使用Docker Compose远程部署Docker镜像时遭遇SSH认证失败及多次密码输入异常问题
Problem Overview
You're trying to use docker-compose to deploy Docker images to a remote server over SSH, but hitting authentication roadblocks:
- With docker-compose 1.27.4, running your command throws a
paramiko.ssh_exception.AuthenticationException: Authentication failederror stack. - When upgrading to docker-compose 1.28.5, you can connect but get prompted for a password five times in a row.
Your environment details:
- docker-compose 1.27.4 / 1.28.5
- Docker 20.10.5
- Ubuntu 18.04
The command you ran:
sudo docker-compose -H "ssh://root@jenkins.evercam.io" --tlscacert "~/.ssh/id_jenkins" -f evercam_camera_server/docker-compose.yml ps
Root Cause Analysis
- Wrong Parameter Usage: The
--tlscacertflag is meant for Docker's TLS certificate authentication (for secure TCP connections), not for SSH private keys. You're passing an SSH key to a TLS-specific parameter, which confuses the docker-compose SSH client and leads to authentication failures in older versions. - Sudo Environment Path Issue: When using
sudo, the~expands to/rootinstead of your user's home directory. So~/.ssh/id_jenkinspoints to/root/.ssh/id_jenkins(which likely doesn't exist) instead of your actual private key path. - Multiple Password Prompts in 1.28.5: The newer version falls back to password authentication when it can't load the SSH key correctly, and paramiko (the SSH library docker-compose uses) retries multiple authentication methods, leading to repeated password prompts.
Fixes & Workarounds
1. Correct the Command Parameters
Replace the incorrect --tlscacert flag with SSH-specific options to specify your private key. Use -o IdentityFile= to point to your key, and use an absolute path instead of ~ when using sudo:
sudo docker-compose -H "ssh://root@jenkins.evercam.io" -o IdentityFile="/home/your_username/.ssh/id_jenkins" -f evercam_camera_server/docker-compose.yml ps
(Replace your_username with your actual Ubuntu username.)
2. Simplify with SSH Config
Create or edit ~/.ssh/config to define the remote host settings, which avoids repeating parameters in every docker-compose command:
Host jenkins-server HostName jenkins.evercam.io User root IdentityFile /home/your_username/.ssh/id_jenkins
Then your command becomes much cleaner:
sudo docker-compose -H "ssh://jenkins-server" -f evercam_camera_server/docker-compose.yml ps
(Note: Make sure the config file has correct permissions: chmod 600 ~/.ssh/config)
3. Fix Key Permissions & Agent Forwarding
- Ensure your private key has strict permissions (otherwise SSH will reject it):
chmod 600 /home/your_username/.ssh/id_jenkins - If you don't want to enter your key passphrase every time, add the key to your SSH agent:
When usingssh-add /home/your_username/.ssh/id_jenkinssudo, you might need to forward the agent withsudo -Eto preserve theSSH_AUTH_SOCKenvironment variable:sudo -E docker-compose -H "ssh://jenkins-server" -f evercam_camera_server/docker-compose.yml ps
4. Verify Remote Server Setup
Double-check that your public key (id_jenkins.pub) is added to the remote server's /root/.ssh/authorized_keys file. You can do this quickly with:
ssh-copy-id -i /home/your_username/.ssh/id_jenkins.pub root@jenkins.evercam.io
Final Notes
After applying these fixes, both older and newer docker-compose versions should work without authentication errors or repeated password prompts. The key mistake was mixing up Docker TLS authentication parameters with SSH key authentication—once that's corrected, the rest is about ensuring proper pathing and permissions.
内容的提问来源于stack exchange,提问作者Sadmi

