GitLab Runner Shell Executor突发SSL证书匹配错误求助
我来帮你梳理这个问题的根源,再一步步给出解决办法:
问题重现
昨天你的Shell Executor用这个测试YML还能正常运行:
stages: - test - build - deploy test: stage: test script: echo "Running tests" build: stage: build script: echo "Building the app" deploy_staging: stage: deploy script: - echo "Deploy to staging server" - export environment: name: staging url: https://staging.example.com only: - master
今天突然抛出了SSL验证错误:
Running with gitlab-runner 10.3.0 (5cf5e19a) on gitlab01ShellSQLRunner (9ec36953) Using Shell executor... Running on debian... Cloning repository... Cloning into '/home/gitlab-runner/builds/9ec36953/0/dev/SQL'... fatal: unable to access 'https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@10.45.18.14/dev/SQL.git/': SSL: certificate subject name (Gitlab01) does not match target host name '10.45.18.14' ERROR: Job failed: exit status 1
你提到的三个疑问,我逐个拆解分析:
疑问解答 & 根源分析
为啥Runner突然用IP访问了?
大概率是DNS解析或本地hosts映射出了问题。昨天Runner能通过gitlab01主机名正确解析到GitLab服务器,今天可能是Runner机器的hosts文件被修改、DNS服务器解析记录变更,或是GitLab返回给Runner的仓库地址改成了IP形式。另外也有可能是Runner被重新注册过,配置里的URL意外换成了IP。IP对应
gitlab01.YXNET.local且有别名,为啥还报错?
SSL证书的验证是严格匹配主机名/IP的——你的GitLab证书主题名是Gitlab01,但现在用IP访问时,证书里并没有包含这个IP,所以不管有没有别名映射,用IP访问都会触发证书不匹配的错误。昨天正常今天不行?
肯定是某个环境配置变动导致的:比如Runner机器的hosts被修改、DNS缓存过期、GitLab项目的仓库URL被调整,或是Runner的config.toml配置文件被改动了。
具体解决步骤
按优先级从高到低尝试:
1. 修复Runner机器的hosts映射
先确保Runner所在的Debian机器能正确解析gitlab01到对应IP:
编辑/etc/hosts文件:
sudo nano /etc/hosts
添加或确认这一行存在:
10.45.18.14 gitlab01 gitlab01.YXNET.local
保存后测试解析是否正常:
ping gitlab01
如果能正常ping通到10.45.18.14,再重新触发CI任务试试。
2. 检查并修正GitLab Runner配置
找到Runner的配置文件/etc/gitlab-runner/config.toml,打开后确认[[runners]]段里的url是https://gitlab01而不是IP:
[[runners]] name = "gitlab01ShellSQLRunner" url = "https://gitlab01" # 这里要确保是主机名,不是IP token = "9ec36953..." executor = "shell" # 其他配置...
如果是IP的话改成主机名,然后重启Runner服务:
sudo gitlab-runner restart
3. 检查GitLab项目的仓库URL
登录GitLab后台,进入你的dev/SQL项目,到Settings > Repository里查看仓库URL,确认是https://gitlab01/dev/SQL.git而不是IP形式的地址。如果是IP,改成主机名即可。
4. 临时跳过SSL验证(仅测试用,不推荐生产)
如果上面的方法都暂时无法生效,作为临时测试可以禁用Runner的SSL验证(注意这会降低安全性,生产环境不建议):
在config.toml的[[runners]]段里添加:
tls_verify = false
然后重启Runner服务,再跑任务测试。
内容的提问来源于stack exchange,提问作者Anders Metnik

