You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Github Action中cloudflared隧道SSH连接报kex_exchange_identification错误求助

通过Cloudflare Tunnel在GitHub Action中SSH连接失败的排查方案

问题描述

我在GitHub Action中尝试通过cloudflared隧道连接后端服务器,用rsync同步项目,但出现连接错误。已经测试过直接放行防火墙22端口可以正常连接,SSH私钥没问题。远程服务器上看不到任何登录失败记录,怀疑问题出在SSH配置或Cloudflare拦截,求排查方法。

对应的GitHub Action Workflow代码

---
name: test cloudflared

on:
  push:
    branches:
      - main
  pull_request:
    types: [opened, synchronize, reopened]

jobs:
  cloudflared:
    name: test cloudflared
    runs-on: ubuntu-latest
    timeout-minutes: 15

    defaults:
      run:
        shell: bash

    steps:
      - name: Checkout
        uses: actions/checkout@v3
        with:
          fetch-depth: 0

      - name: install cloudflared
        run: |
          curl -L https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-archive-keyring.gpg >/dev/null
          echo "deb [signed-by=/usr/share/keyrings/cloudflare-archive-keyring.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | sudo tee  /etc/apt/sources.list.d/cloudflared.list
          sudo apt update
          sudo apt-get install cloudflared

      - name: test cloudflared
        run: |
          which cloudflared
          whereis cloudflared
          /usr/local/bin/cloudflared --version

      - name: install-ssh-key
        uses: shimataro/ssh-key-action@v2
        with:
          key: ${{ secrets.SSH_PRIVATE_KEY }}
          name: id_rsa
          known_hosts: ${{ secrets.KNOWN_HOSTS }}
          config: |
            Host testhost
              HostName ${{ vars.HOST }}
              User ${{ vars.USER }}
              IdentityFile ~/.ssh/id_rsa
              ProxyCommand /usr/local/bin/cloudflared access ssh --hostname %h

      - name: test ssh
        run: ssh -vvv testhost 'whoami'

GitHub Action输出日志

OpenSSH_8.9p1 Ubuntu-3ubuntu0.4, OpenSSL 3.0.2 15 Mar 2022
debug1: Reading configuration data /home/runner/.ssh/config
debug1: /home/runner/.ssh/config line 2: Applying options for testhost
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/runner/.ssh/known_hosts'
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/runner/.ssh/known_hosts2'
debug1: Executing proxy command: exec /usr/local/bin/cloudflared access ssh --hostname ssh.myhost.com
debug1: identity file /home/runner/.ssh/id_rsa type -1
debug1: identity file /home/runner/.ssh/id_rsa-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.4
kex_exchange_identification: Connection closed by remote host
Connection closed by UNKNOWN port 65535
Error: Process completed with exit code 255.

排查步骤

1. 验证Cloudflare Tunnel基础配置

  • 确认Cloudflare Access已正确配置SSH应用,${{ vars.HOST }}对应的域名(如ssh.myhost.com)已绑定到Access应用,且关联的隧道处于活跃状态。
  • 在远程服务器上执行cloudflared tunnel list查看隧道状态,systemctl status cloudflared确认cloudflared服务正常运行。

2. 修正ProxyCommand路径与参数

  • 从测试步骤的which cloudflared输出确认cloudflared的实际路径,确保ProxyCommand中的路径与实际一致(apt安装的cloudflared可能在/usr/bin/而非/usr/local/bin/)。
  • 给ProxyCommand添加--url ssh://localhost:22参数,明确指定转发到服务器本地22端口,修改后的配置:
    ProxyCommand /usr/local/bin/cloudflared access ssh --hostname %h --url ssh://localhost:22
    

3. 单独调试Cloudflared代理命令

  • 在GitHub Action中新增步骤,执行带verbose参数的cloudflared命令,查看详细错误:
    /usr/local/bin/cloudflared access ssh --hostname ${{ vars.HOST }} --url ssh://localhost:22 -v
    
    从输出中可以排查是否存在Cloudflare认证失败、域名未配置等问题。

4. 检查SSH配置细节

  • 确认known_hosts中包含隧道连接的主机指纹,或者临时在SSH命令中添加-o StrictHostKeyChecking=no(仅调试用),排除主机密钥验证故障。
  • 核对${{ vars.USER }}是否为远程服务器上存在且拥有SSH权限的用户。

5. 调整Cloudflare Access权限规则

  • 如果Access应用设置了身份验证规则(如IP白名单),需将GitHub Actions的IP段加入白名单;或者使用Cloudflare服务令牌,在cloudflared命令中添加--service-token ${{ secrets.CLOUDFLARE_SERVICE_TOKEN }},避免交互式身份验证(GitHub Action环境无法完成)。

6. 测试网络连通性

  • 在GitHub Action runner中执行curl -v https://${{ vars.HOST }},确认DNS解析正常,且能建立HTTPS连接,排除基础网络连通问题。

内容的提问来源于stack exchange,提问作者bayman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 00:16:04