You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins Pipeline(K8s/Docker Slave)中Packer用AWS IAM Role构建遇凭证问题求助

Fixing Packer AWS Credential Error with Kube2iam & Jenkins K8s Slaves

Hey Tony, I’ve run into this exact scenario before—let’s break down what’s going on and how to fix it without hardcoding AWS credentials in your Packer template.

First: You Don’t Need to Hardcode Credentials (or Even Explicitly Specify the Role) in Packer

The goal with Kube2iam is to let your Jenkins slave Pod inherit an IAM role automatically, so Packer should pull credentials from the instance metadata service (IMDS) by default. The error you’re seeing means Packer can’t find those credentials, so let’s check the key pieces step by step.

1. Verify Kube2iam is Properly Annotating Your Jenkins Slave Pod

First, make sure your Jenkins Kubernetes Pod template has the correct annotation to tell Kube2iam which IAM role to assign:

  • In your Jenkins cloud plugin configuration, add the annotation iam.amazonaws.com/role: <YOUR_IAM_ROLE_NAME_OR_ARN> to the Pod template.
  • To confirm it’s working, exec into the running slave container and run:
    curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
    
    This should return your IAM role name. If it doesn’t, Kube2iam isn’t correctly binding the role to the Pod—double-check your Kube2iam deployment and cluster RBAC settings.

2. Check Your Packer Template Configuration

You don’t need to add access_key or secret_key to your Amazon Builder, but there are a couple of optional settings to ensure Packer prioritizes IMDS:

  • Ensure you haven’t accidentally set any AWS credential environment variables in your Jenkins Pipeline or slave container (like AWS_ACCESS_KEY_ID)—these will override IMDS credentials.
  • You can explicitly enable IMDS checks in your Packer template (though this is the default) to make it clear:
    source "amazon-ebs" "amazon-linux-2" {
      ami_name      = "amazon-linux-2-build-{{timestamp}}"
      instance_type = "t2.micro"
      region        = "us-east-1"
      source_ami_filter {
        filters = {
          name                = "amzn2-ami-hvm-*-x86_64-gp2"
          root-device-type    = "ebs"
          virtualization-type = "hvm"
        }
        owners      = ["amazon"]
        most_recent = true
      }
      # Optional: Explicitly enable IMDS check (default is false, meaning enabled)
      skip_metadata_api_check = false
    }
    
    Note: You only need to add an assume_role block if your Kube2iam-assigned role needs to assume a separate, dedicated AMI-building role. If you’re using the Kube2iam role directly for Packer actions, skip this.

3. Ensure Network Access to IMDS

Your Jenkins slave Pod needs access to the IMDS endpoint (169.254.169.254). Check if your K8s cluster’s network policies or security groups are blocking this traffic—most default setups allow it, but it’s worth verifying with a quick curl test as mentioned earlier.

Quick Troubleshooting Checklist

  • Jenkins slave Pod has the correct iam.amazonaws.com/role annotation
  • Pod can reach 169.254.169.254 and retrieve role credentials
  • No AWS credential environment variables are set in the slave container
  • Packer template doesn’t have hardcoded access_key/secret_key values

Once these boxes are checked, Packer should automatically pick up the credentials from the Kube2iam-assigned role via IMDS, and your packer build should run successfully.

内容的提问来源于stack exchange,提问作者Tony Lecointre

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:05:06