You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps自托管代理Git拉取失败,托管代理运行正常

问题

此前使用Azure托管Ubuntu代理池运行Pipeline一直正常,现在在Ubuntu服务器配置了自托管代理后,Pipeline在Git拉取步骤失败。

Pipeline配置

trigger:
  batch: true
  branches:
    include:
    - main
  paths:
    include:
    - rg-test-cmn-syd-01-bastion

#pool:
  #vmImage: ubuntu-latest

pool:
  name: self-hosted
  demands:
   - agent.name -equals devops-agent-01   

variables:
  environmentName: 'dev'
  resource_group: '******'
  workDirectory: 'myworkdir'
  gitRepository: 'ssh://git@ssh.dev.azure.com/v3/myorg/myproject'
  backendType: 'azurerm'
  backendServiceArm: '***'
  backendAzureRmSubscriptionId: '*******'
  backendAzureRmResourceGroupName: '******'
  backendAzureRmStorageAccountName: '*****'
  backendAzureRmContainerName: '*****'
  backendAzureRmKey: '$(resource_group).tfstate'
  environmentServiceName: '*****'
 

stages :
  - stage: terraform_plan
    jobs:
      - job: terraform_plan
        displayName: "Terraform Plan"
        steps:
          - checkout: none

          - task: InstallSSHKey@0
            inputs:
              knownHostsEntry: $(known_host)
              sshPublicKey: '******'
              sshKeySecureFile: 'testkey'
              
          - task: CmdLine@2
            displayName: 'Git pull $(workDirectory)'
            inputs:
              script: |
                echo [command] git init
                git init
                echo [command] git sparse-checkout: $(workDirectory)
                git config core.sparsecheckout true
                echo $(workDirectory) >> .git/info/sparse-checkout
                echo [command] git remote add $(gitRepository)
                git remote add origin $(gitRepository)
                echo ##[command] git fetch --progress --verbose --depth=1 origin main
                git fetch --progress --verbose --depth=1 origin main
                ##echo ##[command] git pull --progress --verbose origin main
                git pull --progress --verbose origin main 

报错信息

##git pull --progress --verbose origin main
##[debug]workingDirectory=/myagent/_work/2/s
##[debug]check path : /myagent/_work/2/s
Generating script.
##[debug]Agent.Version=3.220.5
##[debug]agent.tempDirectory=/myagent/_work/_temp
##[debug]check path : /myagent/_work/_temp
========================== Starting Command Output ===========================
##[debug]which 'bash'
##[debug]found: '/usr/bin/bash'
##[debug]which '/usr/bin/bash'
##[debug]found: '/usr/bin/bash'
##[debug]/usr/bin/bash arg: --noprofile
##[debug]/usr/bin/bash arg: --norc
##[debug]/usr/bin/bash arg: /myagent/_work/_temp/229ea54f-8b84-413a-915a-5c29dab2b0fc.sh
##[debug]exec tool: /usr/bin/bash
##[debug]arguments:
##[debug]   --noprofile
##[debug]   --norc
##[debug]   /myagent/_work/_temp/229ea54f-8b84-413a-915a-5c29dab2b0fc.sh
/usr/bin/bash --noprofile --norc /myagent/_work/_temp/229ea54f-8b84-413a-915a-5c29dab2b0fc.sh
 git init
Reinitialized existing Git repository in /myagent/_work/2/s/.git/
 git sparse-checkout: TESRT-Infra/common/rgname/
 git remote add ssh://git@ssh.dev.azure.com/v3/***/***/***
Host key verification failed.
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

请问可能缺少哪些配置?


可能的缺失配置及解决办法

根据报错Host key verification failed,结合自托管代理与Azure托管代理的环境差异,核心问题集中在SSH验证、权限及环境配置上,可能缺失以下配置:

  • Azure DevOps SSH主机密钥未正确配置
    Azure托管代理预先内置了ssh.dev.azure.com的主机密钥,自托管代理需要手动配置。尽管Pipeline中用InstallSSHKey@0指定了knownHostsEntry,需确认$(known_host)变量的值是否为ssh.dev.azure.com的正确主机密钥。可在自托管代理服务器执行ssh-keyscan ssh.dev.azure.com获取密钥,再赋值给该变量。

  • SSH密钥权限不符合要求
    Git/SSH对密钥文件权限要求严格,需确保:

    • 私钥文件权限为600(仅所有者可读可写)
    • .ssh目录权限为700
      虽然InstallSSHKey@0会尝试设置权限,但如果自托管代理环境有特殊权限限制,可能需要手动在服务器上调整。
  • Git用户信息未配置
    Azure托管代理默认配置了Git的用户名和邮箱,自托管代理可能缺失该配置,导致Git操作失败。可在Pipeline的CmdLine任务中添加:

    git config --global user.name "你的用户名"
    git config --global user.email "你的邮箱@xxx.com"
    
  • 稀疏检出后的分支检出步骤缺失
    当前脚本在git fetch后直接执行git pull,但未检出目标分支,可能导致拉取失败。调整脚本顺序:

    git fetch --progress --verbose --depth=1 origin main
    git checkout main
    
  • 代理服务器网络访问限制
    确认自托管代理服务器能正常访问ssh.dev.azure.com的22端口,企业防火墙可能阻止SSH连接。可在代理服务器执行telnet ssh.dev.azure.com 22测试连通性。

内容的提问来源于stack exchange,提问作者user3541321

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 12:55:41