使用build-push-action构建镜像时SSH密钥格式无效问题
问题
我创建了名为【Build Image】的GitHub工作流,可通过Dockerfile和secrets.SSH_KEY成功构建镜像。但另一需构建并上传镜像至GitHub Registry的【Build and Upload Image】工作流,使用相同Dockerfile和secrets.SSH_KEY时,出现Load key "/root/.ssh/id_ed25519": invalid format错误。尝试带引号和不带引号传递SSH_PRIVATE_KEY="${{ secrets.SSH_KEY }}",均出现相同错误,请问问题出在哪里?
Build Image 工作流
name: Build Image on: release: branches: [ "main" ] types: [published] jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Build the Docker image run: docker build . --build-arg SSH_PRIVATE_KEY="${{ secrets.SSH_KEY }}" --file Dockerfile --tag my_image working-directory: ./docker
Build and Upload Image 工作流
name: Docker Image on: push: release: branches: [ "main" ] types: [published] env: REGISTRY: ghcr.io IMAGE_NAME: my_image jobs: build-and-push-image: runs-on: ubuntu-latest permissions: contents: read packages: write steps: - name: Checkout repository uses: actions/checkout@v4 - name: Log in to the Container registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata (tags, labels) for Docker id: meta uses: docker/metadata-action@v5 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} - name: Build and push Docker image uses: docker/build-push-action@v5 with: context: ./docker push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} build-args: | SSH_PRIVATE_KEY="${{ secrets.SSH_KEY }}"
错误信息
0.209 Cloning into 'my_repo'... 0.254 Warning: Permanently added the ECDSA host key for IP address '140.82.112.4' to the list of known hosts. 0.318 Load key "/root/.ssh/id_ed25519": invalid format 0.318 git@github.com: Permission denied (publickey). 0.320 fatal: Could not read from remote repository.
Dockerfile
FROM ubuntu:20.04 ARG SSH_PRIVATE_KEY RUN mkdir /root/.ssh && chmod -R 700 /root/.ssh \ && echo "${SSH_PRIVATE_KEY}" > /root/.ssh/id_ed25519 \ && chmod 0400 /root/.ssh/id_ed25519 && echo "StrictHostKeyChecking no" > /root/.ssh/config \ && ssh-keyscan github.com >> /root/.ssh/known_hosts ARG WORKSPACE_DIR RUN mkdir -p ${WORKSPACE_DIR} WORKDIR ${WORKSPACE_DIR} RUN git clone --depth 1 -b 0.1.0 git@github.com:private-repo/private-repo1.git \ && git clone --depth 1 -b 0.1.0 git@github.com:private-repo/private-repo2.git \ && git clone --depth 1 -b 0.21.0 https://github.com/public-repo/public-repo1.git
解决方案
问题根源在于docker/build-push-action的参数格式处理,以及密钥写入时的换行符丢失,具体修复步骤如下:
- 移除build-args中的引号
使用docker/build-push-action的多行build-args格式时,不需要给变量值加引号。额外的引号会被当作密钥内容的一部分写入文件,导致格式无效。修改后的构建步骤:
- name: Build and push Docker image uses: docker/build-push-action@v5 with: context: ./docker push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} build-args: | SSH_PRIVATE_KEY=${{ secrets.SSH_KEY }}
- 用
printf替代echo写入密钥
Dockerfile中echo命令会自动忽略密钥末尾的换行符,破坏SSH密钥的格式。换成printf可以完整保留密钥的原始结构:
&& printf "%s" "${SSH_PRIVATE_KEY}" > /root/.ssh/id_ed25519 \
- 检查密钥的完整性
确认GitHub Secrets中的SSH_KEY没有多余的前导/尾随换行符,这也是导致密钥格式错误的常见诱因。
内容的提问来源于stack exchange,提问作者theateist
相关产品推荐
相关产品推荐

