【问题标题】:Gitlab-runner has 'access denied' when pushing built image推送构建的图像时,Gitlab-runner 有“访问被拒绝”
【发布时间】:2018-12-21 15:27:06
【问题描述】:

我在将使用 gitlab-runner 构建的映像推送到 gitlab 存储库时遇到问题。

我的 gitlab-ci.yml:

image: docker:latest
services:
- docker:dind

stages:
- build
- release

variables:
TEST_IMAGE: registry.gitlab.com/myhost/haproxy:$CI_COMMIT_REF_NAME
RELEASE_IMAGE: registry.gitlab.com/myhost/haproxy:latest

before_script:
- docker login -u gitlab-ci-token -p $CI_JOB_TOKEN gitlab.com

build:
stage: build
script:
- docker build --pull -t $TEST_IMAGE .
- docker push $TEST_IMAGE

release:
stage: release
script:
- docker pull $TEST_IMAGE
- docker tag $TEST_IMAGE $RELEASE_IMAGE
- docker push $RELEASE_IMAGE
only:
- master

docker 登录有效 - 我得到“登录成功” - 但是当涉及到推送操作时,我得到:

$ docker push $TEST_IMAGE
The push refers to repository [registry.gitlab.com/myhost/haproxy]
d77ab2f42dd4: Preparing
c70258f465dd: Preparing
96b45c1aa07c: Preparing
28587e66f3e8: Preparing
21b59fc0e3a3: Preparing
9c46f426bcb7: Preparing
9c46f426bcb7: Waiting
denied: access forbidden
ERROR: Job failed: exit code 1

跑步者在我自己的服务器上,我正在推送到 gitlab.com

我还检查了我的本地机器,在终端命令中执行,如脚本中的登录、构建和推送 - 一切正常,但如果我使用跑步者在本地运行,注册它并获得工作,我也得到访问禁止错误。

所以我认为问题出在跑步者身上,什么。 我比较了从 10.6 到最新 11.0 的几个版本的 gitlab-runner 的行为

有什么想法吗?

【问题讨论】:

  • 您是否在推送前尝试过登录?也许是超时?
  • 是的,我也尝试在构建阶段登录-它登录-“登录成功”,然后去推送,结果相同:/
  • 你确定你不应该登录registry.gitlab.com而不是gitlab.com吗?
  • 嗯,如果我登录到 gitlab.com,在本地 Ubuntu 上它可以工作,但是像你建议的跑步者我需要登录到 registry.gitlab.com。还误导我,它在终端中显示“已登录”。所以最好的解决方案是使用内置变量:“docker login -u gitlab-ci-token -p $CI_JOB_TOKEN $CI_REGISTRY”。谢谢你的帮助 - 我欠你一杯啤酒:)
  • 因为在本地你已经通过不同的方式登录了,所以docker login 命令不会做任何事情。

标签: gitlab-ci gitlab-ci-runner


【解决方案1】:

所以问题是注册表地址错误-应该是registry.gitlab.com

它误导了我,即使没有“注册表”前缀,它也会在终端中显示“已登录”,因此最好的解决方案是在 gitlab-ci.yml 登录期间使用内置变量:

docker login -u gitlab-ci-token -p $CI_JOB_TOKEN $CI_REGISTRY 

【讨论】:

    猜你喜欢
    • 2013-10-27
    • 2019-03-24
    • 1970-01-01
    • 2020-10-18
    • 1970-01-01
    • 1970-01-01
    • 2016-12-10
    • 2020-06-08
    • 1970-01-01
    相关资源
    最近更新 更多