【问题标题】:Cannot SSH using private key while building Docker image构建 Docker 映像时无法使用私钥进行 SSH
【发布时间】:2014-09-13 15:49:50
【问题描述】:

在构建 Docker 映像期间,我无法检查托管在 GitHub 上的私有 git 存储库。 SSH 在详细模式下的错误是:

OpenSSH_6.6.1, OpenSSL 1.0.1f 6 Jan 2014
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: Applying options for *
debug1: Connecting to github.com [192.30.252.130] port 22.
debug1: Connection established.
debug1: permanently_set_uid: 0/0
debug1: identity file /root/.ssh/id_rsa type -1
debug1: identity file /root/.ssh/id_rsa-cert type -1
debug1: identity file /root/.ssh/id_dsa type -1
debug1: identity file /root/.ssh/id_dsa-cert type -1
debug1: identity file /root/.ssh/id_ecdsa type -1
debug1: identity file /root/.ssh/id_ecdsa-cert type -1
debug1: identity file /root/.ssh/id_ed25519 type -1
debug1: identity file /root/.ssh/id_ed25519-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2
debug1: Remote protocol version 2.0, remote software version libssh-0.6.0
debug1: no match: libssh-0.6.0
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-ctr hmac-sha1 none
debug1: kex: client->server aes128-ctr hmac-sha1 none
debug1: sending SSH2_MSG_KEX_ECDH_INIT
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: RSA 16:27:ac:a5:76:28:2d:36:63:1b:56:4d:eb:df:a6:48
debug1: read_passphrase: can't open /dev/tty: No such device or address
Host key verification failed.

/dev/tty 设备似乎确实存在:

total 4
drwxr-xr-x   4 root root     340 Jul 22 17:12 .
drwxr-xr-x 130 root root    4096 Jul 22 17:12 ..
lrwxrwxrwx   1 root root      13 Jul 22 17:12 fd -> /proc/self/fd
crw-rw-rw-   1 root root  1,   7 Jul 22 17:12 full
c---------   1 root root 10, 229 Jul 22 17:12 fuse
lrwxrwxrwx   1 root root      11 Jul 22 17:12 kcore -> /proc/kcore
crw-rw-rw-   1 root root  1,   3 Jul 22 17:12 null
lrwxrwxrwx   1 root root       8 Jul 22 17:12 ptmx -> pts/ptmx
drwxr-xr-x   2 root root       0 Jul 22 17:12 pts
crw-rw-rw-   1 root root  1,   8 Jul 22 17:12 random
drwxrwxrwt   2 root root      40 Jul 22 17:12 shm
lrwxrwxrwx   1 root root      15 Jul 22 17:12 stderr -> /proc/self/fd/2
lrwxrwxrwx   1 root root      15 Jul 22 17:12 stdin -> /proc/self/fd/0
lrwxrwxrwx   1 root root      15 Jul 22 17:12 stdout -> /proc/self/fd/1
crw-rw-rw-   1 root root  5,   0 Jul 22 17:12 tty
crw-rw-rw-   1 root root  1,   9 Jul 22 17:12 urandom
crw-rw-rw-   1 root root  1,   5 Jul 22 17:12 zero

这是我的Dockerfile 的精简版,说明了我的测试:

FROM ubuntu:trusty

ADD . /my_app
ADD ./config/ssh/docker_ssh_key /root/.ssh/id_rsa

RUN ls -al /dev
RUN ssh -t -t -v git@github.com

CMD bundle exec thin -p $PORT -R config.ru start

我已经测试了构建并且知道密钥确实有效。如果我在不使用 RUN 命令的情况下构建映像并使用交互式 shell 启动容器,我可以很好地访问 git 存储库。

我发现了一些其他带有类似错误消息的问题。但他们是因为缺少/dev/tty,这似乎不是这里的情况。有什么想法吗?

【问题讨论】:

  • 私钥(在客户端或服务器上)是否有密码?如果是这样,也许尝试测试看看使用未加密的私钥是否会导致同样的问题。这不是最安全的设置,但它可能会帮助您隔离问题。

标签: git ssh docker openssh


【解决方案1】:

您需要接受 Github 主机密钥。使用ssh-keyscan

ssh-keyscan -t rsa github.com 2>&1 >> /root/.ssh/known_hosts

【讨论】:

猜你喜欢
  • 1970-01-01
  • 2021-12-24
  • 2019-02-22
  • 2014-08-15
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2015-11-02
  • 2020-05-21
相关资源
最近更新 更多