Jenkins用单引号避免Groovy插值泄露凭证时docker登录失败怎么办
问题根因
使用三单引号定义sh步骤的脚本时,所有$开头的变量都会交给Shell层解析,但dockerRegistry是Groovy层面定义的变量,没有被注入到Shell的环境变量列表中,Shell执行时无法读取$dockerRegistry的值,导致docker login默认请求Docker Hub官方仓库,你存储的凭证是私有镜像仓库的,自然会返回用户名密码错误。
使用双引号写法时,Groovy会提前把docker_usr、docker_pwd、dockerRegistry三个变量全部插值完成再传给Shell,虽然执行成功,但敏感凭证会明文出现在Jenkins的构建上下文、日志中,因此触发安全告警。
正确实现方案
只要区分两类变量的处理规则即可:
- 敏感凭证变量(
docker_usr、docker_pwd):保留$前缀,交给Shell层解析,避免Groovy插值泄露 - 非敏感普通变量(
dockerRegistry):在Groovy层面完成插值
写法1:字符串拼接
withCredentials([usernamePassword(credentialsId: 'my-docker-user', passwordVariable: 'docker_pwd', usernameVariable: 'docker_usr')]) { dcheckScriptResult = sh label: 'Retrieving image', script: '''docker login -u $docker_usr -p $docker_pwd ''' + dockerRegistry, returnStatus: true echo "dcheckScriptResult = $dcheckScriptResult" }
写法2:双引号转义敏感变量前缀
withCredentials([usernamePassword(credentialsId: 'my-docker-user', passwordVariable: 'docker_pwd', usernameVariable: 'docker_usr')]) { dcheckScriptResult = sh label: 'Retrieving image', script: """docker login -u \$docker_usr -p \$docker_pwd ${dockerRegistry}""", returnStatus: true echo "dcheckScriptResult = $dcheckScriptResult" }
两种写法均符合Jenkins安全规范,不会触发敏感信息泄露告警,同时可正常完成私有镜像仓库登录。
内容的提问来源于stack exchange,提问作者julio
相关产品推荐
相关产品推荐

