You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Google Cloud Build中为Kaniko使用非exec入口点定义构建参数

Injecting Secret Manager Tokens as Build Args with Kaniko in Google Cloud Build

Great question—you absolutely can use a bash entrypoint with the Kaniko executor image to replicate your existing Docker build pattern, no need to force the pure exec form or modify your local build setup. Here's how to make it work:

Step-by-Step Explanation

The official Kaniko executor image is built on a base image that includes bash, so you can override its default entrypoint just like you did with the Cloud Build docker image. The key is to:

  1. First decrypt your Secret Manager token into a file (same as your existing flow)
  2. Call the Kaniko executor directly within a bash command, passing the decrypted token as a --build-arg

Full Cloud Build Config Example

steps:
  # Step 1: Decrypt the GitHub PAT from Secret Manager into a file
  - id: 'Decrypt PAT'
    name: 'gcr.io/cloud-builders/gcloud'
    args:
      - 'secrets'
      - 'versions'
      - 'access'
      - 'latest'
      - '--secret=YOUR_SECRET_NAME'
      - '--out-file=decrypted-pat.txt'

  # Step 2: Build with Kaniko, passing the PAT as a build arg
  - id: 'Build with Kaniko (and Cache)'
    name: 'gcr.io/kaniko-project/executor:latest'
    entrypoint: 'bash'
    args:
      - '-c'
      - |
        /kaniko/executor \
          --destination=$_GCR_HOSTNAME/$PROJECT_ID/$REPO_NAME:$SHORT_SHA \
          --cache=true \
          --cache-ttl=6h \
          --build-arg PERSONAL_ACCESS_TOKEN_GITHUB=$(cat decrypted-pat.txt)

Key Details

  • We override the default entrypoint of the Kaniko image to bash, then use a multi-line command to call the actual Kaniko executor binary at /kaniko/executor.
  • Just like your Docker build, we read the decrypted token from the file and pass it directly as a --build-arg to Kaniko. This keeps your local build workflow identical—no need to adjust how developers pass the token locally.
  • The cache settings are preserved from your original Kaniko example, so you still get the benefit of layer caching.

Why This Works

The Kaniko executor image isn't restricted to just the exec form—while that's the recommended default, the underlying image includes standard shell tools, so overriding the entrypoint to bash lets you compose commands just like you did with the Docker builder.

内容的提问来源于stack exchange,提问作者thclark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:54:40