You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions中使用Cloudflared无法SSH连接的问题排查

问题描述

我正尝试配置GitHub Actions,通过Cloudflared以SSH方式连接服务器,但运行Action时遇到连接失败问题。

我的Action配置

name: Deploy to Server

on:
  push:
    branches:
      - main

jobs:
  deploy:
    name: Deploy
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v2

      - name: Set up Cloudflared
        run: |
          sudo mkdir -p --mode=0755 /usr/share/keyrings
          curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/null
          echo 'deb [signed-by=/usr/share/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared jammy main' | sudo tee /etc/apt/sources.list.d/cloudflared.list
          sudo apt-get update && sudo apt-get install cloudflared

      - name: Setup SSH
        run: |
          mkdir -p ~/.ssh
          echo "${{ secrets.SSH_PRIVATE_KEY }}" > ~/.ssh/id_ed25519
          chmod 600 ~/.ssh/id_ed25519

          echo "${{ secrets.SSH_KNOWN_HOSTS }}" > ~/.ssh/known_hosts
          chmod 644 ~/.ssh/known_hosts

          cat <<EOF > ~/.ssh/config
          Host ${{ secrets.SSH_HOST }}
            User ${{ secrets.SSH_USER }}
            IdentityFile ~/.ssh/id_ed25519
            ProxyCommand cloudflared access ssh --hostname %h
          EOF
          chmod 600 ~/.ssh/config
        shell: bash

      - name: Deploy via SSH
        run: |
          ssh -vvv -o StrictHostKeyChecking=yes ${{ secrets.SSH_HOST }} "echo 'HelloWorld!'"
        shell: bash

服务器配置

  • 本地生成SSH密钥对,私钥已添加到GitHub Secrets(SSH_PRIVATE_KEY),公钥已加入服务器authorized_keys文件。
  • 服务器Cloudflared隧道配置:
tunnel: footlab-pi
credentials-file: /etc/cloudflared/e894a30f-3b76-44e1-a530-665abf34a062.json

ingress:
  - hostname: footlab.uk
    service: https://proxy:443
    originRequest:
      originServerName: footlab.uk
  - hostname: ssh.footlab.uk
    service: ssh://host.docker.internal:22
  - service: http_status:404

SSH子域名ssh.footlab.uk可正常访问,本地能通过Cloudflared连接服务器SSH。

错误信息

GitHub Action运行时抛出以下错误:

debug1: Reading configuration data /home/runner/.ssh/config
debug1: /home/runner/.ssh/config line 1: Applying options for ***
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Executing proxy command: exec cloudflared access ssh --hostname ***
debug1: identity file /home/runner/.ssh/id_ed25519 type -1
debug1: identity file /home/runner/.ssh/id_ed25519-cert type -1
kex_exchange_identification: Connection closed by remote host
Connection closed by UNKNOWN port 65535
Error: Process completed with exit code 255.

疑问

出现“Connection closed by remote host”的原因是什么?如何正确配置GitHub Action实现通过Cloudflared的SSH连接?是否是ProxyCommand调用Cloudflared的方式有误,或是其他配置问题?

已尝试操作

  • 验证SSH密钥对配置(私钥在Secrets,公钥在服务器授权)。
  • 确认服务器Cloudflared隧道配置正常,本地连接无问题。
  • 为SSH命令添加-vvv参数调试。

解决方案

核心问题分析

错误根源主要有两点:

  1. GitHub Actions runner是全新环境,没有本地的Cloudflare Access认证会话,而cloudflared access ssh默认需要身份验证,导致隧道连接失败。
  2. SSH私钥写入时的格式问题,以及Cloudflared版本兼容性可能引发连接异常。

具体修复步骤

1. 调整ProxyCommand参数

如果你的SSH子域名未启用Cloudflare Access身份验证,直接在ProxyCommand中添加--no-authn跳过认证:

cat <<EOF > ~/.ssh/config
Host ${{ secrets.SSH_HOST }}
  User ${{ secrets.SSH_USER }}
  IdentityFile ~/.ssh/id_ed25519
  ProxyCommand cloudflared access ssh --hostname %h --no-authn
EOF

如果启用了Cloudflare Access认证,需在GitHub Secrets中添加CF_ACCESS_TOKEN(从Cloudflare Zero Trust控制台生成服务令牌),修改ProxyCommand为:

ProxyCommand CF_ACCESS_TOKEN=${{ secrets.CF_ACCESS_TOKEN }} cloudflared access ssh --hostname %h

2. 安装最新版Cloudflared

替换原有的Cloudflared安装步骤,直接安装官方最新稳定版,避免版本适配问题:

- name: Set up Cloudflared
  run: |
    curl -L --output cloudflared.deb https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb
    sudo dpkg -i cloudflared.deb

3. 修复SSH私钥格式问题

GitHub Secrets粘贴私钥时可能丢失换行符,用printf代替echo写入,保证私钥格式完整:

printf "%s" "${{ secrets.SSH_PRIVATE_KEY }}" > ~/.ssh/id_ed25519

4. 测试时临时放宽主机密钥检查

若known_hosts配置有误,可临时设置StrictHostKeyChecking=no验证连接,确认正常后再修正known_hosts:

ssh -vvv -o StrictHostKeyChecking=no ${{ secrets.SSH_HOST }} "echo 'HelloWorld!'"

5. 验证Cloudflared连接状态

在Action中添加测试步骤,确认Cloudflared能正常识别隧道:

- name: Test Cloudflared connection
  run: |
    cloudflared tunnel info footlab-pi

完整修复后的Action配置示例

name: Deploy to Server

on:
  push:
    branches:
      - main

jobs:
  deploy:
    name: Deploy
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v4

      - name: Set up Cloudflared
        run: |
          curl -L --output cloudflared.deb https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb
          sudo dpkg -i cloudflared.deb

      - name: Setup SSH
        run: |
          mkdir -p ~/.ssh
          printf "%s" "${{ secrets.SSH_PRIVATE_KEY }}" > ~/.ssh/id_ed25519
          chmod 600 ~/.ssh/id_ed25519

          printf "%s" "${{ secrets.SSH_KNOWN_HOSTS }}" > ~/.ssh/known_hosts
          chmod 644 ~/.ssh/known_hosts

          cat <<EOF > ~/.ssh/config
          Host ${{ secrets.SSH_HOST }}
            User ${{ secrets.SSH_USER }}
            IdentityFile ~/.ssh/id_ed25519
            ProxyCommand cloudflared access ssh --hostname %h --no-authn
          EOF
          chmod 600 ~/.ssh/config
        shell: bash

      - name: Deploy via SSH
        run: |
          ssh -vvv -o StrictHostKeyChecking=yes ${{ secrets.SSH_HOST }} "echo 'HelloWorld!'"
        shell: bash

内容的提问来源于stack exchange,提问作者Alfonso Falcone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 22:35:01