在构建Docker镜像时无法使用私钥进行SSH

时间:2014-07-22 17:26:57

标签: git ssh docker openssh

在Docker镜像构建期间,我无法检出GitHub上托管的私有git存储库。 SSH在详细模式下的错误是:

OpenSSH_6.6.1, OpenSSL 1.0.1f 6 Jan 2014
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: Applying options for *
debug1: Connecting to github.com [192.30.252.130] port 22.
debug1: Connection established.
debug1: permanently_set_uid: 0/0
debug1: identity file /root/.ssh/id_rsa type -1
debug1: identity file /root/.ssh/id_rsa-cert type -1
debug1: identity file /root/.ssh/id_dsa type -1
debug1: identity file /root/.ssh/id_dsa-cert type -1
debug1: identity file /root/.ssh/id_ecdsa type -1
debug1: identity file /root/.ssh/id_ecdsa-cert type -1
debug1: identity file /root/.ssh/id_ed25519 type -1
debug1: identity file /root/.ssh/id_ed25519-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2
debug1: Remote protocol version 2.0, remote software version libssh-0.6.0
debug1: no match: libssh-0.6.0
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-ctr hmac-sha1 none
debug1: kex: client->server aes128-ctr hmac-sha1 none
debug1: sending SSH2_MSG_KEX_ECDH_INIT
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: RSA 16:27:ac:a5:76:28:2d:36:63:1b:56:4d:eb:df:a6:48
debug1: read_passphrase: can't open /dev/tty: No such device or address
Host key verification failed.

似乎存在/dev/tty设备:

total 4
drwxr-xr-x   4 root root     340 Jul 22 17:12 .
drwxr-xr-x 130 root root    4096 Jul 22 17:12 ..
lrwxrwxrwx   1 root root      13 Jul 22 17:12 fd -> /proc/self/fd
crw-rw-rw-   1 root root  1,   7 Jul 22 17:12 full
c---------   1 root root 10, 229 Jul 22 17:12 fuse
lrwxrwxrwx   1 root root      11 Jul 22 17:12 kcore -> /proc/kcore
crw-rw-rw-   1 root root  1,   3 Jul 22 17:12 null
lrwxrwxrwx   1 root root       8 Jul 22 17:12 ptmx -> pts/ptmx
drwxr-xr-x   2 root root       0 Jul 22 17:12 pts
crw-rw-rw-   1 root root  1,   8 Jul 22 17:12 random
drwxrwxrwt   2 root root      40 Jul 22 17:12 shm
lrwxrwxrwx   1 root root      15 Jul 22 17:12 stderr -> /proc/self/fd/2
lrwxrwxrwx   1 root root      15 Jul 22 17:12 stdin -> /proc/self/fd/0
lrwxrwxrwx   1 root root      15 Jul 22 17:12 stdout -> /proc/self/fd/1
crw-rw-rw-   1 root root  5,   0 Jul 22 17:12 tty
crw-rw-rw-   1 root root  1,   9 Jul 22 17:12 urandom
crw-rw-rw-   1 root root  1,   5 Jul 22 17:12 zero

以下是我Dockerfile的精简版,说明了我的测试:

FROM ubuntu:trusty

ADD . /my_app
ADD ./config/ssh/docker_ssh_key /root/.ssh/id_rsa

RUN ls -al /dev
RUN ssh -t -t -v git@github.com

CMD bundle exec thin -p $PORT -R config.ru start

我测试了构建并知道密钥确实有效。如果我在没有RUN命令的情况下构建映像并启动带有交互式shell的容器,我可以很好地访问git存储库。

我发现了一些其他类似错误消息的问题。但它们是为了失踪/dev/tty而在这里似乎并非如此。有什么想法吗?

1 个答案:

答案 0 :(得分:9)

您需要接受Github主机密钥。使用ssh-keyscan

ssh-keyscan -t rsa github.com 2>&1 >> /root/.ssh/known_hosts