更换Bitbucket URL后Windows Jenkins Slave节点无法拉取Git仓库
Windows Jenkins Slave无法从新Bitbucket URL拉取Git仓库问题
环境信息
- Jenkins与Windows Slave节点采用SSH密钥认证
- 使用ssh agent Jenkins插件进行SSH认证
错误日志
using credential 046a6520-abcd-abcd-abcd-abcdb1139e55 Fetching changes from the remote Git repository ERROR: Error fetching remote repo 'origin' hudson.plugins.git.GitException: Failed to fetch from ssh://git@bitbucket.<new url>.com/<project>/<repo>.git at hudson.plugins.git.GitSCM.fetchFrom(GitSCM.java:1002) at hudson.plugins.git.GitSCM.retrieveChanges(GitSCM.java:1244) at hudson.plugins.git.GitSCM.checkout(GitSCM.java:1308) at org.jenkinsci.plugins.workflow.steps.scm.SCMStep.checkout(SCMStep.java:129) at org.jenkinsci.plugins.workflow.steps.scm.SCMStep$StepExecutionImpl.run(SCMStep.java:97) at org.jenkinsci.plugins.workflow.steps.scm.SCMStep$StepExecutionImpl.run(SCMStep.java:84) at org.jenkinsci.plugins.workflow.steps.SynchronousNonBlockingStepExecution.lambda$start$0(SynchronousNonBlockingStepExecution.java:47) at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511) at java.util.concurrent.FutureTask.run(FutureTask.java:266) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at java.lang.Thread.run(Thread.java:750) Caused by: hudson.plugins.git.GitException: Command "git fetch --tags --force --progress -- ssh://git@bitbucket.<new url>.com/<project>/<repo>.git +refs/heads/*:refs/remotes/origin/*" returned status code 128: stdout: stderr: No RSA host key is known for bitbucket.<new url>.com and you have requested strict checking. Host key verification failed. fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandIn(CliGitAPIImpl.java:2734) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandWithCredentials(CliGitAPIImpl.java:2111) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.access$500(CliGitAPIImpl.java:87)
已执行的检查
- 通过命令
eval 'ssh-agent -s' && ssh-add验证Windows节点已加载正确的SSH密钥 - 通过流水线脚本
script { bat 'echo %USERNAME%' }验证用户上下文正确 - 重启Windows节点
- 执行命令移除Git凭证助手配置:
git config --global --unset credential.helper、git config --system --unset credential.helper - 重新安装Git并添加至系统路径
解决方案
1. 为Jenkins运行用户添加新Bitbucket域名的主机密钥
Windows Jenkins Slave通常以本地系统账户或指定服务账户运行,手动克隆用的是当前登录用户,两者的known_hosts文件路径不同:
- 本地系统账户:
C:\Windows\System32\config\systemprofile\.ssh\known_hosts - 自定义服务账户:
C:\Users\<服务账户名>\.ssh\known_hosts
操作步骤:
- 打开命令提示符,切换到Jenkins运行用户的目录:
- 系统账户:
cd C:\Windows\System32\config\systemprofile - 自定义账户:
cd C:\Users\<服务账户名>
- 系统账户:
- 若
.ssh目录不存在,先创建:mkdir .ssh - 执行命令添加主机密钥:
ssh-keyscan bitbucket.<new url>.com >> .ssh\known_hosts
2. 手动指定Git的SSH配置(可选)
若Git无法自动识别默认known_hosts路径,可在流水线中明确指定:
script { bat 'git config --global core.sshCommand "ssh -i <SSH密钥路径> -o UserKnownHostsFile=<known_hosts文件路径>"' }
替换<SSH密钥路径>和<known_hosts文件路径>为实际路径,例如C:\Windows\System32\config\systemprofile\.ssh\id_rsa和C:\Windows\System32\config\systemprofile\.ssh\known_hosts
3. 确保Jenkins用户拥有密钥文件权限
右键.ssh目录 → 「属性」→ 「安全」:
- 添加Jenkins服务账户,赋予「读取和执行」权限
- 对密钥文件(如
id_rsa)设置读取权限,避免权限过高(不要给Everyone完全控制)
内容的提问来源于stack exchange,提问作者Hemanth Sundareshan
相关产品推荐
相关产品推荐

