Azure DevOps自托管代理Git拉取失败,托管代理运行正常
此前使用Azure托管Ubuntu代理池运行Pipeline一直正常,现在在Ubuntu服务器配置了自托管代理后,Pipeline在Git拉取步骤失败。
Pipeline配置
trigger: batch: true branches: include: - main paths: include: - rg-test-cmn-syd-01-bastion #pool: #vmImage: ubuntu-latest pool: name: self-hosted demands: - agent.name -equals devops-agent-01 variables: environmentName: 'dev' resource_group: '******' workDirectory: 'myworkdir' gitRepository: 'ssh://git@ssh.dev.azure.com/v3/myorg/myproject' backendType: 'azurerm' backendServiceArm: '***' backendAzureRmSubscriptionId: '*******' backendAzureRmResourceGroupName: '******' backendAzureRmStorageAccountName: '*****' backendAzureRmContainerName: '*****' backendAzureRmKey: '$(resource_group).tfstate' environmentServiceName: '*****' stages : - stage: terraform_plan jobs: - job: terraform_plan displayName: "Terraform Plan" steps: - checkout: none - task: InstallSSHKey@0 inputs: knownHostsEntry: $(known_host) sshPublicKey: '******' sshKeySecureFile: 'testkey' - task: CmdLine@2 displayName: 'Git pull $(workDirectory)' inputs: script: | echo [command] git init git init echo [command] git sparse-checkout: $(workDirectory) git config core.sparsecheckout true echo $(workDirectory) >> .git/info/sparse-checkout echo [command] git remote add $(gitRepository) git remote add origin $(gitRepository) echo ##[command] git fetch --progress --verbose --depth=1 origin main git fetch --progress --verbose --depth=1 origin main ##echo ##[command] git pull --progress --verbose origin main git pull --progress --verbose origin main
报错信息
##git pull --progress --verbose origin main ##[debug]workingDirectory=/myagent/_work/2/s ##[debug]check path : /myagent/_work/2/s Generating script. ##[debug]Agent.Version=3.220.5 ##[debug]agent.tempDirectory=/myagent/_work/_temp ##[debug]check path : /myagent/_work/_temp ========================== Starting Command Output =========================== ##[debug]which 'bash' ##[debug]found: '/usr/bin/bash' ##[debug]which '/usr/bin/bash' ##[debug]found: '/usr/bin/bash' ##[debug]/usr/bin/bash arg: --noprofile ##[debug]/usr/bin/bash arg: --norc ##[debug]/usr/bin/bash arg: /myagent/_work/_temp/229ea54f-8b84-413a-915a-5c29dab2b0fc.sh ##[debug]exec tool: /usr/bin/bash ##[debug]arguments: ##[debug] --noprofile ##[debug] --norc ##[debug] /myagent/_work/_temp/229ea54f-8b84-413a-915a-5c29dab2b0fc.sh /usr/bin/bash --noprofile --norc /myagent/_work/_temp/229ea54f-8b84-413a-915a-5c29dab2b0fc.sh git init Reinitialized existing Git repository in /myagent/_work/2/s/.git/ git sparse-checkout: TESRT-Infra/common/rgname/ git remote add ssh://git@ssh.dev.azure.com/v3/***/***/*** Host key verification failed. fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
请问可能缺少哪些配置?
根据报错Host key verification failed,结合自托管代理与Azure托管代理的环境差异,核心问题集中在SSH验证、权限及环境配置上,可能缺失以下配置:
Azure DevOps SSH主机密钥未正确配置
Azure托管代理预先内置了ssh.dev.azure.com的主机密钥,自托管代理需要手动配置。尽管Pipeline中用InstallSSHKey@0指定了knownHostsEntry,需确认$(known_host)变量的值是否为ssh.dev.azure.com的正确主机密钥。可在自托管代理服务器执行ssh-keyscan ssh.dev.azure.com获取密钥,再赋值给该变量。SSH密钥权限不符合要求
Git/SSH对密钥文件权限要求严格,需确保:- 私钥文件权限为
600(仅所有者可读可写) .ssh目录权限为700
虽然InstallSSHKey@0会尝试设置权限,但如果自托管代理环境有特殊权限限制,可能需要手动在服务器上调整。
- 私钥文件权限为
Git用户信息未配置
Azure托管代理默认配置了Git的用户名和邮箱,自托管代理可能缺失该配置,导致Git操作失败。可在Pipeline的CmdLine任务中添加:git config --global user.name "你的用户名" git config --global user.email "你的邮箱@xxx.com"稀疏检出后的分支检出步骤缺失
当前脚本在git fetch后直接执行git pull,但未检出目标分支,可能导致拉取失败。调整脚本顺序:git fetch --progress --verbose --depth=1 origin main git checkout main代理服务器网络访问限制
确认自托管代理服务器能正常访问ssh.dev.azure.com的22端口,企业防火墙可能阻止SSH连接。可在代理服务器执行telnet ssh.dev.azure.com 22测试连通性。
内容的提问来源于stack exchange,提问作者user3541321

