【问题标题】:Jenkins Git plugin with https带有 https 的 Jenkins Git 插件
【发布时间】:2020-05-27 16:25:41
【问题描述】:

我正在尝试使用 Git 插件在 Jenkins 中配置一个 Git 项目。在项目配置页面中,我在 Git 配置中输入存储库 URL,即 https URL (https://git.mycompany.com/git/MyProject.git)。但是,当我构建项目时,出现以下错误:

Started by user Hudson Administrator
[EnvInject] - Loading node environment variables.
Building in workspace /home/hudson/.hudson/jobs/MyProject/workspace
Checkout:workspace / /home/hudson/.hudson/jobs/MyProject/workspace - hudson.remoting.LocalChannel@3699cfcc
Using strategy: Default
Cloning the remote Git repository
Cloning repository https://git.mycompany.com/git/MyProject.git
git --version
git version 1.8.2.1
ERROR: Error cloning remote repo 'origin' : Could not clone https://git.mycompany.com/git/MyProject.git
hudson.plugins.git.GitException: Could not clone https://git.mycompany.com/git/MyProject.git
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:286)
    at org.jenkinsci.plugins.gitclient.AbstractGitAPIImpl.clone(AbstractGitAPIImpl.java:59)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.clone(CliGitAPIImpl.java:47)
    at hudson.plugins.git.GitSCM$2.invoke(GitSCM.java:1012)
    at hudson.plugins.git.GitSCM$2.invoke(GitSCM.java:948)
    at hudson.FilePath.act(FilePath.java:912)
    at hudson.FilePath.act(FilePath.java:885)
    at hudson.plugins.git.GitSCM.determineRevisionToBuild(GitSCM.java:948)
    at hudson.plugins.git.GitSCM.checkout(GitSCM.java:1114)
    at hudson.model.AbstractProject.checkout(AbstractProject.java:1411)
    at hudson.model.AbstractBuild$AbstractBuildExecution.defaultCheckout(AbstractBuild.java:652)
    at jenkins.scm.SCMCheckoutStrategy.checkout(SCMCheckoutStrategy.java:88)
    at hudson.model.AbstractBuild$AbstractBuildExecution.run(AbstractBuild.java:557)
    at hudson.model.Run.execute(Run.java:1665)
    at hudson.maven.MavenModuleSetBuild.run(MavenModuleSetBuild.java:507)
    at hudson.model.ResourceController.execute(ResourceController.java:88)
    at hudson.model.Executor.run(Executor.java:230)
Caused by: hudson.plugins.git.GitException: Failed to connect to https://git.mycompany.com/git/MyProject.git
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.getURLWithCrendentials(CliGitAPIImpl.java:1374)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.getURLWithCrendentials(CliGitAPIImpl.java:1326)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.access$300(CliGitAPIImpl.java:47)
    at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:280)
    ... 16 more
Trying next repository
ERROR: Could not clone repository
java.io.IOException: Could not clone
    at hudson.plugins.git.GitSCM$2.invoke(GitSCM.java:1025)
    at hudson.plugins.git.GitSCM$2.invoke(GitSCM.java:948)
    at hudson.FilePath.act(FilePath.java:912)
    at hudson.FilePath.act(FilePath.java:885)
    at hudson.plugins.git.GitSCM.determineRevisionToBuild(GitSCM.java:948)
    at hudson.plugins.git.GitSCM.checkout(GitSCM.java:1114)
    at hudson.model.AbstractProject.checkout(AbstractProject.java:1411)
    at hudson.model.AbstractBuild$AbstractBuildExecution.defaultCheckout(AbstractBuild.java:652)
    at jenkins.scm.SCMCheckoutStrategy.checkout(SCMCheckoutStrategy.java:88)
    at hudson.model.AbstractBuild$AbstractBuildExecution.run(AbstractBuild.java:557)
    at hudson.model.Run.execute(Run.java:1665)
    at hudson.maven.MavenModuleSetBuild.run(MavenModuleSetBuild.java:507)
    at hudson.model.ResourceController.execute(ResourceController.java:88)
    at hudson.model.Executor.run(Executor.java:230)

我可以从命令行克隆存储库,也可以在 Jenkins 项目预构建步骤中将 git clone 作为 shell 命令执行,所以我不知道为什么插件配置不起作用.认为这可能是身份验证问题,我尝试在 .netrc 文件中指定凭据,并将它们包含在 URL 中(即https://username:password@git.mycompany.com/git/MyProject.git),但在所有情况下我仍然遇到相同的错误。有什么想法吗?

