运维系列 | Jenkins错误com.michelin.cio.hudson.plugins.rolestrategy.RoleBasedAuthorizationStrategy
卸载 Role-based Authorization Strategy这个插件导致的错误
问题
如果配置错了,可以登录到Jenkins那台机器,找到$JENKINS_HOME目录下的config.xml配置文件,因为我配置错误了,所以这里面我贴一下出错后的配置:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 | <?xml version= '1.1' encoding= 'UTF-8' ?> <hudson> <disabledAdministrativeMonitors/> <version>2.121.1</version> <installStateName>RUNNING</installStateName> <numExecutors>3</numExecutors> <mode>NORMAL</mode> <useSecurity> true </useSecurity> <authorizationStrategy class = "com.michelin.cio.hudson.plugins.rolestrategy.RoleBasedAuthorizationStrategy" > <roleMap type= "projectRoles" > <role name= "op" pattern= "op.*" > <permissions> <permission>hudson.model.Item.Create</permission> <permission>hudson.model.Run.Delete</permission> <permission>hudson.model.Item.Workspace</permission> <permission>hudson.model.Run.Replay</permission> <permission>hudson.model.Item.Configure</permission> <permission>hudson.model.Item.Cancel</permission> <permission>hudson.model.Item.Delete</permission> <permission>hudson.model.Item.Read</permission> <permission>hudson.model.Item.Build</permission> <permission>hudson.scm.SCM.Tag</permission> <permission>hudson.model.Item.Move</permission> <permission>hudson.model.Item.Discover</permission> <permission>hudson.model.Run.Update</permission> </permissions> <assignedSIDs/> </role> </roleMap> <roleMap type= "globalRoles" > <role name= "admin" pattern= ".*" > <permissions> <permission>hudson.model.View.Delete</permission> <permission>hudson.model.Computer.Connect</permission> <permission>hudson.model.Run.Delete</permission> <permission>com.cloudbees.plugins.credentials.CredentialsProvider.ManageDomains</permission> <permission>hudson.model.Computer.Create</permission> <permission>hudson.model.View.Configure</permission> <permission>hudson.model.Computer.Build</permission> <permission>hudson.model.Item.Configure</permission> <permission>hudson.model.Hudson.Administer</permission> <permission>hudson.model.Item.Cancel</permission> <permission>hudson.model.Item.Read</permission> <permission>com.cloudbees.plugins.credentials.CredentialsProvider.View</permission> <permission>hudson.model.Computer.Delete</permission> <permission>hudson.model.Item.Build</permission> <permission>hudson.scm.SCM.Tag</permission> <permission>hudson.model.Item.Move</permission> <permission>hudson.model.Item.Discover</permission> <permission>hudson.model.Hudson.Read</permission> <permission>com.cloudbees.plugins.credentials.CredentialsProvider.Update</permission> <permission>hudson.model.Item.Create</permission> <permission>hudson.model.Item.Workspace</permission> <permission>com.cloudbees.plugins.credentials.CredentialsProvider.Delete</permission> <permission>hudson.model.Computer.Provision</permission> <permission>hudson.model.Run.Replay</permission> <permission>hudson.model.View.Read</permission> <permission>hudson.model.View.Create</permission> <permission>hudson.model.Item.Delete</permission> <permission>hudson.model.Computer.Configure</permission> <permission>com.cloudbees.plugins.credentials.CredentialsProvider.Create</permission> <permission>hudson.model.Computer.Disconnect</permission> <permission>hudson.model.Run.Update</permission> </permissions> <assignedSIDs/> </role> <role name= "op" pattern= ".