GitHub Actions中使用Cloudflared无法SSH连接的问题排查
我正尝试配置GitHub Actions,通过Cloudflared以SSH方式连接服务器,但运行Action时遇到连接失败问题。
我的Action配置
name: Deploy to Server on: push: branches: - main jobs: deploy: name: Deploy runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v2 - name: Set up Cloudflared run: | sudo mkdir -p --mode=0755 /usr/share/keyrings curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/null echo 'deb [signed-by=/usr/share/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared jammy main' | sudo tee /etc/apt/sources.list.d/cloudflared.list sudo apt-get update && sudo apt-get install cloudflared - name: Setup SSH run: | mkdir -p ~/.ssh echo "${{ secrets.SSH_PRIVATE_KEY }}" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 echo "${{ secrets.SSH_KNOWN_HOSTS }}" > ~/.ssh/known_hosts chmod 644 ~/.ssh/known_hosts cat <<EOF > ~/.ssh/config Host ${{ secrets.SSH_HOST }} User ${{ secrets.SSH_USER }} IdentityFile ~/.ssh/id_ed25519 ProxyCommand cloudflared access ssh --hostname %h EOF chmod 600 ~/.ssh/config shell: bash - name: Deploy via SSH run: | ssh -vvv -o StrictHostKeyChecking=yes ${{ secrets.SSH_HOST }} "echo 'HelloWorld!'" shell: bash
服务器配置
- 本地生成SSH密钥对,私钥已添加到GitHub Secrets(
SSH_PRIVATE_KEY),公钥已加入服务器authorized_keys文件。 - 服务器Cloudflared隧道配置:
tunnel: footlab-pi credentials-file: /etc/cloudflared/e894a30f-3b76-44e1-a530-665abf34a062.json ingress: - hostname: footlab.uk service: https://proxy:443 originRequest: originServerName: footlab.uk - hostname: ssh.footlab.uk service: ssh://host.docker.internal:22 - service: http_status:404
SSH子域名ssh.footlab.uk可正常访问,本地能通过Cloudflared连接服务器SSH。
错误信息
GitHub Action运行时抛出以下错误:
debug1: Reading configuration data /home/runner/.ssh/config debug1: /home/runner/.ssh/config line 1: Applying options for *** debug1: Reading configuration data /etc/ssh/ssh_config debug1: Executing proxy command: exec cloudflared access ssh --hostname *** debug1: identity file /home/runner/.ssh/id_ed25519 type -1 debug1: identity file /home/runner/.ssh/id_ed25519-cert type -1 kex_exchange_identification: Connection closed by remote host Connection closed by UNKNOWN port 65535 Error: Process completed with exit code 255.
疑问
出现“Connection closed by remote host”的原因是什么?如何正确配置GitHub Action实现通过Cloudflared的SSH连接?是否是ProxyCommand调用Cloudflared的方式有误,或是其他配置问题?
已尝试操作
- 验证SSH密钥对配置(私钥在Secrets,公钥在服务器授权)。
- 确认服务器Cloudflared隧道配置正常,本地连接无问题。
- 为SSH命令添加
-vvv参数调试。
核心问题分析
错误根源主要有两点:
- GitHub Actions runner是全新环境,没有本地的Cloudflare Access认证会话,而
cloudflared access ssh默认需要身份验证,导致隧道连接失败。 - SSH私钥写入时的格式问题,以及Cloudflared版本兼容性可能引发连接异常。
具体修复步骤
1. 调整ProxyCommand参数
如果你的SSH子域名未启用Cloudflare Access身份验证,直接在ProxyCommand中添加--no-authn跳过认证:
cat <<EOF > ~/.ssh/config Host ${{ secrets.SSH_HOST }} User ${{ secrets.SSH_USER }} IdentityFile ~/.ssh/id_ed25519 ProxyCommand cloudflared access ssh --hostname %h --no-authn EOF
如果启用了Cloudflare Access认证,需在GitHub Secrets中添加CF_ACCESS_TOKEN(从Cloudflare Zero Trust控制台生成服务令牌),修改ProxyCommand为:
ProxyCommand CF_ACCESS_TOKEN=${{ secrets.CF_ACCESS_TOKEN }} cloudflared access ssh --hostname %h
2. 安装最新版Cloudflared
替换原有的Cloudflared安装步骤,直接安装官方最新稳定版,避免版本适配问题:
- name: Set up Cloudflared run: | curl -L --output cloudflared.deb https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb sudo dpkg -i cloudflared.deb
3. 修复SSH私钥格式问题
GitHub Secrets粘贴私钥时可能丢失换行符,用printf代替echo写入,保证私钥格式完整:
printf "%s" "${{ secrets.SSH_PRIVATE_KEY }}" > ~/.ssh/id_ed25519
4. 测试时临时放宽主机密钥检查
若known_hosts配置有误,可临时设置StrictHostKeyChecking=no验证连接,确认正常后再修正known_hosts:
ssh -vvv -o StrictHostKeyChecking=no ${{ secrets.SSH_HOST }} "echo 'HelloWorld!'"
5. 验证Cloudflared连接状态
在Action中添加测试步骤,确认Cloudflared能正常识别隧道:
- name: Test Cloudflared connection run: | cloudflared tunnel info footlab-pi
完整修复后的Action配置示例
name: Deploy to Server on: push: branches: - main jobs: deploy: name: Deploy runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Cloudflared run: | curl -L --output cloudflared.deb https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb sudo dpkg -i cloudflared.deb - name: Setup SSH run: | mkdir -p ~/.ssh printf "%s" "${{ secrets.SSH_PRIVATE_KEY }}" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 printf "%s" "${{ secrets.SSH_KNOWN_HOSTS }}" > ~/.ssh/known_hosts chmod 644 ~/.ssh/known_hosts cat <<EOF > ~/.ssh/config Host ${{ secrets.SSH_HOST }} User ${{ secrets.SSH_USER }} IdentityFile ~/.ssh/id_ed25519 ProxyCommand cloudflared access ssh --hostname %h --no-authn EOF chmod 600 ~/.ssh/config shell: bash - name: Deploy via SSH run: | ssh -vvv -o StrictHostKeyChecking=yes ${{ secrets.SSH_HOST }} "echo 'HelloWorld!'" shell: bash
内容的提问来源于stack exchange,提问作者Alfonso Falcone

