You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Bitbucket staging环境部署管道运行失败求助

Bitbucket Staging部署管道SSH连接失败问题解决

问题概述

Bitbucket Staging环境的部署管道已成功将Docker镜像推送至Docker Hub,但服务器部署环节失败。修改bitbucket-pipeline.yml和服务器端deployment.yml后问题仍未解决,需实现管道自动完成部署。

相关配置文件

bitbucket-pipeline.yml

image: atlassian/default-image:4

pipelines:
  branches:
    staging:
      - step:
          name: Build Docker Images
          services:
            - docker
          caches:
            - docker-cache  
          script:
            - docker build -t admintdocker08/admin_staging:python-${BITBUCKET_COMMIT:0:7} ./services/
            - echo "$DOCKER_HUB_PASSWORD" | docker login -u "$DOCKER_HUB_USERNAME" --password-stdin
            - docker push admintdocker08/admin_staging:python-${BITBUCKET_COMMIT:0:7}

      - step:
          name: Deploy to Staging
          deployment: staging
          services:
            - docker
          script:
            - pipe: atlassian/ssh-run:0.8.1
              variables:
                SSH_USER: "root"
                SERVER: "$STAGING_SERVER_IP"
                COMMAND: |
                  cd /root/deployment
                  PYTHON_TAG=${BITBUCKET_COMMIT:0:7} docker-compose -f deployment.yml up -d python

definitions:
  services:
    docker:
      memory: 2048
  caches:
    docker-cache: /var/lib/docker

服务器端deployment.yml

services:
  python:
    image: admintdocker08/admin_staging:python-${PYTHON_TAG}
    container_name: python
    env_file: "python.env"
    ports:
      - "8010:8010"  # Map port 8010 inside the container to port 8010 on the host
    networks:
      - webnet
    restart: always

管道错误信息

Status: Downloaded newer image for bitbucketpipelines/ssh-run:0.8.1
INFO: Executing the pipe...
INFO: Using default ssh key
INFO: Executing command on 191.1,2,3
ssh -A -tt -i /root/.ssh/pipelines_id -o StrictHostKeyChecking=no -p 22 root@191.1,2,3,4 bash -c cd /root/deployment
PYTHON_TAG=2art0b7 docker-compose -f deployment.yml up -d pythonai

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:Dd5/fOmFyxv8KlHnz.
Please contact your system administrator.
Add correct host key in /root/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /root/.ssh/known_hosts:8
Password authentication is disabled to avoid man-in-the-middle attacks.
Keyboard-interactive authentication is disabled to avoid man-in-the-middle attacks.
Agent forwarding is disabled to avoid man-in-the-middle attacks.
UpdateHostkeys is disabled because the host key is not trusted.
root@191.1.2.3.4: Permission denied (publickey,password).
✖ Execution failed.

问题分析

核心错误是远程主机标识已更改:Bitbucket管道的SSH客户端检测到目标服务器的主机密钥与本地known_hosts中存储的旧密钥不一致,触发安全拦截,即使配置了StrictHostKeyChecking=no,但管道环境的known_hosts已有旧条目,仍导致SSH连接被拒绝。此外,错误信息中命令出现pythonai,与deployment.yml中的服务名python不符,存在笔误;原bitbucket-pipeline.yml中script缩进错误,可能影响命令执行。

解决方案

1. 清理旧主机密钥并修正部署命令

修改bitbucket-pipeline.yml中Deploy步骤的COMMAND,先删除目标服务器的旧主机密钥,再执行部署命令,同时修正服务名笔误:

COMMAND: |
  ssh-keygen -R "${STAGING_SERVER_IP}"
  cd /root/deployment
  PYTHON_TAG=${BITBUCKET_COMMIT:0:7} docker-compose -f deployment.yml up -d python

2. 修正YAML缩进错误

确保bitbucket-pipeline.yml中script、variables等节点的缩进正确(YAML对缩进敏感),修正后的Deploy步骤结构如下:

- step:
    name: Deploy to Staging
    deployment: staging
    services:
      - docker
    script:
      - pipe: atlassian/ssh-run:0.8.1
        variables:
          SSH_USER: "root"
          SERVER: "$STAGING_SERVER_IP"
          COMMAND: |
            ssh-keygen -R "${STAGING_SERVER_IP}"
            cd /root/deployment
            PYTHON_TAG=${BITBUCKET_COMMIT:0:7} docker-compose -f deployment.yml up -d python

3. 验证SSH密钥配置

  • 确认Bitbucket管道中配置的SSH公钥已正确添加到目标服务器root用户的~/.ssh/authorized_keys文件中。
  • 检查服务器/etc/ssh/sshd_config,确保PermitRootLogin yes(允许root用户通过公钥登录),并重启SSH服务:systemctl restart sshd。

内容的提问来源于stack exchange,提问作者harish nair

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 21:14:58