Jenkins Pipeline(K8s/Docker Slave)中Packer用AWS IAM Role构建遇凭证问题求助
Hey Tony, I’ve run into this exact scenario before—let’s break down what’s going on and how to fix it without hardcoding AWS credentials in your Packer template.
First: You Don’t Need to Hardcode Credentials (or Even Explicitly Specify the Role) in Packer
The goal with Kube2iam is to let your Jenkins slave Pod inherit an IAM role automatically, so Packer should pull credentials from the instance metadata service (IMDS) by default. The error you’re seeing means Packer can’t find those credentials, so let’s check the key pieces step by step.
1. Verify Kube2iam is Properly Annotating Your Jenkins Slave Pod
First, make sure your Jenkins Kubernetes Pod template has the correct annotation to tell Kube2iam which IAM role to assign:
- In your Jenkins cloud plugin configuration, add the annotation
iam.amazonaws.com/role: <YOUR_IAM_ROLE_NAME_OR_ARN>to the Pod template. - To confirm it’s working, exec into the running slave container and run:
This should return your IAM role name. If it doesn’t, Kube2iam isn’t correctly binding the role to the Pod—double-check your Kube2iam deployment and cluster RBAC settings.curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
2. Check Your Packer Template Configuration
You don’t need to add access_key or secret_key to your Amazon Builder, but there are a couple of optional settings to ensure Packer prioritizes IMDS:
- Ensure you haven’t accidentally set any AWS credential environment variables in your Jenkins Pipeline or slave container (like
AWS_ACCESS_KEY_ID)—these will override IMDS credentials. - You can explicitly enable IMDS checks in your Packer template (though this is the default) to make it clear:
Note: You only need to add ansource "amazon-ebs" "amazon-linux-2" { ami_name = "amazon-linux-2-build-{{timestamp}}" instance_type = "t2.micro" region = "us-east-1" source_ami_filter { filters = { name = "amzn2-ami-hvm-*-x86_64-gp2" root-device-type = "ebs" virtualization-type = "hvm" } owners = ["amazon"] most_recent = true } # Optional: Explicitly enable IMDS check (default is false, meaning enabled) skip_metadata_api_check = false }assume_roleblock if your Kube2iam-assigned role needs to assume a separate, dedicated AMI-building role. If you’re using the Kube2iam role directly for Packer actions, skip this.
3. Ensure Network Access to IMDS
Your Jenkins slave Pod needs access to the IMDS endpoint (169.254.169.254). Check if your K8s cluster’s network policies or security groups are blocking this traffic—most default setups allow it, but it’s worth verifying with a quick curl test as mentioned earlier.
Quick Troubleshooting Checklist
- Jenkins slave Pod has the correct
iam.amazonaws.com/roleannotation - Pod can reach
169.254.169.254and retrieve role credentials - No AWS credential environment variables are set in the slave container
- Packer template doesn’t have hardcoded
access_key/secret_keyvalues
Once these boxes are checked, Packer should automatically pick up the credentials from the Kube2iam-assigned role via IMDS, and your packer build should run successfully.
内容的提问来源于stack exchange,提问作者Tony Lecointre

