'

    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandIn(CliGitAPIImpl.java:2671)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandWithCredentials(CliGitAPIImpl.java:2096)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.access$500(CliGitAPIImpl.java:84)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:618)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$2.execute(CliGitAPIImpl.java:847)
    at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler$GitCommandMasterToSlaveCallable.call(RemoteGitImpl.java:158)
    at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler$GitCommandMasterToSlaveCallable.call(RemoteGitImpl.java:151)
    at hudson.remoting.UserRequest.perform(UserRequest.java:211)
    at hudson.remoting.UserRequest.perform(UserRequest.java:54)
    at hudson.remoting.Request$2.run(Request.java:376)
    at hudson.remoting.InterceptingExecutorService.lambda$wrap$0(InterceptingExecutorService.java:78)
    at java.util.concurrent.FutureTask.run(FutureTask.java:266)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
    at java.lang.Thread.run(Thread.java:748)
    Suppressed: hudson.remoting.Channel$CallSiteStackTrace: Remote call to Mac Server ABC (mm)
    ...

注:执行「Rebuild」操作后可正常完成构建。

排查方向与解决方案

1. GitHub App凭据初始化延迟

你使用的是GitHub App凭据,首次构建时Jenkins可能未完成凭据的动态生成/刷新流程,导致首次请求传递的凭据无效;重试时凭据已完成初始化,因此请求成功。

  • 处理方案:
    • 在Jenkins的GitHub App配置中,添加凭据预加载逻辑;
    • 在Pipeline的checkout步骤前添加短延迟(比如sleep 5),给凭据生成留足时间。

2. Agent节点Git凭据缓存问题

从日志看,首次构建在Mac Agent节点执行,使用的是Apple Git-130,而Jenkins Master使用的是git version 2.30.2。Agent节点首次克隆时,GIT_ASKPASS传递的凭据可能未被正确缓存,重试时缓存生效。

  • 处理方案:
    • 在Agent节点手动执行一次git fetch目标仓库,确认凭据可正常使用,触发Git凭据缓存;
    • 修改Agent节点的Git配置,禁用凭据助手的自动清理,或配置持久化的凭据存储。

3. Jenkins Git插件并发凭据冲突

当多个Pipeline同时启动时,首次构建的凭据请求可能被并发请求干扰,导致凭据传递错误;重试时并发压力降低,请求恢复正常。

  • 处理方案:
    • 检查Jenkins全局配置中Git插件的「凭据缓存超时」设置,适当延长超时时间;
    • 给Pipeline添加互斥锁,避免同一仓库的首次构建并发执行。

4. MacOS钥匙串权限问题

MacOS的钥匙串可能阻止Jenkins Agent进程首次访问凭据,重试时权限已被授予。

  • 处理方案:
    • 在Agent节点的钥匙串中,添加Jenkins运行用户对Git相关凭据的访问权限;
    • 禁用Agent节点Git的钥匙串凭据助手,改用Jenkins内置的凭据管理。

内容的提问来源于stack exchange,提问作者mg-ddci

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 11:36:06