Windows无WSL环境下DevContainer的SSH代理与挂载权限问题
问题1:能否实现DevContainer自动转发SSH代理?
Windows主机(未使用WSL),已创建自定义SSH密钥id_github,ssh-agent已配置自动运行,主机上使用该密钥执行git fetch无问题。主机~/.ssh/config配置如下:
Host github.com IdentityFile "~/.ssh/id_github" ForwardAgent yes
但DevContainer无法自动转发SSH代理(官方文档说明应支持),请问是否可以实现自动转发?
问题2:如何正确配置只读挂载~/.ssh到DevContainer?
作为替代方案,尝试在devcontainer.json中配置mounts项(未使用docker-compose),希望将主机~/.ssh目录以只读方式挂载到容器/home/vscode/.ssh,尝试的配置如下:
"mounts": [ "source=~/.ssh,target=/home/vscode/.ssh,readonly,type=bind" ]
但挂载后目录并非只读,执行ls -lha ~/.ssh显示权限如下:
drwxr-sr-x 1 vscode vscode 4.0K Oct 15 10:13 .. -rwxr-xr-x 1 vscode vscode 124 Oct 15 09:47 config -rwxr-xr-x 1 vscode vscode 133 Oct 15 07:58 id_github -rwxr-xr-x 1 vscode vscode 133 Oct 15 07:58 id_github.pub -rwxr-xr-x 1 vscode vscode 828 Oct 14 10:18 known_hosts -rwxr-xr-x 1 vscode vscode 92 Oct 14 10:16 known_hosts.old
使用密钥时出现以下警告:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0755 for '/home/vscode/.ssh/id_github' are too open.
请问如何正确配置只读挂载?
问题3:容器内执行sudo chmod -R 600 ~/.ssh/会修改主机权限吗?为何postCreateCommand执行后权限未改变?
尝试在容器内执行sudo chmod -R 600 ~/.ssh/,请问这会修改主机上的文件权限吗?是否会有问题?
另外,将该命令配置到devcontainer.json的postCreateCommand中:
"postCreateCommand": { "chmod-ssh": "sudo chmod -R 600 ~/.ssh/" }
日志显示命令已执行,但容器内~/.ssh目录的权限并未改变,这是为什么?
内容的提问来源于stack exchange,提问作者Asule

