如何解决Jenkins Artifactory插件的Conan SSL用户认证错误?
解决Jenkins流水线中Conan访问HTTPS Artifactory的SSL认证问题
针对你遇到的SSL证书验证失败问题,我会分别给出两种方案的实现方式,优先覆盖你需要的短期解决方案:
方案1:在流水线中禁用SSL验证(短期解决)
你可以通过两种方式在Jenkins Artifactory Conan客户端中禁用SSL验证:
方式1:使用client.remote.add的verifySsl参数
你的Jenkins Artifactory插件版本(v2.16.1)已经支持在添加远程仓库时指定verifySsl参数,直接修改流水线代码即可:
stage('Package and Publish') { def artifactory_name = "MyCompanyArtifactory" def artifactory_repo = "conan-local" def server = Artifactory.server artifactory_name def client = Artifactory.newConanClient() // 添加remote时禁用SSL验证 def serverName = client.remote.add server: server, repo: artifactory_repo, verifySsl: false client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Debug") client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Release") String myCmd = "upload MyLib/* --all -r ${serverName} --confirm" def bInfo = client.run(command: myCmd) //server.publishBuildInfo bInfo }
方式2:直接执行conan remote add命令(兼容旧版本插件)
如果上述参数在你的环境中不生效,也可以绕过插件的remote.add方法,直接用client.run执行原生Conan命令来添加远程仓库并禁用SSL:
stage('Package and Publish') { def artifactory_name = "MyCompanyArtifactory" def artifactory_repo = "conan-local" def server = Artifactory.server artifactory_name def client = Artifactory.newConanClient() // 自定义远程仓库名称 def serverName = "MyConanRemote" // 手动执行conan remote add命令,末尾加False禁用SSL验证 client.run(command: "remote add ${serverName} ${server.getUrl()}/api/conan/${artifactory_repo} False") // 添加用户(如果需要) client.run(command: "user ci-user -r ${serverName} -p <your-password>") client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Debug") client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Release") String myCmd = "upload MyLib/* --all -r ${serverName} --confirm" def bInfo = client.run(command: myCmd) //server.publishBuildInfo bInfo }
方案2:配置服务器证书到Conan工作区(长期解决方案)
这种方式更安全,需要将Artifactory的CA证书添加到Conan工作区的cacert.pem文件中,步骤如下:
1. 上传证书到Jenkins凭据
- 导出Artifactory服务器的CA证书(
.crt格式) - 登录Jenkins,进入凭据 > 系统 > 全局凭据,点击添加凭据
- 选择Secret file类型,上传你的证书文件,设置一个凭据ID(比如
artifactory-ca-cert)
2. 修改流水线代码添加证书
在流水线中引入凭据,并将证书内容追加到Conan的CA证书文件中:
stage('Package and Publish') { def artifactory_name = "MyCompanyArtifactory" def artifactory_repo = "conan-local" def server = Artifactory.server artifactory_name def client = Artifactory.newConanClient() // 引入Jenkins中存储的证书文件 withCredentials([file(credentialsId: 'artifactory-ca-cert', variable: 'ARTIFACTORY_CERT')]) { // 将证书追加到Conan的cacert.pem中 sh "cat ${ARTIFACTORY_CERT} >> \$(conan config get cacert)" } def serverName = client.remote.add server: server, repo: artifactory_repo client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Debug") client.run(command: "export-pkg . ci-user/stable -s os=Linux -s arch=x86_64 -s build_type=Release") String myCmd = "upload MyLib/* --all -r ${serverName} --confirm" def bInfo = client.run(command: myCmd) //server.publishBuildInfo bInfo }
这样每次流水线运行时,都会自动将证书添加到当前工作区专属的Conan环境中,解决SSL验证问题。
内容的提问来源于stack exchange,提问作者Chris S.
相关产品推荐
相关产品推荐