*" > <permissions> <permission>hudson.model.Hudson.Read</permission> <permission>hudson.model.Item.Cancel</permission> <permission>hudson.model.Item.Read</permission> <permission>hudson.model.Item.Build</permission> <permission>hudson.scm.SCM.Tag</permission> <permission>hudson.model.View.Read</permission> </permissions> <assignedSIDs> <sid>chenmo</sid> </assignedSIDs> </role> </roleMap> <roleMap type= "slaveRoles" /> </authorizationStrategy> <securityRealm class = "hudson.security.HudsonPrivateSecurityRealm" > <disableSignup> false </disableSignup> <enableCaptcha> false </enableCaptcha> </securityRealm> <disableRememberMe> false </disableRememberMe> <projectNamingStrategy class = "jenkins.model.ProjectNamingStrategy$DefaultProjectNamingStrategy" /> <workspaceDir>${JENKINS_HOME}/workspace/${ITEM_FULL_NAME}</workspaceDir> <buildsDir>${ITEM_ROOTDIR}/builds</buildsDir> <markupFormatter class = "hudson.markup.EscapedMarkupFormatter" /> <jdks> <jdk> <name>java-1.8-openjdk</name> <home>/usr/lib/jvm/ default -jvm</home> <properties/> </jdk> </jdks> <viewsTabBar class = "hudson.views.DefaultViewsTabBar" /> <myViewsTabBar class = "hudson.views.DefaultMyViewsTabBar" /> <clouds/> <quietPeriod>5</quietPeriod> <scmCheckoutRetryCount>0</scmCheckoutRetryCount> <views> <hudson.model.AllView> <owner class = "hudson" reference= "../../.." /> <name>all</name> <description>### 部署项目之前请在微信里通知</description> <filterExecutors> false </filterExecutors> <filterQueue> false </filterQueue> <properties class = "hudson.model.View$PropertyList" /> </hudson.model.AllView> </views> <primaryView>all</primaryView> <slaveAgentPort>50000</slaveAgentPort> <disabledAgentProtocols> < string >JNLP-connect</ string > < string >JNLP2-connect</ string > </disabledAgentProtocols> <label></label> <crumbIssuer class = "hudson.security.csrf.DefaultCrumbIssuer" > <excludeClientIPFromCrumb> false </excludeClientIPFromCrumb> </crumbIssuer> <nodeProperties/> <globalNodeProperties/> </hudson> |
这里面有个节点,authorizationStrategy,这个节点作用就是配置权限的策略,这里我们由于使用了Role-based Authorization Strategy插件,因此就会是这个策略。
1 2 3 | <authorizationStrategy class = "com.michelin.cio.hudson.plugins.rolestrategy.RoleBasedAuthorizationStrategy" > </authorizationStrategy> |
解决
解决办法很简单,你只需要修改conifg.xml文件中的这个策略,将下面节点整个删除掉。
1 2 3 | <authorizationStrategy class = "com.michelin.cio.hudson.plugins.rolestrategy.RoleBasedAuthorizationStrategy" > </authorizationStrategy> |
替换成:
1 2 3 | <authorizationStrategy class = "hudson.security.FullControlOnceLoggedInAuthorizationStrategy" > <denyAnonymousReadAccess> false </denyAnonymousReadAccess> </authorizationStrategy> |
这个权限对应”登录用“可以做任何事”。
此时重启Jenkins后会重新加载此配置文件,然后就一切正常了,如果出现了有些项目未成功加载的情况,不要慌张,去升级一下插件就好!
【推荐】还在用 ECharts 开发大屏?试试这款永久免费的开源 BI 工具!
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· .NET 原生驾驭 AI 新基建实战系列:向量数据库的应用与畅想
· 从问题排查到源码分析:ActiveMQ消费端频繁日志刷屏的秘密
· 一次Java后端服务间歇性响应慢的问题排查记录
· dotnet 源代码生成器分析器入门
· ASP.NET Core 模型验证消息的本地化新姿势
· ThreeJs-16智慧城市项目(重磅以及未来发展ai)
· .NET 原生驾驭 AI 新基建实战系列(一):向量数据库的应用与畅想
· Ai满嘴顺口溜,想考研?浪费我几个小时
· Browser-use 详细介绍&使用文档
· 智能Agent如何改造传统工作流:从搜索到全能助手
2017-03-09 【转】Nginx配置location总结及rewrite规则写法
2017-03-09 【转】(总结)Nginx配置文件nginx.conf中文详解
2017-03-09 Nginx模块Lua-Nginx-Module学习笔记(二)Lua指令详解(Directives)