You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Jenkins任务中传递运行时参数(如密码)并解决凭证请求问题

Hey there! Let's figure out how to pass runtime parameters like passwords in Jenkins jobs, especially that annoying [sshexec] Enter password for datasource user prompt you're hitting. Here are a few practical, secure ways to handle this:

This is the safest way to handle sensitive info like passwords—Jenkins encrypts and stores them securely instead of exposing them in logs or configs. Here's how to set it up:

  • First, create a credential in Jenkins:
    • Go to your Jenkins homepage → Click Credentials in the left menu → Pick a domain (like Global credentials for cross-project use) → Click Add Credentials
    • Choose the Username with password type, fill in your datasource SSH username and password, set a memorable ID (e.g., datasource-ssh-creds) and a description, then save.
  • Next, link this credential to your Jenkins job:
    • For Freestyle Projects:
      1. Skip adding a parameter if you don't need runtime input—we'll use the stored credential directly.
      2. Find your sshexec build step (whether it's part of an Ant/Maven task or the Jenkins SSH plugin). Look for an option like Use configured credentials and select the credential you just created from the dropdown.
    • For Pipeline Projects:
      Use the credentials() helper to inject the credential into your pipeline script. Here's an example:
      pipeline {
          agent any
          stages {
              stage('Run SSH Command') {
                  steps {
                      withCredentials([usernamePassword(
                          credentialsId: 'datasource-ssh-creds',
                          usernameVariable: 'SSH_USER',
                          passwordVariable: 'SSH_PASS'
                      )]) {
                          sh '''
                              # Pass the injected password to sshexec directly
                              sshexec -user $SSH_USER -password $SSH_PASS -host your-datasource-host -command "your-target-command"
                          '''
                      }
                  }
              }
          }
      }
      

This way, Jenkins automatically supplies the password to sshexec without any interactive prompts.

2. Add a Password Build Parameter (For Temporary Testing)

If you need to input the password manually each time the job runs (great for quick tests, not recommended for production), do this:

  • Go to your job's configuration → Check This project is parameterized
  • Click Add parameter → Select Password Parameter
  • Name it something clear (e.g., DATASOURCE_SSH_PASS), add a brief description, then save.
  • In your sshexec step, reference the parameter like this:
    sshexec -user your-username -password ${DATASOURCE_SSH_PASS} -host your-host -command "your-command"
    When you trigger the job, Jenkins will show a hidden input field for the password—enter it, and the job will pass it to sshexec automatically.

I only mention this for local, throwaway testing—never do this in production. You can directly include the password in your sshexec command or config, but it will be visible in job logs and config files, which is a huge security risk. Example:
sshexec -user your-user -password plaintext-password -host your-host -command "your-command"

To specifically fix that [sshexec] Enter password for datasource user prompt: it just means sshexec is waiting for interactive password input. Any of the first two methods above will bypass that by providing the password upfront.

内容的提问来源于stack exchange,提问作者Niket Sharma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:45:54