ci: pass registry auth directly to buildx via --auth flag
The docker-container driver's buildkit session mechanism does not reliably forward host Docker credentials to the buildkit container, causing every docker buildx build --push to fail with 401 Unauthorized on the manifest HEAD request. Fix: remove the standalone Login Registry stage and embed withCredentials directly into each build stage, passing credentials to buildkit via the docker buildx build --auth flag: --auth 'reg.nxsir.cn=:' This sends auth directly to buildkit rather than relying on the implicit docker login -> config.json -> session forwarding chain. Each stage also does a docker login for the host CLI (needed for buildx inspect --bootstrap to pull images from the registry, and for cache-from/cache-to operations). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Vendored
+22
-17
@@ -52,23 +52,6 @@ pipeline {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
stage('Login Registry') {
|
|
||||||
steps {
|
|
||||||
withCredentials([
|
|
||||||
usernamePassword(
|
|
||||||
credentialsId: "${DOCKER_CREDS}",
|
|
||||||
usernameVariable: 'DOCKER_USERNAME',
|
|
||||||
passwordVariable: 'DOCKER_PASSWORD'
|
|
||||||
)
|
|
||||||
]) {
|
|
||||||
sh """
|
|
||||||
set -e
|
|
||||||
echo "\$DOCKER_PASSWORD" | sudo docker login ${REGISTRY_URL} -u "\$DOCKER_USERNAME" --password-stdin
|
|
||||||
"""
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
stage('Prepare Buildx') {
|
stage('Prepare Buildx') {
|
||||||
steps {
|
steps {
|
||||||
sh """
|
sh """
|
||||||
@@ -122,8 +105,18 @@ EOF
|
|||||||
|
|
||||||
stage('Build And Push API Image') {
|
stage('Build And Push API Image') {
|
||||||
steps {
|
steps {
|
||||||
|
withCredentials([
|
||||||
|
usernamePassword(
|
||||||
|
credentialsId: "${DOCKER_CREDS}",
|
||||||
|
usernameVariable: 'DOCKER_USERNAME',
|
||||||
|
passwordVariable: 'DOCKER_PASSWORD'
|
||||||
|
)
|
||||||
|
]) {
|
||||||
sh """
|
sh """
|
||||||
set -e
|
set -e
|
||||||
|
# Login to registry (buildx docker-container driver does not
|
||||||
|
# always forward host auth — --auth below is the authoritative path).
|
||||||
|
echo "\$DOCKER_PASSWORD" | sudo docker login ${REGISTRY_URL} -u "\$DOCKER_USERNAME" --password-stdin
|
||||||
run_with_heartbeat() {
|
run_with_heartbeat() {
|
||||||
log_file="\$1"
|
log_file="\$1"
|
||||||
build_label="\$2"
|
build_label="\$2"
|
||||||
@@ -170,6 +163,7 @@ EOF
|
|||||||
--provenance=false \
|
--provenance=false \
|
||||||
--cache-from type=registry,ref=${API_CACHE_IMAGE} \
|
--cache-from type=registry,ref=${API_CACHE_IMAGE} \
|
||||||
--cache-to type=registry,ref=${API_CACHE_IMAGE},mode=max \
|
--cache-to type=registry,ref=${API_CACHE_IMAGE},mode=max \
|
||||||
|
--auth "${REGISTRY_URL}=\$DOCKER_USERNAME:\$DOCKER_PASSWORD" \
|
||||||
--build-arg HTTP_PROXY=${HTTP_PROXY_URL} \
|
--build-arg HTTP_PROXY=${HTTP_PROXY_URL} \
|
||||||
--build-arg HTTPS_PROXY=${HTTP_PROXY_URL} \
|
--build-arg HTTPS_PROXY=${HTTP_PROXY_URL} \
|
||||||
--build-arg NO_PROXY=${NO_PROXY_HOSTS} \
|
--build-arg NO_PROXY=${NO_PROXY_HOSTS} \
|
||||||
@@ -182,13 +176,22 @@ EOF
|
|||||||
--push \
|
--push \
|
||||||
.
|
.
|
||||||
"""
|
"""
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
stage('Build And Push Web Image') {
|
stage('Build And Push Web Image') {
|
||||||
steps {
|
steps {
|
||||||
|
withCredentials([
|
||||||
|
usernamePassword(
|
||||||
|
credentialsId: "${DOCKER_CREDS}",
|
||||||
|
usernameVariable: 'DOCKER_USERNAME',
|
||||||
|
passwordVariable: 'DOCKER_PASSWORD'
|
||||||
|
)
|
||||||
|
]) {
|
||||||
sh """
|
sh """
|
||||||
set -e
|
set -e
|
||||||
|
echo "\$DOCKER_PASSWORD" | sudo docker login ${REGISTRY_URL} -u "\$DOCKER_USERNAME" --password-stdin
|
||||||
run_with_heartbeat() {
|
run_with_heartbeat() {
|
||||||
log_file="\$1"
|
log_file="\$1"
|
||||||
build_label="\$2"
|
build_label="\$2"
|
||||||
@@ -235,6 +238,7 @@ EOF
|
|||||||
--provenance=false \
|
--provenance=false \
|
||||||
--cache-from type=registry,ref=${WEB_CACHE_IMAGE} \
|
--cache-from type=registry,ref=${WEB_CACHE_IMAGE} \
|
||||||
--cache-to type=registry,ref=${WEB_CACHE_IMAGE},mode=max \
|
--cache-to type=registry,ref=${WEB_CACHE_IMAGE},mode=max \
|
||||||
|
--auth "${REGISTRY_URL}=\$DOCKER_USERNAME:\$DOCKER_PASSWORD" \
|
||||||
--build-arg NODE_IMAGE=${WEB_NODE_IMAGE} \
|
--build-arg NODE_IMAGE=${WEB_NODE_IMAGE} \
|
||||||
--build-arg NGINX_IMAGE=${WEB_NGINX_IMAGE} \
|
--build-arg NGINX_IMAGE=${WEB_NGINX_IMAGE} \
|
||||||
--build-arg HTTP_PROXY=${HTTP_PROXY_URL} \
|
--build-arg HTTP_PROXY=${HTTP_PROXY_URL} \
|
||||||
@@ -250,6 +254,7 @@ EOF
|
|||||||
--push \
|
--push \
|
||||||
frontend
|
frontend
|
||||||
"""
|
"""
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user