Jenkins声明性管道-将Docker映像推送到私有Docker Hub仓库

时间:2019-03-29 10:32:47

标签: docker jenkins

我尝试从Jenkins推送到私有dockerhub仓库,但是我猜总是由于授权而出错。

以下是相关的詹金斯管道:

pipeline {
  agent {
    // run this pipeline inside an docker image with node 8 and git installed
    docker {
      image 'node/8-alpine'
      registryUrl 'https://registry.hub.docker.com'
      registryCredentialsId 'dockerhub' // the id of username/password credentials I have in Jenkins
    }
  }
  environment {
    registry = '<my-org>/<my-project>'
    tag_beta = "${currentBuild.displayName}-${env.BRANCH_NAME}"
  }
  stages {

    stage("Docker") {
      steps {
          script {
            // NPM_TOKEN was set as environment variable inside Jenkins
            def image = docker.build("${env.registry}:${env.tag-beta}",  "-e NPM_TOKEN=${env.NPM_TOKEN}")
            /* Push the container to the custom Registry */
            image.push()
          }

      }
    }
  }
}

这是错误堆栈跟踪

groovy.lang.MissingPropertyException: No such property: beta for class: groovy.lang.Binding
    at groovy.lang.Binding.getVariable(Binding.java:63)
    at org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.SandboxInterceptor.onGetProperty(SandboxInterceptor.java:264)
    at org.kohsuke.groovy.sandbox.impl.Checker$6.call(Checker.java:289)
    at org.kohsuke.groovy.sandbox.impl.Checker.checkedGetProperty(Checker.java:293)
    at org.kohsuke.groovy.sandbox.impl.Checker.checkedGetProperty(Checker.java:269)
    at org.kohsuke.groovy.sandbox.impl.Checker.checkedGetProperty(Checker.java:269)
    at org.kohsuke.groovy.sandbox.impl.Checker.checkedGetProperty(Checker.java:269)
    at org.kohsuke.groovy.sandbox.impl.Checker.checkedGetProperty(Checker.java:269)
    at com.cloudbees.groovy.cps.sandbox.SandboxInvoker.getProperty(SandboxInvoker.java:29)
    at com.cloudbees.groovy.cps.impl.PropertyAccessBlock.rawGet(PropertyAccessBlock.java:20)
    at WorkflowScript.run(WorkflowScript:57)
    at ___cps.transform___(Native Method)
    at com.cloudbees.groovy.cps.impl.PropertyishBlock$ContinuationImpl.get(PropertyishBlock.java:74)
    at com.cloudbees.groovy.cps.LValueBlock$GetAdapter.receive(LValueBlock.java:30)
    at com.cloudbees.groovy.cps.impl.PropertyishBlock$ContinuationImpl.fixName(PropertyishBlock.java:66)
    at sun.reflect.GeneratedMethodAccessor351.invoke(Unknown Source)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
    at java.lang.reflect.Method.invoke(Method.java:498)
    at com.cloudbees.groovy.cps.impl.ContinuationPtr$ContinuationImpl.receive(ContinuationPtr.java:72)
    at com.cloudbees.groovy.cps.impl.ConstantBlock.eval(ConstantBlock.java:21)
    at com.cloudbees.groovy.cps.Next.step(Next.java:83)
    at com.cloudbees.groovy.cps.Continuable$1.call(Continuable.java:174)
    at com.cloudbees.groovy.cps.Continuable$1.call(Continuable.java:163)
    at org.codehaus.groovy.runtime.GroovyCategorySupport$ThreadCategoryInfo.use(GroovyCategorySupport.java:129)
    at org.codehaus.groovy.runtime.GroovyCategorySupport.use(GroovyCategorySupport.java:268)
    at com.cloudbees.groovy.cps.Continuable.run0(Continuable.java:163)
    at org.jenkinsci.plugins.workflow.cps.SandboxContinuable.access$101(SandboxContinuable.java:34)
    at org.jenkinsci.plugins.workflow.cps.SandboxContinuable.lambda$run0$0(SandboxContinuable.java:59)
    at org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.GroovySandbox.runInSandbox(GroovySandbox.java:136)
    at org.jenkinsci.plugins.workflow.cps.SandboxContinuable.run0(SandboxContinuable.java:58)
    at org.jenkinsci.plugins.workflow.cps.CpsThread.runNextChunk(CpsThread.java:182)
    at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup.run(CpsThreadGroup.java:332)
    at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup.access$200(CpsThreadGroup.java:83)
    at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup$2.call(CpsThreadGroup.java:244)
    at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup$2.call(CpsThreadGroup.java:232)
    at org.jenkinsci.plugins.workflow.cps.CpsVmExecutorService$2.call(CpsVmExecutorService.java:64)
    at java.util.concurrent.FutureTask.run(FutureTask.java:266)
    at hudson.remoting.SingleLaneExecutorService$1.run(SingleLaneExecutorService.java:131)
    at jenkins.util.ContextResettingExecutorService$1.run(ContextResettingExecutorService.java:28)
    at jenkins.security.ImpersonatingExecutorService$1.run(ImpersonatingExecutorService.java:59)
    at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)
    at java.util.concurrent.FutureTask.run(FutureTask.java:266)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
    at java.lang.Thread.run(Thread.java:748)
Finished: FAILURE

