使用GitHub Action部署Laravel应用到Ubuntu VPS失败求助
问题描述
尝试通过GitHub Action将Laravel应用部署到Ubuntu VPS时,SSH连接失败,错误日志如下:
1s Run ssh -v -o StrictHostKeyChecking=no root@89.117.36.246 'echo "SSH connection successful"' OpenSSH_9.6p1 Ubuntu-3ubuntu13.5, OpenSSL 3.0.13 30 Jan 2024 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug1: Connecting to 89.117.36.246 [89.117.36.246] port 22. debug1: Connection established. debug1: identity file /home/runner/.ssh/id_rsa type -1 debug1: identity file /home/runner/.ssh/id_rsa-cert type -1 debug1: identity file /home/runner/.ssh/id_ecdsa type -1 debug1: identity file /home/runner/.ssh/id_ecdsa-cert type -1 debug1: identity file /home/runner/.ssh/id_ecdsa_sk type -1 debug1: identity file /home/runner/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /home/runner/.ssh/id_ed25519 type -1 debug1: identity file /home/runner/.ssh/id_ed25519-cert type -1 debug1: identity file /home/runner/.ssh/id_ed25519_sk type -1 debug1: identity file /home/runner/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /home/runner/.ssh/id_xmss type -1 debug1: identity file /home/runner/.ssh/id_xmss-cert type -1 debug1: identity file /home/runner/.ssh/id_dsa type -1 debug1: identity file /home/runner/.ssh/id_dsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.5 debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6p1 Ubuntu-3ubuntu13.5 debug1: compat_banner: match: OpenSSH_9.6p1 Ubuntu-3ubuntu13.5 pat OpenSSH* compat 0x04000000 debug1: Authenticating to 89.117.36.246:22 as 'root' debug1: load_hostkeys: fopen /home/runner/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: sntrup761x25519-sha512@openssh.com debug1: kex: host key algorithm: rsa-sha2-512 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: SSH2_MSG_KEX_ECDH_REPLY received debug1: Server host key: ssh-rsa SHA256:cgFpf3vL9Eo8wJinsZ9XMe8HmrLbGzQN9Gy0niGisA4 debug1: load_hostkeys: fopen /home/runner/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: Host '89.117.36.246' is known and matches the RSA host key. debug1: Found key in /home/runner/.ssh/known_hosts:5 debug1: ssh_packet_send2_wrapped: resetting send seqnr 3 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: Sending SSH2_MSG_EXT_INFO debug1: expecting SSH2_MSG_NEWKEYS debug1: ssh_packet_read_poll2: resetting read seqnr 3 debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 134217728 blocks debug1: SSH2_MSG_EXT_INFO received debug1: kex_ext_info_client_parse: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256> debug1: kex_ext_info_check_ver: publickey-hostbound@openssh.com=<0> debug1: kex_ext_info_check_ver: ping@openssh.com=<0> debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: SSH2_MSG_EXT_INFO received debug1: kex_ext_info_client_parse: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256> debug1: Authentications that can continue: publickey,password debug1: Next authentication method: publickey debug1: get_agent_identities: bound agent to hostkey debug1: get_agent_identities: agent returned 1 keys debug1: Will attempt key: cengr.wahid@gmail.com RSA SHA256:03n0BMa15ODRTf2sE4F82bt1RxZDaxV2j8OvQFVuKO4 agent debug1: Will attempt key: /home/runner/.ssh/id_rsa debug1: Will attempt key: /home/runner/.ssh/id_ecdsa debug1: Will attempt key: /home/runner/.ssh/id_ecdsa_sk debug1: Will attempt key: /home/runner/.ssh/id_ed25519 debug1: Will attempt key: /home/runner/.ssh/id_ed25519_sk debug1: Will attempt key: /home/runner/.ssh/id_xmss debug1: Will attempt key: /home/runner/.ssh/id_dsa debug1: Offering public key: cengr.wahid@gmail.com RSA SHA256:03n0BMa15ODRTf2sE4F82bt1RxZDaxV2j8OvQFVuKO4 agent debug1: Authentications that can continue: publickey,password debug1: Trying private key: /home/runner/.ssh/id_rsa debug1: Trying private key: /home/runner/.ssh/id_ecdsa debug1: Trying private key: /home/runner/.ssh/id_ecdsa_sk debug1: Trying private key: /home/runner/.ssh/id_ed25519 debug1: Trying private key: /home/runner/.ssh/id_ed25519_sk debug1: Trying private key: /home/runner/.ssh/id_xmss debug1: Trying private key: /home/runner/.ssh/id_dsa debug1: Next authentication method: password debug1: read_passphrase: can't open /dev/tty: No such device or address debug1: Authentications that can continue: publickey,password Permission denied, please try again. debug1: read_passphrase: can't open /dev/tty: No such device or address debug1: Authentications that can continue: publickey,password Permission denied, please try again. debug1: read_passphrase: can't open /dev/tty: No such device or address debug1: Authentications that can continue: publickey,password debug1: No more authentication methods to try. root@89.117.36.246: Permission denied (publickey,password). Error: Process completed with exit code 255.
问题分析
从日志可知,SSH连接建立后,公钥认证失败,随后尝试密码认证但因无终端无法输入,最终触发权限拒绝。核心问题是GitHub Action使用的SSH密钥未被VPS正确授权。
解决方案
1. 验证VPS上的公钥配置
- 登录VPS的root账户,查看
/root/.ssh/authorized_keys文件,确认是否包含GitHub Action使用的私钥对应的公钥 - 确保权限符合要求:
.ssh目录权限设为700:chmod 700 /root/.sshauthorized_keys文件权限设为600:chmod 600 /root/.ssh/authorized_keys
- 若文件不存在,手动创建:
mkdir -p /root/.ssh && touch /root/.ssh/authorized_keys
2. 正确配置GitHub Action的SSH密钥
- 在GitHub仓库的
Settings > Secrets and variables > Actions中,添加新Secret(如命名为SSH_PRIVATE_KEY),值为无密码短语的SSH私钥内容 - 在Workflow文件中使用
webfactory/ssh-agent加载密钥,示例:
jobs: deploy: runs-on: ubuntu-latest steps: - name: 拉取代码 uses: actions/checkout@v4 - name: 配置SSH代理 uses: webfactory/ssh-agent@v0.8.0 with: ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }} - name: 测试SSH连接 run: ssh -o StrictHostKeyChecking=no root@89.117.36.246 'echo "SSH连接成功"'
3. 确保VPS允许root用户SSH登录
- 编辑VPS上的
/etc/ssh/sshd_config文件,将PermitRootLogin设为yes或prohibit-password(后者仅允许密钥登录,更安全) - 重启SSH服务:
systemctl restart sshd
4. 排查密钥不匹配问题
- 重新生成无密码短语的密钥对:
ssh-keygen -t ed25519 -f ~/.ssh/laravel-deploy -N "" - 将公钥
~/.ssh/laravel-deploy.pub内容复制到VPS的/root/.ssh/authorized_keys中 - 将私钥
~/.ssh/laravel-deploy内容更新到GitHub仓库的Secret中
内容的提问来源于stack exchange,提问作者Wahidul Alam
相关产品推荐
相关产品推荐

