You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab CI/CD拉取同服务器第二个仓库失败问题排查

解决GitLab CI/CD中SSH克隆仓库的Host key verification失败问题

错误原因

CI任务执行git clone时出现Host key verification failed,是因为GitLab Runner所在服务器未将目标GitLab服务器(192.168.100.179)的SSH主机密钥加入信任列表,导致SSH连接的主机验证环节失败。

解决方案

1. 自动添加目标主机的SSH密钥

在git clone命令前,用ssh-keyscan获取目标GitLab服务器的主机密钥并写入known_hosts,跳过手动验证步骤:

ssh-keyscan 192.168.100.179 >> ~/.ssh/known_hosts

2. 确认SSH私钥配置正确

  • 确保GitLab项目CI/CD变量中的$PRIVATE_KEY是文件类型变量(变量类型选择"File"),这样cat $PRIVATE_KEY才能正确输出完整的私钥内容。
  • 确认该私钥对应的公钥已添加到拥有chat-api-manifest仓库读写权限的GitLab用户(建议使用专用CI用户)的SSH密钥列表中。

3. 修复脚本中的其他潜在问题

  • 脚本注释提到要修改deployment.yaml,但实际执行的是修改docker-compose.yaml,请确认目标文件是否正确。
  • 提交信息使用了中文引号,建议替换为英文引号,避免可能的解析错误:
    git commit -m "Update image tag to $CI_COMMIT_REF_NAME"
    
  • 可以将git用户配置放在克隆后的仓库目录内,避免影响全局配置:
    cd chat-api-manifest
    git config user.email "ci@soxprox.com"
    git config user.name "CI"
    

修改后的完整deploy阶段配置

deploy:
  stage: deploy
  tags:
    - shell
  script:
    - rm -f ~/.ssh/known_hosts
    - cat $PRIVATE_KEY > ~/.ssh/id_ed25519
    - chmod 600 ~/.ssh/id_ed25519
    - ssh-keyscan 192.168.100.179 >> ~/.ssh/known_hosts
    - git clone git@192.168.100.179:soxprox/projects/chat/chat-api-manifest.git
    - cd chat-api-manifest
    - git config user.email "ci@soxprox.com"
    - git config user.name "CI"
    # 修改deployment.yaml中的镜像标签为当前分支/标签名
    - sed -i.back "/image:/s/:[0-9].*/:$CI_COMMIT_REF_NAME/g" deployment.yaml
    - git add .
    - git commit -m "Update image tag to $CI_COMMIT_REF_NAME"
    - git push origin main

内容的提问来源于stack exchange,提问作者PrestonDocks

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 17:00:19