You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Runner Shell Executor突发SSL证书匹配错误求助

GitLab Shell Executor SSL证书主机名不匹配问题解决

我来帮你梳理这个问题的根源,再一步步给出解决办法:

问题重现

昨天你的Shell Executor用这个测试YML还能正常运行:

stages:
  - test
  - build
  - deploy
test:
  stage: test
  script: echo "Running tests"
build:
  stage: build
  script: echo "Building the app"
deploy_staging:
  stage: deploy
  script:
    - echo "Deploy to staging server"
    - export environment: name: staging url: https://staging.example.com
  only:
    - master

今天突然抛出了SSL验证错误:

Running with gitlab-runner 10.3.0 (5cf5e19a) on gitlab01ShellSQLRunner (9ec36953)
Using Shell executor...
Running on debian...
Cloning repository...
Cloning into '/home/gitlab-runner/builds/9ec36953/0/dev/SQL'...
fatal: unable to access 'https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@10.45.18.14/dev/SQL.git/': SSL: certificate subject name (Gitlab01) does not match target host name '10.45.18.14'
ERROR: Job failed: exit status 1

你提到的三个疑问,我逐个拆解分析:


疑问解答 & 根源分析

  1. 为啥Runner突然用IP访问了?
    大概率是DNS解析或本地hosts映射出了问题。昨天Runner能通过gitlab01主机名正确解析到GitLab服务器,今天可能是Runner机器的hosts文件被修改、DNS服务器解析记录变更,或是GitLab返回给Runner的仓库地址改成了IP形式。另外也有可能是Runner被重新注册过,配置里的URL意外换成了IP。

  2. IP对应gitlab01.YXNET.local且有别名,为啥还报错?
    SSL证书的验证是严格匹配主机名/IP的——你的GitLab证书主题名是Gitlab01,但现在用IP访问时,证书里并没有包含这个IP,所以不管有没有别名映射,用IP访问都会触发证书不匹配的错误。

  3. 昨天正常今天不行?
    肯定是某个环境配置变动导致的:比如Runner机器的hosts被修改、DNS缓存过期、GitLab项目的仓库URL被调整,或是Runner的config.toml配置文件被改动了。


具体解决步骤

按优先级从高到低尝试:

1. 修复Runner机器的hosts映射

先确保Runner所在的Debian机器能正确解析gitlab01到对应IP:
编辑/etc/hosts文件:

sudo nano /etc/hosts

添加或确认这一行存在:

10.45.18.14    gitlab01 gitlab01.YXNET.local

保存后测试解析是否正常:

ping gitlab01

如果能正常ping通到10.45.18.14,再重新触发CI任务试试。

2. 检查并修正GitLab Runner配置

找到Runner的配置文件/etc/gitlab-runner/config.toml,打开后确认[[runners]]段里的url是https://gitlab01而不是IP:

[[runners]]
  name = "gitlab01ShellSQLRunner"
  url = "https://gitlab01"  # 这里要确保是主机名,不是IP
  token = "9ec36953..."
  executor = "shell"
  # 其他配置...

如果是IP的话改成主机名,然后重启Runner服务:

sudo gitlab-runner restart

3. 检查GitLab项目的仓库URL

登录GitLab后台,进入你的dev/SQL项目,到Settings > Repository里查看仓库URL,确认是https://gitlab01/dev/SQL.git而不是IP形式的地址。如果是IP,改成主机名即可。

4. 临时跳过SSL验证(仅测试用,不推荐生产)

如果上面的方法都暂时无法生效,作为临时测试可以禁用Runner的SSL验证(注意这会降低安全性,生产环境不建议):
在config.toml的[[runners]]段里添加:

tls_verify = false

然后重启Runner服务,再跑任务测试。


内容的提问来源于stack exchange,提问作者Anders Metnik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:02:02