You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨网络通过Jenkins自动化部署私有GitHub Helm Charts至Kubernetes集群

Alright, let's tackle this step by step—since your Jenkins and Kubernetes cluster are on separate networks, and you're using a private GitHub Helm repo, we need to cover network access, authentication, and pipeline automation. Here's how to get it working:

Step 1: Set Up Jenkins to Access Your Cross-Network Kubernetes Cluster

First, you need to grant Jenkins secure access to your K8s cluster's API server (since they're on different networks):

  • Create a dedicated K8s service account with deployment permissions. Avoid using cluster-admin unless absolutely necessary—lock down permissions to specific namespaces/resources instead:
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: jenkins-deployer
      namespace: default
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: jenkins-deployer-binding
    roleRef:
      apiGroup: rbac.authorization.k8s.io
      kind: ClusterRole
      name: edit # Restrict to edit permissions instead of cluster-admin
    subjects:
    - kind: ServiceAccount
      name: jenkins-deployer
      namespace: default
    
  • Retrieve the service account token for Jenkins authentication:
    kubectl get secret $(kubectl get sa jenkins-deployer -o jsonpath='{.secrets[0].name}') -o jsonpath='{.data.token}' | base64 -d
    
  • Store credentials in Jenkins:
    • Add a Secret text credential with the token above (ID: k8s-deploy-token)
    • Add a Secret file credential with your K8s API server's CA certificate (ID: k8s-ca-cert)
Step 2: Install Helm on Your Jenkins Agent

Ensure Helm 3 is available on your Jenkins agent (either pre-installed in your agent Docker image or installed dynamically in the pipeline):

curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
helm version --short
Step 3: Authenticate Jenkins with Your Private GitHub Helm Repo

Since you've already added the repo manually, you just need to automate authentication using GitHub PATs:

  • Create a GitHub Personal Access Token (PAT) with repo permissions (this lets Jenkins pull your private Helm repo)
  • Store PAT in Jenkins: Add a Username with password credential (username = your GitHub handle, password = PAT; ID: github-helm-repo-creds)
  • Use the credential in your pipeline to add/update the repo securely:
    helm repo add --username ${GITHUB_CREDS_USR} --password ${GITHUB_CREDS_PSW} my-private-repo https://raw.githubusercontent.com/your-username/your-helm-repo/main/ || true
    helm repo update
    
Step 4: Build the Jenkins Pipeline for Automated Deployment

Here's a declarative pipeline example that ties everything together—adjust values to match your setup:

pipeline {
  agent any
  environment {
    K8S_API_SERVER = 'https://your-k8s-api-server:6443'
    HELM_REPO_NAME = 'my-private-repo'
    CHART_NAME = 'your-app-chart'
    RELEASE_NAME = 'your-app-release'
    DEPLOY_NAMESPACE = 'prod'
    // Pull credentials from Jenkins Credentials Manager
    GITHUB_CREDS = credentials('github-helm-repo-creds')
    K8S_TOKEN = credentials('k8s-deploy-token')
    K8S_CA_CERT = credentials('k8s-ca-cert')
  }
  stages {
    stage('Configure K8s Access') {
      steps {
        sh '''
          mkdir -p ~/.kube
          # Build a temporary kubeconfig for the pipeline
          cat > ~/.kube/config << EOF
apiVersion: v1
clusters:
- cluster:
    certificate-authority: ${K8S_CA_CERT}
    server: ${K8S_API_SERVER}
  name: my-k8s-cluster
contexts:
- context:
    cluster: my-k8s-cluster
    user: jenkins-deployer
    namespace: ${DEPLOY_NAMESPACE}
  name: jenkins-deploy-context
current-context: jenkins-deploy-context
users:
- name: jenkins-deployer
  user:
    token: ${K8S_TOKEN}
EOF
          # Verify access
          kubectl get namespaces
        '''
      }
    }
    stage('Update Helm Repo') {
      steps {
        sh '''
          helm repo add --username ${GITHUB_CREDS_USR} --password ${GITHUB_CREDS_PSW} ${HELM_REPO_NAME} https://raw.githubusercontent.com/your-username/your-helm-repo/main/ || true
          helm repo update
        '''
      }
    }
    stage('Deploy with Helm') {
      steps {
        sh '''
          helm upgrade --install ${RELEASE_NAME} ${HELM_REPO_NAME}/${CHART_NAME} \
            --namespace ${DEPLOY_NAMESPACE} \
            --create-namespace \
            --set image.tag=${BUILD_NUMBER} \
            --values ./config/prod-values.yaml # Use your custom values file
        '''
      }
    }
    stage('Validate Deployment') {
      steps {
        sh '''
          helm status ${RELEASE_NAME} -n ${DEPLOY_NAMESPACE}
          kubectl get pods -n ${DEPLOY_NAMESPACE} -l app=${RELEASE_NAME}
        '''
      }
    }
  }
  post {
    success {
      echo "✅ Deployment ${RELEASE_NAME} completed successfully!"
    }
    failure {
      echo "❌ Deployment failed—check pipeline logs for details."
    }
  }
}
Key Troubleshooting Tips
  • Network Connectivity: Ensure Jenkins can reach both your K8s API server and GitHub (check firewall rules, security groups, or proxy settings if needed)
  • Helm Repo Index: Make sure your private GitHub repo has an up-to-date index.yaml (run helm repo index . locally and push changes when you update charts)
  • Permission Issues: If Jenkins can't deploy, double-check the K8s service account's role binding—use kubectl auth can-i deploy deployments --as=system:serviceaccount:default:jenkins-deployer to test permissions

内容的提问来源于stack exchange,提问作者Duncan Martin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:27:08