Jenkins与Github间歇性认证失败问题求助
Jenkins 首次构建GitHub仓库认证失败,重试正常的问题排查
问题现象
代码托管在GitHub,使用Jenkins进行克隆与构建:
- 首次启动构建立即失败,报错:
ERROR: Error cloning remote repo 'origin' stderr: remote: Invalid username or password.
- 重新运行任务则正常构建,后续95%的情况均可成功。
环境信息
- Jenkins版本:2.332.2(从2.263.4升级后问题依旧)
- 操作系统:MacOS Monterey 12.4(Big Sur系统下同样存在该问题)
- 所有Git相关插件均已更新至最新版本
失败任务日志
Started by user d*** 12:21:27 Connecting to https://api.github.com using github-app-*** Obtained Jenkinsfile_client from *** Loading library c***shared-lib***@**shared*** Examining ***shared-lib*** Attempting to resolve **shared*** as a branch Resolved **shared*** as branch **shared*** at revision ***cda*** The recommended git tool is: NONE using credential github-app-*** > git rev-parse --resolve-git-dir /var/jenkins_home/workspace/***_utils***_upm@libs/***167***/.git # timeout=10 Fetching changes from the remote Git repository > git config remote.origin.url https://github.com/***shared-lib***.git # timeout=10 Fetching without tags Fetching upstream changes from https://github.com/***shared-lib***.git > git --version # timeout=10 > git --version # 'git version 2.30.2' using GIT_ASKPASS to set credentials > git fetch --no-tags --force --progress -- https://github.com/***shared-lib***.git +refs/heads/**shared***:refs/remotes/origin/**shared*** # timeout=10 Checking out Revision ***cda*** (**shared***) > git config core.sparsecheckout # timeout=10 > git checkout -f ***cda*** # timeout=10 Commit message: "updated ***" [Pipeline] Start of Pipeline [Pipeline] node Running on Mac Server ABC (mm) in /Users/xxx/***_utils***_upm [Pipeline] { [Pipeline] stage [Pipeline] { (Declarative: Checkout SCM) [Pipeline] checkout The recommended git tool is: NONE using credential github-app-*** Cloning the remote Git repository Cloning with configured refspecs honoured and without tags Cloning repository https://github.com/***/utils***.git > git init /Users/xxx/***_utils***_upm # timeout=10 Fetching upstream changes from https://github.com/***/utils***.git > git --version # timeout=10 > git --version # 'git version 2.30.1 (Apple Git-130)' using GIT_ASKPASS to set credentials > git fetch --no-tags --force --progress -- https://github.com/***/utils***.git +refs/heads/upm:refs/remotes/origin/upm # timeout=10 ERROR: Error cloning remote repo 'origin' hudson.plugins.git.GitException: Command "git fetch --no-tags --force --progress -- https://github.com/***/utils***.git +refs/heads/upm:refs/remotes/origin/upm" returned status code 128: stdout: stderr: remote: Invalid username or password. fatal: Authentication failed for 'https://github.com/***/utils***.git/' at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandIn(CliGitAPIImpl.java:2671) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandWithCredentials(CliGitAPIImpl.java:2096) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.access$500(CliGitAPIImpl.java:84) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:618) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$2.execute(CliGitAPIImpl.java:847) at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler$GitCommandMasterToSlaveCallable.call(RemoteGitImpl.java:158) at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler$GitCommandMasterToSlaveCallable.call(RemoteGitImpl.java:151) at hudson.remoting.UserRequest.perform(UserRequest.java:211) at hudson.remoting.UserRequest.perform(UserRequest.java:54) at hudson.remoting.Request$2.run(Request.java:376) at hudson.remoting.InterceptingExecutorService.lambda$wrap$0(InterceptingExecutorService.java:78) at java.util.concurrent.FutureTask.run(FutureTask.java:266) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at java.lang.Thread.run(Thread.java:748) Suppressed: hudson.remoting.Channel$CallSiteStackTrace: Remote call to Mac Server ABC (mm) ...
注:执行「Rebuild」操作后可正常完成构建。
排查方向与解决方案
1. GitHub App凭据初始化延迟
你使用的是GitHub App凭据,首次构建时Jenkins可能未完成凭据的动态生成/刷新流程,导致首次请求传递的凭据无效;重试时凭据已完成初始化,因此请求成功。
- 处理方案:
- 在Jenkins的GitHub App配置中,添加凭据预加载逻辑;
- 在Pipeline的
checkout步骤前添加短延迟(比如sleep 5),给凭据生成留足时间。
2. Agent节点Git凭据缓存问题
从日志看,首次构建在Mac Agent节点执行,使用的是Apple Git-130,而Jenkins Master使用的是git version 2.30.2。Agent节点首次克隆时,GIT_ASKPASS传递的凭据可能未被正确缓存,重试时缓存生效。
- 处理方案:
- 在Agent节点手动执行一次
git fetch目标仓库,确认凭据可正常使用,触发Git凭据缓存; - 修改Agent节点的Git配置,禁用凭据助手的自动清理,或配置持久化的凭据存储。
- 在Agent节点手动执行一次
3. Jenkins Git插件并发凭据冲突
当多个Pipeline同时启动时,首次构建的凭据请求可能被并发请求干扰,导致凭据传递错误;重试时并发压力降低,请求恢复正常。
- 处理方案:
- 检查Jenkins全局配置中Git插件的「凭据缓存超时」设置,适当延长超时时间;
- 给Pipeline添加互斥锁,避免同一仓库的首次构建并发执行。
4. MacOS钥匙串权限问题
MacOS的钥匙串可能阻止Jenkins Agent进程首次访问凭据,重试时权限已被授予。
- 处理方案:
- 在Agent节点的钥匙串中,添加Jenkins运行用户对Git相关凭据的访问权限;
- 禁用Agent节点Git的钥匙串凭据助手,改用Jenkins内置的凭据管理。
内容的提问来源于stack exchange,提问作者mg-ddci
相关产品推荐
相关产品推荐

