You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用build-push-action构建镜像时SSH密钥格式无效问题

问题

我创建了名为【Build Image】的GitHub工作流,可通过Dockerfile和secrets.SSH_KEY成功构建镜像。但另一需构建并上传镜像至GitHub Registry的【Build and Upload Image】工作流,使用相同Dockerfile和secrets.SSH_KEY时,出现Load key "/root/.ssh/id_ed25519": invalid format错误。尝试带引号和不带引号传递SSH_PRIVATE_KEY="${{ secrets.SSH_KEY }}",均出现相同错误,请问问题出在哪里?

Build Image 工作流

name: Build Image
on:
  release:
    branches: [ "main" ]
    types: [published]

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - name: Build the Docker image
        run: docker build . --build-arg SSH_PRIVATE_KEY="${{ secrets.SSH_KEY }}" --file Dockerfile --tag my_image
        working-directory: ./docker

Build and Upload Image 工作流

name: Docker Image
on:
  push:
  release:
    branches: [ "main" ]
    types: [published]

env:
  REGISTRY: ghcr.io
  IMAGE_NAME: my_image

jobs:
  build-and-push-image:
    runs-on: ubuntu-latest

    permissions:
      contents: read
      packages: write

    steps:
      - name: Checkout repository
        uses: actions/checkout@v4

      - name: Log in to the Container registry
        uses: docker/login-action@v3
        with:
          registry: ${{ env.REGISTRY }}
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}

      - name: Extract metadata (tags, labels) for Docker
        id: meta
        uses: docker/metadata-action@v5
        with:
          images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}

      - name: Build and push Docker image
        uses: docker/build-push-action@v5
        with:
          context: ./docker
          push: true
          tags: ${{ steps.meta.outputs.tags }}
          labels: ${{ steps.meta.outputs.labels }}
          build-args: |
            SSH_PRIVATE_KEY="${{ secrets.SSH_KEY }}"

错误信息

0.209 Cloning into 'my_repo'...
0.254 Warning: Permanently added the ECDSA host key for IP address '140.82.112.4' to the list of known hosts.
0.318 Load key "/root/.ssh/id_ed25519": invalid format
0.318 git@github.com: Permission denied (publickey).
0.320 fatal: Could not read from remote repository.

Dockerfile

FROM ubuntu:20.04

ARG SSH_PRIVATE_KEY
RUN mkdir /root/.ssh && chmod -R 700 /root/.ssh \
    && echo "${SSH_PRIVATE_KEY}" > /root/.ssh/id_ed25519 \
    && chmod 0400 /root/.ssh/id_ed25519 && echo "StrictHostKeyChecking no" > /root/.ssh/config \
    && ssh-keyscan github.com >> /root/.ssh/known_hosts

ARG WORKSPACE_DIR
RUN mkdir -p ${WORKSPACE_DIR}
WORKDIR ${WORKSPACE_DIR}

RUN git clone --depth 1 -b 0.1.0 git@github.com:private-repo/private-repo1.git \
    && git clone --depth 1 -b 0.1.0 git@github.com:private-repo/private-repo2.git \
    && git clone --depth 1 -b 0.21.0 https://github.com/public-repo/public-repo1.git
解决方案

问题根源在于docker/build-push-action的参数格式处理,以及密钥写入时的换行符丢失,具体修复步骤如下:

  1. 移除build-args中的引号
    使用docker/build-push-action的多行build-args格式时,不需要给变量值加引号。额外的引号会被当作密钥内容的一部分写入文件,导致格式无效。修改后的构建步骤:
- name: Build and push Docker image
  uses: docker/build-push-action@v5
  with:
    context: ./docker
    push: true
    tags: ${{ steps.meta.outputs.tags }}
    labels: ${{ steps.meta.outputs.labels }}
    build-args: |
      SSH_PRIVATE_KEY=${{ secrets.SSH_KEY }}
  1. 用printf替代echo写入密钥
    Dockerfile中echo命令会自动忽略密钥末尾的换行符,破坏SSH密钥的格式。换成printf可以完整保留密钥的原始结构:
&& printf "%s" "${SSH_PRIVATE_KEY}" > /root/.ssh/id_ed25519 \
  1. 检查密钥的完整性
    确认GitHub Secrets中的SSH_KEY没有多余的前导/尾随换行符,这也是导致密钥格式错误的常见诱因。

内容的提问来源于stack exchange,提问作者theateist

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 20:02:40