在jenkinsfile中运行AWS ECR扫描命令

尝试在Jenkins文件中的以下2条命令下运行 注意:以下命令在安装Jenkins的本地运行正常

sh '''  aws ecr start-image-scan --registry-id 123 \
           --repository-name test1 \
           --image-id imagetag=${BUILD_NUMber} --output json | tee ecr_start_scan_${BUILD_NUMber}.txt'''


sh ''' aws ecr describe-image-scan-findings --registry-id 123 \
          --repository-name test \
          --image-id imagetag=${BUILD_NUMber}  --output json | tee ecr_scanResult_${BUILD_NUMber}.txt'''

下面是这两个命令的输出:

+ aws ecr start-image-scan --repository-name valhalla --image-id imagetag=13 --region ap-southeast-1 --output json
+ tee ecr_start_scan_13.txt
usage: aws [options] <command> <subcommand> [<subcommand> ...] [parameters]
To see help text,you can run:

  aws help
  aws <command> help
  aws <command> <subcommand> help
aws: error: argument operation: Invalid choice,valid choices are:

batch-check-layer-availability           | batch-delete-image                      
batch-get-image                          | complete-layer-upload                   
create-repository                        | delete-lifecycle-policy                 
delete-repository                        | delete-repository-policy                
describe-images                          | describe-repositories                   
get-authorization-token                  | get-download-url-for-layer              
get-lifecycle-policy                     | get-lifecycle-policy-preview            
get-repository-policy                    | initiate-layer-upload                   
list-images                              | put-image                               
put-lifecycle-policy                     | set-repository-policy                   
start-lifecycle-policy-preview           | upload-layer-part                       
get-login                                | help                                    
xjdyjk2007 回答:在jenkinsfile中运行AWS ECR扫描命令

更新AWS CLI版本。。我在 aws-cli / 1.11.13 中也遇到了同样的问题。但是在 aws-cli / 1.18.16

中得到了预期的结果 ,

是的,更新 AWS CLI 版本可以解决问题,但我认为中间缺少一个步骤 aws ecr wait image-scan-complete,因为扫描结果不会立即显示,因此此命令会等到可以访问结果。

本文链接:https://www.f2er.com/2569134.html

大家都在问