我也尝试过

docker.withRegistry('', "myJenkinsCredentialsIdForDockerhub") {            
  /* Push the container to the custom Registry */
  image.push()
}

任何有关如何从Jenkins声明性管道到私有Docker Hub注册表进行身份验证的帮助都将受到赞赏!

4 个答案:

答案 0 :(得分:1)

我认为您有错字:

def image = docker.build("${env.registry}:${env.tag-beta}",  "-e NPM_TOKEN=${env.NPM_TOKEN}"

应该是

def image = docker.build("${env.registry}:${env.tag_beta}",  "-e NPM_TOKEN=${env.NPM_TOKEN}"

请注意$ {env.tag_beta}中的_

答案 1 :(得分:1)

这里是我如何使用两个标签创建图像,将其推送到私有存储库并从本地删除图像的方法:

stage('Build and Push Docker Images'){
    steps{
        script {
            def imageName = "${containerRegistry}/${serviceName}/${optionalImageName}"
            docker.withRegistry("https://${containerRegistry}/${serviceName}", "1feb1e1e-9999-41bb-a269-89c999999999") {
                def customImage = docker.build(imageName)
                customImage.push("${newVersion}")
                customImage.push("latest")
                sh "docker rmi --force \$(docker images -q ${customImage.id} | uniq)"
            }
        }
    }
}

答案 2 :(得分:1)

withRegistry需要将注册表作为第一个参数,将凭据ID(用于jenkins凭据)作为第二个参数。工作示例方法:

/**
 * Stage **Push to registry**
 * login to Docker registry
 * @param dockerRegistryURL
 * @param dockerRegistryCredentialsId - Jenkins stored credentials for Docker registry
 * @param pushLatest - if true will push again with tag latest
 * @param newImage - Docker image handle with freshly built image to be pushed
 */
void push(String dockerRegistryURL, String dockerRegistryCredentialsId, boolean pushLatest, newImage) {
    stage('Push to registry') {
        echo (
            "pushing to registry url: 'https://${dockerRegistryURL}' " +
            "with credentials: '${dockerRegistryCredentialsId}'"
        )
        docker.withRegistry("https://${dockerRegistryURL}", dockerRegistryCredentialsId) {
            newImage.push()
            if (pushLatest)
                newImage.push("latest")
        }
    }
}

答案 3 :(得分:0)

在这篇文章中有一个很好的解决方案,它为我工作:https://issues.jenkins-ci.org/browse/JENKINS-48437?focusedCommentId=338354&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-338354

node {
    withDockerRegistry([credentialsId: 'docker-creds', url: 'https://index.docker.io/v1/']) {
        echo "Hello"
    }
}