【问题标题】:Gitlab-ci-token user unable to clone repositoriesGitlab-ci-token 用户无法克隆存储库
【发布时间】:2017-01-26 19:57:22
【问题描述】:

我正在尝试设置一个 docker runner 并成功地用 gitlab-ce 注册了这个runner。但是,当作业运行时,它总是会失败并显示以下内容:

Running with gitlab-ci-multi-runner 1.10.2 (d171b73)
Using Docker executor with image python:3.4 ...
Starting service postgres:latest ...
Pulling docker image postgres:latest ...
Waiting for services to be up and running...
Pulling docker image python:3.4 ...
Running on runner-b35ff618-project-96-concurrent-0 via toucan...
Cloning repository...
Cloning into '/builds/amrstratus/webportal'...
fatal: unable to access 'https://gitlab-ci-token:xxxxxxxxxxxxxxxxxxxx@gitlab.xxxxxxxxx/amrstratus/webportal.git/': Failed to connect to gitlab.xxxxxx port 443: Connection refused
ERROR: Build failed: exit code 1

我尝试简单地克隆存储库并得到类似的错误:

root@toucan:/tmp# git clone https://gitlab-ci-token:b35ff618453c702944c736668e1c2c@gitlab.xxxxxxxx/amrstratus/webportal.git/
Cloning into 'webportal'...
remote: HTTP Basic: Access denied
fatal: Authentication failed for 'https://gitlab-ci-token:xxxxxxxxxxx@gitlab.xxxxxxxx/amrstratus/webportal.git/'

通过 https 访问似乎工作正常,其他一切似乎都工作。

有什么想法吗?我完全被卡住了。

系统详情:

Debian 8 (Jessie)
GitLab 8.16.2
GitLab Shell 4.1.1
GitLab Workhorse v1.3.0
GitLab API v3
Git 2.10.2
Ruby 2.3.3p222
Rails 4.2.7.1
PostgreSQL 9.6.1

【问题讨论】:

    标签: gitlab gitlab-ci-runner


    【解决方案1】:

    请注意,可能有两个问题。

    关于令牌本身(和fatal: Authentication failed),请参阅this thread

    现在为每个构建安全地生成 CI 令牌。它在$CI_BUILD_TOKEN 中可用。
    如果您要从 .gitlab-ci.yml 克隆不同的存储库(就像我们一样),您最好的选择是使用 SSH。

    另一种解决方案是使用您的个人私人令牌:

    git clone https://<username>:<private-token>@gitlab.anydomainhere.com/developers/<projectname>.git
    

    (请注意此令牌可以访问您的所有项目)

    另一个问题与Docker有关:fatal: unable to access

    您需要确保可以与您的 Gitlab 实例通信(as in here 或 issue 305)。
    还有check the ownership as in this thread。

    【讨论】:

    • 谢谢,您的帖子帮助我解决了问题。这不是身份验证问题,而是与 docker 相关的问题,我的防火墙阻止了请求。使用 docker run python:3.4 /usr/bin/curl gitlab.xxxx 帮我解决了。
    【解决方案2】:

    我知道这已经过时了,但是,为我解决这个问题的是根据 this comment 对主力进行的调整。

    修改/etc/gitlab/gitlab.rb如下:

    取消注释该行

    gitlab_workhorse['enable'] = true
    

    添加这两行

    gitlab_workhorse['listen_network'] = "tcp"
    gitlab_workhorse['listen_addr'] = "127.0.0.1:8181"
    

    然后修改网络服务器配置以将反向代理指向此而不是独角兽。

    【讨论】:

      【解决方案3】:

      虽然已经针对该问题给出了解决方案,但使用的是个人令牌。 正如所指出的,它可能会失败,因为如果您使用 CI_BUILD_TOKEN/CI_JOB_TOKEN 进行克隆,则仅对该作业运行有效。 因此,如果您希望每次都通过跑步者进行拉动,您可以在拉动时指定 url:

      git pull https://gitlab-ci-token:$CI_JOB_TOKEN@gitlab.anydomainhere.com/developers/<projectname>.git
      

      这样,在每次拉取请求时,都会使用新令牌。

      【讨论】:

        猜你喜欢
        • 1970-01-01
        • 2014-10-30
        • 2019-12-02
        • 1970-01-01
        • 1970-01-01
        • 2022-01-23
        • 2016-03-04
        • 1970-01-01
        • 2022-11-10
        相关资源
        最近更新 更多