GitLab Pavlovia SSH密钥认证失败:Permission denied (publickey)
解决GitLab Pavlovia多账号SSH认证失败问题
核心问题定位
从你提供的SSH debug日志可以看到:
debug1: Will attempt key: /Users/warrenpettine/.ssh/id_rsa_gitlab_pavlovia_um RSA SHA256:Lm8V+7wUbTDazm7k7RClvnZYQkUA+kmGwG7Evh9kha4 explicit agent
但你配置的SSH config里指定的密钥是id_rsa_gitlab_pavlovia,文件名不匹配是导致认证失败的直接原因之一。此外,同一GitLab实例下多账号需要通过SSH Host别名区分配置,否则会出现密钥混淆。
分步解决方案
1. 修正密钥文件名与SSH配置的匹配
- 要么将本地密钥文件重命名为SSH config中指定的名称:
mv ~/.ssh/id_rsa_gitlab_pavlovia_um ~/.ssh/id_rsa_gitlab_pavlovia mv ~/.ssh/id_rsa_gitlab_pavlovia_um.pub ~/.ssh/id_rsa_gitlab_pavlovia.pub - 要么修改
~/.ssh/config中的IdentityFile路径,改为实际的密钥文件名。
2. 多账号SSH配置规范
针对两个账号分别配置独立的Host别名,避免密钥冲突:
编辑~/.ssh/config,替换原有内容为:
# 账号A专属配置 Host gitlab-pavlovia-A HostName gitlab.pavlovia.org User git PreferredAuthentications publickey IdentityFile ~/.ssh/id_rsa_gitlab_pavlovia_A # 账号B专属配置 Host gitlab-pavlovia-B HostName gitlab.pavlovia.org User git PreferredAuthentications publickey IdentityFile ~/.ssh/id_rsa_gitlab_pavlovia_B
注意:
User必须设为git,GitLab所有SSH认证均使用该用户名,通过密钥关联对应账号- 两个账号的密钥文件需分别命名(比如
id_rsa_gitlab_pavlovia_A和id_rsa_gitlab_pavlovia_B),避免混淆
3. 验证密钥与权限设置
- 确认公钥完整添加到对应GitLab账号的SSH设置中:复制公钥文件的全部内容(从
ssh-rsa开头到邮箱结尾),确保无多余空格、换行 - 修复文件权限(SSH对权限要求严格):
chmod 700 ~/.ssh chmod 600 ~/.ssh/id_rsa_gitlab_pavlovia_* chmod 644 ~/.ssh/id_rsa_gitlab_pavlovia_*.pub - 重置SSH代理并重新加载密钥:
执行ssh-add -D ssh-add ~/.ssh/id_rsa_gitlab_pavlovia_A ssh-add ~/.ssh/id_rsa_gitlab_pavlovia_Bssh-add -l确认两个密钥均已加载
4. 测试认证
分别测试两个账号的连接:
- 账号A:
ssh -v -T gitlab-pavlovia-A - 账号B:
ssh -v -T gitlab-pavlovia-B
如果成功,会返回Welcome to GitLab, @你的用户名!的提示
额外排查点
- 检查GitLab账号中的SSH密钥是否处于启用状态,无过期/禁用标记
- 确认密钥生成时的邮箱与对应GitLab账号关联
内容的提问来源于stack exchange,提问作者WWP
相关产品推荐
相关产品推荐

