【问题标题】:Artifactory Plugin Proxy Results in /v1/_ping: Bad GatewayArtifactory 插件代理导致 /v1/_ping:网关错误
【发布时间】:2017-09-25 20:32:06
【问题描述】:

当我按照使用artifactory plugin with docker 的说明进行操作时,为什么会出现/v1/_ping: Bad Gateway 错误?

  1. jenkins 2.60.3 和 Artifactory 插件 2.12.2
  2. Enable Build-Info proxy for Docker images 9999 端口
  3. jenkins /var/lib/jenkins/secrets/jfrog/certs/jfrog.proxy.crt 添加到 jenkins master 和 slave 上的 $JAVA_HOME/jre/lib/security/cacerts
  4. jfrog nginx 自签名证书添加到 jenkins master 和 slave 上的 $JAVA_HOME/jre/lib/security/cacerts
  5. 访问 jenkins:9999 在主机之间打开
  6. /etc/systemd/system/docker.service.d/http-proxy.conf 包含以下内容,与测试没有区别

    [服务] 环境="HTTP_PROXY=http://jenkins:9999/"

    [服务] 环境="HTTPS_PROXY=https://jenkins:9999/"

  7. 本地 docker 测试 (docker login 127.0.0.1:9999) 结果

Error response from daemon: Login: Bad Request to URI: /v1/users/ (Code: 400; Headers: map[Content-Length:[30] Content-Type:[text/html; chars...

  1. Jenkins 测试结果在com.github.dockerjava.api.exception.BadRequestException: Bad Request to URI: /images/artifactory:<port>/hello-world:latest/json

Jenkins 日志中的错误

SEVERE: (DISCONNECTED) [id: ..., L:0.0.0.0/0.0.0.0:... ! R:artifactory/...:5000]: 
Caught an exception on ProxyToServerConnection
io.netty.handler.codec.DecoderException: 
javax.net.ssl.SSLHandshakeException: General SSLEngine problem
...
Caused by: sun.security.validator.ValidatorException: PKIX path building
 failed: sun.security.provider.certpath.SunCertPathBuilderException: 
 unable to find valid certification path to requested target

我的虚拟存储库,当我不使用 jenkins 代理时它的远程和本地工作,但根据插件文档,我需要 jenkins 代理来获取我需要的构建信息以进行 CI/CD 推广。

【问题讨论】:

    标签: docker jenkins-plugins artifactory


    【解决方案1】:

    如果 jenkins 不使用该证书文件,则将证书添加到 cacerts 的效果会稍差一些。我不确定向商店添加证书是否需要在 jenkins 中重新启动,但它似乎是 tomcat 的情况,所以这可能就是 jenkins 的工作方式。

    1. 将 jenkins 实例配置为使用私有密钥库 cloudbees doc on keystore
    2. 复制 $JENKINS_HOME/secrets/jfrog/certs/jfrog.proxy.crt 到 /etc/docker/certs.d/:/ca.crt
    3. 重启泊坞窗
    4. 重启詹金斯
    5. 在跟踪 jenkins 日志时通过命令行测试代理 - PASS

      docker rmi artifactory:5000/hello-world:latest docker pull artifactory:5000/hello-world:latest

    这应该使用/etc/systemd/system/docker.service.d/http-proxy.conf HTTP_PROXY 并在转到实际的工件主机时转到 jenkins 代理。应在商店中找到所需的密钥,因此 ssl 握手会很好并使用 v2 api。如果没有,你会在 jenkins.log 中看到错误

    1. 通过 shell 在节点上测试 helloworld

      node("docker-experiments") {
      withCredentials([usernamePassword(
          credentialsId: 'artifactory.jenkins.user',
          passwordVariable: 'ARTIFACTORY_PASSWORD',
          usernameVariable: 'ARTIFACTORY_USER')]) {
      
          sh "uname -a "
          def registry="artifactory:5000"
          def tag="${registry}/hello-world:${BUILD_NUMBER}-shelltest"
          stage('login') {
              sh "docker login ${registry} -u ${ARTIFACTORY_USER} -p ${ARTIFACTORY_PASSWORD}"
          }
          stage('pull and tag') {
              sh "docker pull hello-world"
              sh "docker tag hello-world:latest ${tag}"
          }
          stage('push') {
              sh "docker push ${tag}"
          }
      }
      }
      
    2. 通过 artifactory 插件在节点上测试 helloworld

      node("docker-experiments") {
      withCredentials([usernamePassword(
          credentialsId: 'artifactory.jenkins.user',
          passwordVariable: 'ARTIFACTORY_PASSWORD',
          usernameVariable: 'ARTIFACTORY_USER')]) {
      
          def server = Artifactory.server "artifactory01"
          def artDocker = Artifactory.docker(username: ARTIFACTORY_USER, 
                                             password: ARTIFACTORY_PASSWORD)
      
          def registry="artifactory:5000"
          def tag="${registry}/hello-world:${BUILD_NUMBER}-artifactoryTest"
          def dockerInfo
      
          stage('pull and tag') {
              sh "docker tag hello-world:latest ${tag}"
          }
      
          stage('push') {
            dockerInfo = artDocker.push "${tag}", "docker-local"
          }
          stage('publish') {
              server.publishBuildInfo(dockerInfo)
          }
      }
      }
      

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2019-10-18
      • 2021-09-08
      • 2018-10-26
      • 2017-02-07
      • 2022-10-24
      • 2021-05-08
      • 1970-01-01
      • 2023-02-17
      相关资源
      最近更新 更多