【问题讨论】:

  • 一个可能的原因是 Jenkins 无法接受您的 ssl 证书(可能不是您使用的域)
  • 确实我目前的SSL证书有问题,这就是我在全局.gitconfig中添加sslVeridy=false的原因。詹金斯没有考虑到这一点吗?有不同的配置吗?
  • 由于 Jenkins 是用 Java 编写的,它使用 Java 的接受证书列表,所以也许你只需要将它添加到该存储中。这里有一些解决方法:mkyong.com/webservices/jax-ws/…
  • 我看到了同样的问题。这是 jenkins git 插件中的一个错误。当您在 jenkins 配置中设置使用 JGit 时,您可以让它工作。或者使用 SSH。它在以前的版本中工作(几个月前)。
  • @jimpic 看来毕竟是这样。我还测试了对公共 Git 存储库的访问(以确保我传递凭据的方式没有问题),但它仍然没有工作,所以我想剩下的唯一选择是插件的错误。如果您将此作为答案发布(可能会提供有关可能解决方法的更多详细信息),我将很乐意接受。

标签: git jenkins jenkins-plugins


【解决方案1】:

这是Jenkins Git Plugin 中的一个错误。

您可以通过使用凭据插件创建凭据来解决凭据问题,然后在您的作业的 SCM/Git 部分中使用这些凭据。但是,如果检出失败,这将在构建日志中以纯文本形式公开您的用户/密码。

此外,如果您在 git 中使用 HTTP 代理,这将不起作用。 (目前)最好的方法是使用 JGit(在 Jenkins 配置中进行配置)。然而,JGit 是实验性的,在代理方面也非常有限。

(由于受欢迎的要求而发布的答案;))

【讨论】:

  • 您知道这方面是否存在未解决的问题吗?
  • +1 用于确认这是插件的错误。至少我不会发疯 :) 你有 Jenkins 错误 ID 和/或修复进度吗?我发现了几个看起来像我正在经历的错误(如果需要,我可以发布一些),但它看起来并不完全像我的,所以我不确定进展。哎呀,有人甚至说“不是缺陷”
  • 我不知道有一张未结票,我在那里没有帐户,所以我没有创建一个 - 如果有人能做到这一点,那就太好了:)
  • 那么,我们在哪里?这是一个错误吗?如果错误,那么它是否已解决?
【解决方案2】:

如果您为 Git 存储库使用自签名证书,并且 Git 从命令行而不是从 Jenkins Git 客户端插件工作,您需要将证书添加到 Jenkins Java 密钥库(如 所述tijs 在comment above)。

这是因为 Git Client 插件尝试使用 Java 的 Apache HttpClient 直接连接(绕过 git.exe),所以通常用于创建连接的所有 Git 设置都被忽略(包括 GIT_SSL_NO_VERIFY 和 curl-ca-bundle.crt) 中的证书。HttpClient throwsSunCertPathBuilderException: unable to find valid certification path to requested target 不幸地被包裹在一个没有堆栈跟踪的 GitException 中,所以我们只能看到 'Failed to connect' 消息。

为了修复它,您可以点击 tijs 提供的链接: http://www.mkyong.com/webservices/jax-ws/suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/

如果您使用默认 Jenkins 安装,则需要将生成的 jssecacerts 文件复制到 C:\Program Files (x86)\Jenkins\jre\lib\security。

您可以在原始 Andreas Sterbenz post(感谢 web.archive.org)中找到指向 InstallCert.java 的链接,或者在 code.google 中找到稍作修改的版本。

我检查了上述方法是否适用于 Git Client 插件版本 1.4.6。

【讨论】:

  • 尚未在 Jenkins 中验证它,但对于 Teamcity 来说,一种更简单的方法也可以使用 - 只需在 Jenkins 的 jre 目录中运行以下命令:bin\keytool -Import -Noprompt -Keystore lib\security\cacerts -Deststorepass changeit -Alias -File
【解决方案3】:

将您的 Git 客户端升级到 2.10.0 或更高版本。

执行以下命令。

git config --system http.sslVerify false    
git config --global http.sslVerify false    

【讨论】:

  • 我可以知道你为什么恢复我的(绝对正确的)格式吗?
  • 我是新来的。所以我不明白你的ans的目的。但现在我知道了,所以你可以改变它。感谢支持。
【解决方案4】:

Main page of git plugin 有话要说:

如果您看到指示 Git 无法克隆的输出,则说明 像下面的输出一样,转到 Jenkins 配置设置 (不是项目设置,全局设置)并将 Git 路径更改为 一个完全限定的路径(例如,不是“git”而是“/usr/bin/git”或任何地方 您的 Git 二进制文件已安装)。您还应该验证 如果您正在执行基于文件系统的克隆,则权限是正确的。

