Github Action中cloudflared隧道SSH连接报kex_exchange_identification错误求助
通过Cloudflare Tunnel在GitHub Action中SSH连接失败的排查方案
问题描述
我在GitHub Action中尝试通过cloudflared隧道连接后端服务器,用rsync同步项目,但出现连接错误。已经测试过直接放行防火墙22端口可以正常连接,SSH私钥没问题。远程服务器上看不到任何登录失败记录,怀疑问题出在SSH配置或Cloudflare拦截,求排查方法。
对应的GitHub Action Workflow代码
--- name: test cloudflared on: push: branches: - main pull_request: types: [opened, synchronize, reopened] jobs: cloudflared: name: test cloudflared runs-on: ubuntu-latest timeout-minutes: 15 defaults: run: shell: bash steps: - name: Checkout uses: actions/checkout@v3 with: fetch-depth: 0 - name: install cloudflared run: | curl -L https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-archive-keyring.gpg >/dev/null echo "deb [signed-by=/usr/share/keyrings/cloudflare-archive-keyring.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.list sudo apt update sudo apt-get install cloudflared - name: test cloudflared run: | which cloudflared whereis cloudflared /usr/local/bin/cloudflared --version - name: install-ssh-key uses: shimataro/ssh-key-action@v2 with: key: ${{ secrets.SSH_PRIVATE_KEY }} name: id_rsa known_hosts: ${{ secrets.KNOWN_HOSTS }} config: | Host testhost HostName ${{ vars.HOST }} User ${{ vars.USER }} IdentityFile ~/.ssh/id_rsa ProxyCommand /usr/local/bin/cloudflared access ssh --hostname %h - name: test ssh run: ssh -vvv testhost 'whoami'
GitHub Action输出日志
OpenSSH_8.9p1 Ubuntu-3ubuntu0.4, OpenSSL 3.0.2 15 Mar 2022 debug1: Reading configuration data /home/runner/.ssh/config debug1: /home/runner/.ssh/config line 2: Applying options for testhost debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/runner/.ssh/known_hosts' debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/runner/.ssh/known_hosts2' debug1: Executing proxy command: exec /usr/local/bin/cloudflared access ssh --hostname ssh.myhost.com debug1: identity file /home/runner/.ssh/id_rsa type -1 debug1: identity file /home/runner/.ssh/id_rsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.4 kex_exchange_identification: Connection closed by remote host Connection closed by UNKNOWN port 65535 Error: Process completed with exit code 255.
排查步骤
1. 验证Cloudflare Tunnel基础配置
- 确认Cloudflare Access已正确配置SSH应用,
${{ vars.HOST }}对应的域名(如ssh.myhost.com)已绑定到Access应用,且关联的隧道处于活跃状态。 - 在远程服务器上执行
cloudflared tunnel list查看隧道状态,systemctl status cloudflared确认cloudflared服务正常运行。
2. 修正ProxyCommand路径与参数
- 从测试步骤的
which cloudflared输出确认cloudflared的实际路径,确保ProxyCommand中的路径与实际一致(apt安装的cloudflared可能在/usr/bin/而非/usr/local/bin/)。 - 给ProxyCommand添加
--url ssh://localhost:22参数,明确指定转发到服务器本地22端口,修改后的配置:ProxyCommand /usr/local/bin/cloudflared access ssh --hostname %h --url ssh://localhost:22
3. 单独调试Cloudflared代理命令
- 在GitHub Action中新增步骤,执行带verbose参数的cloudflared命令,查看详细错误:
从输出中可以排查是否存在Cloudflare认证失败、域名未配置等问题。/usr/local/bin/cloudflared access ssh --hostname ${{ vars.HOST }} --url ssh://localhost:22 -v
4. 检查SSH配置细节
- 确认
known_hosts中包含隧道连接的主机指纹,或者临时在SSH命令中添加-o StrictHostKeyChecking=no(仅调试用),排除主机密钥验证故障。 - 核对
${{ vars.USER }}是否为远程服务器上存在且拥有SSH权限的用户。
5. 调整Cloudflare Access权限规则
- 如果Access应用设置了身份验证规则(如IP白名单),需将GitHub Actions的IP段加入白名单;或者使用Cloudflare服务令牌,在cloudflared命令中添加
--service-token ${{ secrets.CLOUDFLARE_SERVICE_TOKEN }},避免交互式身份验证(GitHub Action环境无法完成)。
6. 测试网络连通性
- 在GitHub Action runner中执行
curl -v https://${{ vars.HOST }},确认DNS解析正常,且能建立HTTPS连接,排除基础网络连通问题。
内容的提问来源于stack exchange,提问作者bayman
相关产品推荐
相关产品推荐

