【问题标题】:Run Kaniko in Jenkins Slave在 Jenkins Slave 中运行 Kaniko
【发布时间】:2018-12-10 19:03:19
【问题描述】:
我想在 jenkins 中将 kaniko 作为奴隶运行。我的管道在 docker 插件上运行,如何使用 kaniko 设置 gcr 凭据。
我想将 GCR 凭据上传到 Jenkins 主服务器。
我的管道 groovy 如下所示:
node("kaniko-jnlp") {
stage('Building Stage') {
git 'https://github.com/jenkinsci/docker-jnlp-slave.git'
sh ''' /kaniko/executor -f `pwd`/Dockerfile -c `pwd` --insecure-
skip-tls-verify --cache=true
--- destination=gcr.io/project/project:v1 '''
}
【问题讨论】:
标签:
jenkins
jenkins-pipeline
devops
kaniko
【解决方案1】:
我正在使用 Kaniko 构建图像并推送到私人仓库。我的 Kaniko docker 镜像使用 Kubernetes pull-secret 进行身份验证,但您应该可以使用以下代码:
stage('Kaniko') {
environment {
ARTIFACTORY_CREDS = credentials('your-credentials')
}
steps{
sh "echo ********** EXAMPLE APP **********"
container(name: 'kaniko', shell: '/busybox/sh') {
withEnv(['PATH+EXTRA=/busybox']) {
sh '''#!/busybox/sh
/kaniko/executor --context `pwd` --cleanup --dockerfile=your/Dockerfile --build-arg ARTIFACTORY_USER=$ARTIFACTORY_CREDS_USR --build-arg ARTIFACTORY_PASS=$ARTIFACTORY_CREDS_PSW --destination=your.docker.repo/team/image:tag
'''
}
}
}
}
【解决方案2】:
我运行封装在一个 pod 中的整个管道,这里是我如何使用 Kaniko:
pipeline {
agent {
kubernetes {
yaml """
apiVersion: v1
kind: Pod
metadata:
labels:
jenkins: worker
spec:
containers:
- name: kaniko
image: gcr.io/kaniko-project/executor:debug
command: ["/busybox/cat"]
tty: true
volumeMounts:
- name: dockercred
mountPath: /root/.docker/
volumes:
- name: dockercred
secret:
secretName: dockercred
"""
}
}
stages {
stage('Stage 1: Build with Kaniko') {
steps {
container('kaniko') {
sh '/kaniko/executor --context=git://github.com/repository/project.git \
--destination=repository/image:tag \
--insecure \
--skip-tls-verify \
-v=debug'
}
}
}
}
}