You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub Action部署Laravel应用到Ubuntu VPS失败求助

问题描述

尝试通过GitHub Action将Laravel应用部署到Ubuntu VPS时,SSH连接失败,错误日志如下:

1s
Run ssh -v -o StrictHostKeyChecking=no root@89.117.36.246 'echo "SSH connection successful"'
OpenSSH_9.6p1 Ubuntu-3ubuntu13.5, OpenSSL 3.0.13 30 Jan 2024
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug1: Connecting to 89.117.36.246 [89.117.36.246] port 22.
debug1: Connection established.
debug1: identity file /home/runner/.ssh/id_rsa type -1
debug1: identity file /home/runner/.ssh/id_rsa-cert type -1
debug1: identity file /home/runner/.ssh/id_ecdsa type -1
debug1: identity file /home/runner/.ssh/id_ecdsa-cert type -1
debug1: identity file /home/runner/.ssh/id_ecdsa_sk type -1
debug1: identity file /home/runner/.ssh/id_ecdsa_sk-cert type -1
debug1: identity file /home/runner/.ssh/id_ed25519 type -1
debug1: identity file /home/runner/.ssh/id_ed25519-cert type -1
debug1: identity file /home/runner/.ssh/id_ed25519_sk type -1
debug1: identity file /home/runner/.ssh/id_ed25519_sk-cert type -1
debug1: identity file /home/runner/.ssh/id_xmss type -1
debug1: identity file /home/runner/.ssh/id_xmss-cert type -1
debug1: identity file /home/runner/.ssh/id_dsa type -1
debug1: identity file /home/runner/.ssh/id_dsa-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.5
debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6p1 Ubuntu-3ubuntu13.5
debug1: compat_banner: match: OpenSSH_9.6p1 Ubuntu-3ubuntu13.5 pat OpenSSH* compat 0x04000000
debug1: Authenticating to 89.117.36.246:22 as 'root'
debug1: load_hostkeys: fopen /home/runner/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: sntrup761x25519-sha512@openssh.com
debug1: kex: host key algorithm: rsa-sha2-512
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-rsa SHA256:cgFpf3vL9Eo8wJinsZ9XMe8HmrLbGzQN9Gy0niGisA4
debug1: load_hostkeys: fopen /home/runner/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host '89.117.36.246' is known and matches the RSA host key.
debug1: Found key in /home/runner/.ssh/known_hosts:5
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: Sending SSH2_MSG_EXT_INFO
debug1: expecting SSH2_MSG_NEWKEYS
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 134217728 blocks
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_ext_info_client_parse: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256>
debug1: kex_ext_info_check_ver: publickey-hostbound@openssh.com=<0>
debug1: kex_ext_info_check_ver: ping@openssh.com=<0>
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_ext_info_client_parse: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256>
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: agent returned 1 keys
debug1: Will attempt key: cengr.wahid@gmail.com RSA SHA256:03n0BMa15ODRTf2sE4F82bt1RxZDaxV2j8OvQFVuKO4 agent
debug1: Will attempt key: /home/runner/.ssh/id_rsa 
debug1: Will attempt key: /home/runner/.ssh/id_ecdsa 
debug1: Will attempt key: /home/runner/.ssh/id_ecdsa_sk 
debug1: Will attempt key: /home/runner/.ssh/id_ed25519 
debug1: Will attempt key: /home/runner/.ssh/id_ed25519_sk 
debug1: Will attempt key: /home/runner/.ssh/id_xmss 
debug1: Will attempt key: /home/runner/.ssh/id_dsa 
debug1: Offering public key: cengr.wahid@gmail.com RSA SHA256:03n0BMa15ODRTf2sE4F82bt1RxZDaxV2j8OvQFVuKO4 agent
debug1: Authentications that can continue: publickey,password
debug1: Trying private key: /home/runner/.ssh/id_rsa
debug1: Trying private key: /home/runner/.ssh/id_ecdsa
debug1: Trying private key: /home/runner/.ssh/id_ecdsa_sk
debug1: Trying private key: /home/runner/.ssh/id_ed25519
debug1: Trying private key: /home/runner/.ssh/id_ed25519_sk
debug1: Trying private key: /home/runner/.ssh/id_xmss
debug1: Trying private key: /home/runner/.ssh/id_dsa
debug1: Next authentication method: password
debug1: read_passphrase: can't open /dev/tty: No such device or address
debug1: Authentications that can continue: publickey,password
Permission denied, please try again.
debug1: read_passphrase: can't open /dev/tty: No such device or address
debug1: Authentications that can continue: publickey,password
Permission denied, please try again.
debug1: read_passphrase: can't open /dev/tty: No such device or address
debug1: Authentications that can continue: publickey,password
debug1: No more authentication methods to try.
root@89.117.36.246: Permission denied (publickey,password).
Error: Process completed with exit code 255.
问题分析

从日志可知,SSH连接建立后,公钥认证失败,随后尝试密码认证但因无终端无法输入,最终触发权限拒绝。核心问题是GitHub Action使用的SSH密钥未被VPS正确授权。

解决方案

1. 验证VPS上的公钥配置

  • 登录VPS的root账户,查看/root/.ssh/authorized_keys文件,确认是否包含GitHub Action使用的私钥对应的公钥
  • 确保权限符合要求:
    • .ssh目录权限设为700:chmod 700 /root/.ssh
    • authorized_keys文件权限设为600:chmod 600 /root/.ssh/authorized_keys
  • 若文件不存在,手动创建:mkdir -p /root/.ssh && touch /root/.ssh/authorized_keys

2. 正确配置GitHub Action的SSH密钥

  • 在GitHub仓库的Settings > Secrets and variables > Actions中,添加新Secret(如命名为SSH_PRIVATE_KEY),值为无密码短语的SSH私钥内容
  • 在Workflow文件中使用webfactory/ssh-agent加载密钥,示例:
jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - name: 拉取代码
        uses: actions/checkout@v4

      - name: 配置SSH代理
        uses: webfactory/ssh-agent@v0.8.0
        with:
          ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }}

      - name: 测试SSH连接
        run: ssh -o StrictHostKeyChecking=no root@89.117.36.246 'echo "SSH连接成功"'

3. 确保VPS允许root用户SSH登录

  • 编辑VPS上的/etc/ssh/sshd_config文件,将PermitRootLogin设为yes或prohibit-password(后者仅允许密钥登录,更安全)
  • 重启SSH服务:systemctl restart sshd

4. 排查密钥不匹配问题

  • 重新生成无密码短语的密钥对:ssh-keygen -t ed25519 -f ~/.ssh/laravel-deploy -N ""
  • 将公钥~/.ssh/laravel-deploy.pub内容复制到VPS的/root/.ssh/authorized_keys中
  • 将私钥~/.ssh/laravel-deploy内容更新到GitHub仓库的Secret中

内容的提问来源于stack exchange,提问作者Wahidul Alam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 03:15:07