【问题标题】:How to deploy with .gitlab-ci.yml in runner used by docker?如何在 docker 使用的运行器中使用 .gitlab-ci.yml 进行部署?
【发布时间】:2020-01-01 22:21:53
【问题描述】:

我使用本教程安装了 docker 和 gitlab + 一个跑步者:https://frenchco.de/article/Add-un-Runner-Gitlab-CE-Docker

问题是当我尝试修改 .gitlab-ci.yml 以在我的主机上进行部署时,我无法做到。

我的 .yml :

stages:
  - deploy

deploy_develop:
   stage: deploy
   before_script:
     - apk update && apk add bash && apk add openssh && apk add rsync
     - apk add --no-cache bash
   script:
     - mkdir -p ~/.ssh
     - ssh-keygen -t rsa -N "" -f ~/.ssh/id_rsa
     - cat ~/.ssh/id_rsa.pub
     - rsync -hrvz ~/ root@172.16.1.97:~/web_dev/www/test/
   environment:
     name: develop

问题在于,在 ssh 或 rsync 中,我的工作中总是出现相同的错误消息:

$ rsync -hrvz ~/ root@172.16.1.97:~/web_dev/www/test/
Host key verification failed.
rsync: connection unexpectedly closed (0 bytes received so far) [sender]
rsync error: unexplained error (code 255) at io.c(226) [sender=3.1.3]

我尝试复制主机中的ssh id_rsa和id_rsa.pub,还是一样。

肯定有问题,因为我的跑步者是在一个码头可以吗?这很奇怪,因为自从执行 .yml 以来,我设法 ping 我的主机(172.16.1.97)。一个想法有我的问题?

【问题讨论】:

    标签: deployment gitlab runner


    【解决方案1】:

    您似乎没有将公钥添加到部署用户的主机服务器上的 authorized_keys 中?

    例如,我使用 gitlab-ci 来部署我的 webapp,因此我在我的主机上添加了用户 gitlab,并将公钥添加到 authorized_keys,然后我可以与 ssh gitlab@IP -i PRIVATE_KEY 连接到那个服务器。

    我的gitlab-ci.yml 看起来像这样:

    deploy-app:
      stage: deploy
      image: ubuntu
      before_script:
        - apt-get update -qq
        - 'which ssh-agent || ( apt-get install -qq openssh-client )'
        - eval $(ssh-agent -s)
        - ssh-add <(cat "$DEPLOY_SERVER_PRIVATE_KEY")
        - mkdir -p ~/.ssh
        - '[[ -f /.dockerenv ]] && echo -e "Host *\n\tStrictHostKeyChecking no\n\n" > ~/.ssh/config'
        - chmod 755 ./deploy.sh
      script:
        - ./deploy.sh
    

    我将私钥的内容作为变量添加到我的 gitlab-instance 中。 (见https://docs.gitlab.com/ee/ci/variables/)

    deploy.sh 看起来像这样:

    #!/bin/bash
    set -eo pipefail
    
    scp app/docker-compose.yml gitlab@"${DEPLOY_SERVER_IP}":~/apps/${NGINX_SERVER_NAME}/
    ssh gitlab@$DEPLOY_SERVER_IP "apps/${NGINX_SERVER_NAME}/app.sh update" # this is just doing docker-compose pull && docker-compose up in the app's directory.
    

    也许这有帮助?它对我来说工作正常,并且 scp/ssh 给出的错误消息比在这种特殊情况下使用 rsync 得到的错误消息更直观。

    【讨论】:

      猜你喜欢
      • 2022-01-09
      • 2018-11-29
      • 2017-02-13
      • 2017-05-31
      • 2018-10-24
      • 1970-01-01
      • 2020-02-20
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多