跨网络通过Jenkins自动化部署私有GitHub Helm Charts至Kubernetes集群
Alright, let's tackle this step by step—since your Jenkins and Kubernetes cluster are on separate networks, and you're using a private GitHub Helm repo, we need to cover network access, authentication, and pipeline automation. Here's how to get it working:
First, you need to grant Jenkins secure access to your K8s cluster's API server (since they're on different networks):
- Create a dedicated K8s service account with deployment permissions. Avoid using
cluster-adminunless absolutely necessary—lock down permissions to specific namespaces/resources instead:apiVersion: v1 kind: ServiceAccount metadata: name: jenkins-deployer namespace: default --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: jenkins-deployer-binding roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: edit # Restrict to edit permissions instead of cluster-admin subjects: - kind: ServiceAccount name: jenkins-deployer namespace: default - Retrieve the service account token for Jenkins authentication:
kubectl get secret $(kubectl get sa jenkins-deployer -o jsonpath='{.secrets[0].name}') -o jsonpath='{.data.token}' | base64 -d - Store credentials in Jenkins:
- Add a Secret text credential with the token above (ID:
k8s-deploy-token) - Add a Secret file credential with your K8s API server's CA certificate (ID:
k8s-ca-cert)
- Add a Secret text credential with the token above (ID:
Ensure Helm 3 is available on your Jenkins agent (either pre-installed in your agent Docker image or installed dynamically in the pipeline):
curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash helm version --short
Since you've already added the repo manually, you just need to automate authentication using GitHub PATs:
- Create a GitHub Personal Access Token (PAT) with
repopermissions (this lets Jenkins pull your private Helm repo) - Store PAT in Jenkins: Add a Username with password credential (username = your GitHub handle, password = PAT; ID:
github-helm-repo-creds) - Use the credential in your pipeline to add/update the repo securely:
helm repo add --username ${GITHUB_CREDS_USR} --password ${GITHUB_CREDS_PSW} my-private-repo https://raw.githubusercontent.com/your-username/your-helm-repo/main/ || true helm repo update
Here's a declarative pipeline example that ties everything together—adjust values to match your setup:
pipeline { agent any environment { K8S_API_SERVER = 'https://your-k8s-api-server:6443' HELM_REPO_NAME = 'my-private-repo' CHART_NAME = 'your-app-chart' RELEASE_NAME = 'your-app-release' DEPLOY_NAMESPACE = 'prod' // Pull credentials from Jenkins Credentials Manager GITHUB_CREDS = credentials('github-helm-repo-creds') K8S_TOKEN = credentials('k8s-deploy-token') K8S_CA_CERT = credentials('k8s-ca-cert') } stages { stage('Configure K8s Access') { steps { sh ''' mkdir -p ~/.kube # Build a temporary kubeconfig for the pipeline cat > ~/.kube/config << EOF apiVersion: v1 clusters: - cluster: certificate-authority: ${K8S_CA_CERT} server: ${K8S_API_SERVER} name: my-k8s-cluster contexts: - context: cluster: my-k8s-cluster user: jenkins-deployer namespace: ${DEPLOY_NAMESPACE} name: jenkins-deploy-context current-context: jenkins-deploy-context users: - name: jenkins-deployer user: token: ${K8S_TOKEN} EOF # Verify access kubectl get namespaces ''' } } stage('Update Helm Repo') { steps { sh ''' helm repo add --username ${GITHUB_CREDS_USR} --password ${GITHUB_CREDS_PSW} ${HELM_REPO_NAME} https://raw.githubusercontent.com/your-username/your-helm-repo/main/ || true helm repo update ''' } } stage('Deploy with Helm') { steps { sh ''' helm upgrade --install ${RELEASE_NAME} ${HELM_REPO_NAME}/${CHART_NAME} \ --namespace ${DEPLOY_NAMESPACE} \ --create-namespace \ --set image.tag=${BUILD_NUMBER} \ --values ./config/prod-values.yaml # Use your custom values file ''' } } stage('Validate Deployment') { steps { sh ''' helm status ${RELEASE_NAME} -n ${DEPLOY_NAMESPACE} kubectl get pods -n ${DEPLOY_NAMESPACE} -l app=${RELEASE_NAME} ''' } } } post { success { echo "✅ Deployment ${RELEASE_NAME} completed successfully!" } failure { echo "❌ Deployment failed—check pipeline logs for details." } } }
- Network Connectivity: Ensure Jenkins can reach both your K8s API server and GitHub (check firewall rules, security groups, or proxy settings if needed)
- Helm Repo Index: Make sure your private GitHub repo has an up-to-date
index.yaml(runhelm repo index .locally and push changes when you update charts) - Permission Issues: If Jenkins can't deploy, double-check the K8s service account's role binding—use
kubectl auth can-i deploy deployments --as=system:serviceaccount:default:jenkins-deployerto test permissions
内容的提问来源于stack exchange,提问作者Duncan Martin