Started by user anonymous
Checkout:workspace / C:\Documents and Settings\Administrator\.hudson\jobs\watir\workspace - hudson.remoting.LocalChannel@1a1f370
Last Build : #4
Checkout:workspace / C:\Documents and Settings\Administrator\.hudson\jobs\watir\workspace - hudson.remoting.LocalChannel@1a1f370
Cloning the remote Git repository
Cloning repository origin
$ git clone -o origin git://github.com/bret/watir.git "C:\Documents and Settings\Administrator\.hudson\jobs\watir\workspace"
Trying next repository
ERROR: Could not clone from a repository
FATAL: Could not clone
hudson.plugins.git.GitException: Could not clone
    at hudson.plugins.git.GitSCM$2.invoke(GitSCM.java:400)
    at hudson.plugins.git.GitSCM$2.invoke(GitSCM.java:358)
    at hudson.FilePath.act(FilePath.java:676)
    at hudson.FilePath.act(FilePath.java:660)
    at hudson.plugins.git.GitSCM.checkout(GitSCM.java:358)
    at hudson.model.AbstractProject.checkout(AbstractProject.java:833)
    at hudson.model.AbstractBuild$AbstractRunner.checkout(AbstractBuild.java:314)
    at hudson.model.AbstractBuild$AbstractRunner.run(AbstractBuild.java:266)
    at hudson.model.Run.run(Run.java:948)
    at hudson.model.Build.run(Build.java:112)
    at hudson.model.ResourceController.execute(ResourceController.java:93)
    at hudson.model.Executor.run(Executor.java:118)

这对你来说可能也是个问题。

如果默认插件行为存在问题,同一页面还建议使用 JGit 进行测试 (-Dorg.jenkinsci.plugins.gitclient.Git.useCLI=false)。

【讨论】:

  • 我见过这个,但至少在我的情况下,这不是问题。
【解决方案5】:

为了在Jenkins中使用Git,需要安装以下两个插件:

  1. Git 客户端插件
  2. Git 插件

第一个插件(Git-Client-plugin)是一个执行 git 操作(git add, git commit, git push,git clone,..etc)的低级 API。

第二个插件 (Git-plugin) 添加 Git 作为 Jenkins 作业的 SCM 选项。

第二个插件依赖于第一个插件的功能,因此两者都必须存在,Git 才能与 Jenkins 一起工作。

【讨论】:

    【解决方案6】:

    您可以使用您的登录名和密码在“凭据”中注册您的git凭据以访问git通过 https 协议(在“管理 Jenkins”下方)存储库,它将生成一个 credentialId(例如 dd0d6733-cc2e-4464-bb7d-4b6af86fe40a ) 帮助 Jenkins 在管道中使用此凭证。

    当您使用 Jenkins Pipeline 时,您可以:

    node{
        git url: "https://tfs:8080/tfs/job.git", branch: "feature/migration", credentialsId:'dd0d6733-cc2e-4464-bb7d-4b6af86fe40a'
    }
    

    它将您的源代码下载到作业的工作区

    【讨论】:

      【解决方案7】:

      我尝试了所有方法来解决证书问题,但最后是 git 插件的问题。我将插件回滚到 git 1.5(来自 2.0.3)和 git-client 1.0.7(来自 1.6.3)并且它工作正常。请注意,我首先尝试了 git-client 1.4.6,以便可以使用凭据选项,但它没有用。所以我认为这两个插件的正确组合很重要。 JENKINS-20533

      提到了这个解决方案

      【讨论】:

        【解决方案8】:

        在我的例子中,一个 Jenkins 奴隶正常工作,而另一个没有。当我将 Git 可执行文件从默认更改为 JGit 时,它们都可以工作。

        【讨论】:

          【解决方案9】:

          这个问题现在已经修复,并且不再是最新插件的问题(因为我正在编写这个 1.19.0)。它发生在 git-plugin-client 1.6.x 上。

          【讨论】:

            【解决方案10】:

            使用 git:// 而不是 https:// 在 jenkins 1.644 和 git 客户端 1.19.6 上为我工作

            【讨论】:

              【解决方案11】:

              我的解决方案确实适用于 Jenkins-Git-Plugin。

              # create my exec
              su root
              darngit=/usr/bin/darngit
              touch $darngit
              echo "#! /usr/bin/env bash" > $darngit
              echo "git -c sslVerify=false $@" > $darngit
              

              转到系统设置,设置 git 可执行文件 = /usr/bin/darngit

              【讨论】:

                猜你喜欢
                • 2021-11-01
                • 1970-01-01
                • 2014-12-31
                • 2019-02-10
                • 1970-01-01
                • 1970-01-01
                • 2010-12-05
                • 1970-01-01
                • 2012-07-15
                相关资源
                最近更新 更多