Jenkins通过SSH Agent连接Kubernetes Master失败,K8s集群部署遇阻求助
Let's work through why your Jenkins SSH Agent can't connect to your K8s Master, and fix the deployment pipeline along the way. I'll start with the most obvious issues first, then move to deeper debugging steps.
1. Fix the Critical Path Mismatch in Your Pipeline
First, I notice a big mistake in your script: you're copying the complete-demo.yaml file to /home/younes/k8s on the K8s Master, but then running kubectl apply -f . which looks for files in younes' home directory (/home/younes), not the k8s subfolder. That's going to fail even if the SSH connection works!
Update your pipeline to target the correct path:
stage('deploy to K8s cluster '){ steps{ sshagent(['Jenkins-Access-Kube']) { sh "scp -r -o StrictHostKeyChecking=no /home/automate-deployment-on-k8s/complete-demo.yaml younes@192.168.8.199:/home/younes/k8s" script{ try{ // Use the full path to your YAML file sh 'ssh younes@192.168.8.199 "kubectl apply -f /home/younes/k8s/complete-demo.yaml"' }catch(error){ sh 'ssh younes@192.168.8.199 "kubectl create -f /home/younes/k8s/complete-demo.yaml"' } } } } }
2. Verify Your SSH Key Setup is Correct
Even if the path is fixed, a misconfigured SSH key will block the connection. Let's double-check these details:
- Public key on K8s Master: Make sure the public key matching your Jenkins private key is added to
/home/younes/.ssh/authorized_keyson the Master. Also, set strict permissions for this file and folder:
SSHD will reject key-based login if these permissions are too open.chmod 700 /home/younes/.ssh chmod 600 /home/younes/.ssh/authorized_keys - Private key in Jenkins: Confirm the private key stored in Jenkins' Credentials (under
Jenkins-Access-Kube) is complete—including the full-----BEGIN RSA PRIVATE KEY-----and-----END RSA PRIVATE KEY-----lines, with no extra spaces or missing characters. - SSH Agent tool on Jenkins: If Jenkins is running in a container, ensure the
openssh-clientpackage is installed (runapt-get install openssh-clientinside the container if needed). Thesshagentstep relies on this tool to work.
3. Test the SSH Connection Manually
The best way to isolate the issue is to test the SSH connection directly from the Jenkins server/container, outside of the pipeline:
- Log into the machine where Jenkins is running (or exec into the Jenkins container with
docker exec -it <jenkins-container-id> bash). - Create a temporary file with your private key content (e.g.,
temp_key), then set its permissions:chmod 600 temp_key. - Run this command to test the connection:
If this fails, the error message will tell you exactly what's wrong:ssh -i temp_key younes@192.168.8.199 "echo Connected successfully && kubectl get pods"Permission denied (publickey): Double-check the authorized_keys file and permissions on the K8s Master.Host key verification failed: Add-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=noto the SSH command to bypass host key checks (or add the Master's host key to Jenkins' user known_hosts file).
4. Check K8s Master's SSHD Configuration
Ensure your K8s Master's SSH server is configured to allow key-based login:
- Edit
/etc/ssh/sshd_configand verify these settings:PubkeyAuthentication yes PasswordAuthentication no # Optional, but prevents password login attempts AllowUsers younes # If set, make sure your user is listed - Restart the SSH service to apply changes:
sudo systemctl restart sshd
5. Add Debugging to Your Pipeline
To get more visibility into what's happening during the SSH connection, add the -v (verbose) flag to your scp and ssh commands. This will print detailed logs in the Jenkins console, helping you pinpoint where the connection fails:
stage('deploy to K8s cluster '){ steps{ sshagent(['Jenkins-Access-Kube']) { sh "scp -v -r -o StrictHostKeyChecking=no /home/automate-deployment-on-k8s/complete-demo.yaml younes@192.168.8.199:/home/younes/k8s" script{ try{ sh 'ssh -v younes@192.168.8.199 "kubectl apply -f /home/younes/k8s/complete-demo.yaml"' }catch(error){ echo "Apply failed, trying create instead: ${error.getMessage()}" sh 'ssh -v younes@192.168.8.199 "kubectl create -f /home/younes/k8s/complete-demo.yaml"' } } } } }
Start with fixing the path mismatch first—this is likely the immediate issue causing your deployment to fail, even if the SSH connection works. Then work through the other steps if you still have connection problems.
内容的提问来源于stack exchange,提问作者Younes Ichiba

