使用Tekton git-clone任务克隆Bitbucket私有仓库遇SSH认证失败
解决Tekton git-clone任务SSH认证失败问题
问题描述
使用Tekton Hub提供的git-clone任务克隆Bitbucket私有仓库时,反复遇到no SSH credentials have been provided警告,最终触发git@bitbucket.org: Permission denied (publickey)权限拒绝错误。已在fetebird-tekton命名空间创建SSH密钥Secret、Pipeline及PipelineRun资源,但认证始终失败。
已配置资源
Kubernetes Secret(git-ssh-key-secret)
apiVersion: v1 kind: Secret metadata: name: git-ssh-key-secret namespace: fetebird-tekton annotations: tekton.dev/git-0: bitbucket.org type: kubernetes.io/ssh-auth stringData: ssh-privatekey: | -----BEGIN OPENSSH PRIVATE KEY----- ......... -----END OPENSSH PRIVATE KEY----- known_hosts: | bitbucket.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIazEu89wgQZ4bqs3d63QSMzYVa0MuJ2e2gKTKqu+UUO bitbucket.org ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPIQmuzMBuKdWeF4+a2sjSSpBK0iqitSQ+5BM9KhpexuGt20JpTVM7u5BDZngncgrqDMbWdxMWWOGtZ9UgbqgZE= bitbucket.org ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQeJzhupRu0u0cdegZIa8e86EG2qOCsIsD1Xw0xSeiPDlCr7kq97NLmMbpKTX6Esc30NuoqEEHCuc7yWtwp8dI76EEEB1VqY9QJq6vk+aySyboD5QF61I/1WeTwu+deCbgKMGbUijeXhtfbxSxm6JwGrXrhBdofTsbKRUsrN1WoNgUa8uqN1Vx6WAJw1JHPhglEGGHea6QICwJOAr/6mrui/oB7pkaWKHj3z7d1IC4KWLtY47elvjbaTlkN04Kc/5LFEirorGYVbt15kAUlqGM65pk6ZBxtaO3+30LVlORZkxOh+LKL/BvbZ/iRNhItLqNyieoQj/uh/7Iv4uyH/cV/0b4WDSd3DptigWq84lJubb9t/DnZlrJazxyDCulTmKdOR7vs9gMTo+uoIrPSb8ScTtvw65+odKAlBj59dhnVp9zd7QUojOpXlL62Aw56U4oO+FALuevvMjiWeavKhJqlR7i5n9srYcrNV7ttmDw7kf/97P5zauIhxcjX+xHv4M=
Pipeline(ft-common)
apiVersion: tekton.dev/v1beta1 kind: Pipeline metadata: name: ft-common namespace: fetebird-tekton spec: params: - name: repo-url type: string description: The git repository URL to clone from. workspaces: - name: shared-data description: | cloned git repo. - name: git-credentials description: | This workspace contains SSH key. tasks: - name: fetch-repo taskRef: name: git-clone workspaces: - name: output workspace: shared-data - name: ssh-directory workspace: git-credentials params: - name: url value: "$(params.repo-url)"
PipelineRun(ft-common-run)
apiVersion: tekton.dev/v1beta1 kind: PipelineRun metadata: name: ft-common-run namespace: fetebird-tekton spec: pipelineRef: name: ft-common podTemplate: securityContext: fsGroup: 65532 workspaces: - name: shared-data volumeClaimTemplate: spec: accessModes: - ReadWriteOnce resources: requests: storage: 1Gi - name: git-credentials secret: secretName: git-ssh-key-secret params: - name: repo-url value: git@bitbucket.org:anandjaisy/common.git
错误日志
2023-07-22T04:22:38.350474002Z + '[' false '=' true ] 2023-07-22T04:22:38.350605085Z + '[' true '=' true ] 2023-07-22T04:22:38.350614877Z + cp -R /workspace/ssh-directory /home/git/.ssh 2023-07-22T04:22:38.353488627Z + chmod 700 /home/git/.ssh 2023-07-22T04:22:38.355256585Z + chmod -R 400 /home/git/.ssh/known_hosts /home/git/.ssh/ssh-privatekey 2023-07-22T04:22:38.357084710Z + '[' false '=' true ] 2023-07-22T04:22:38.357117169Z + CHECKOUT_DIR=/workspace/output/ 2023-07-22T04:22:38.357124877Z + '[' true '=' true ] 2023-07-22T04:22:38.357130419Z + cleandir 2023-07-22T04:22:38.357135127Z + '[' -d /workspace/output/ ] 2023-07-22T04:22:38.357589919Z + rm -rf '/workspace/output//*' 2023-07-22T04:22:38.359449752Z + rm -rf /workspace/output//.git 2023-07-22T04:22:38.362385919Z + rm -rf '/workspace/output//..?*' 2023-07-22T04:22:38.363630044Z + test -z 2023-07-22T04:22:38.363649377Z + test -z 2023-07-22T04:22:38.363655377Z + test -z 2023-07-22T04:22:38.363702419Z + git config --global --add safe.directory /workspace/output 2023-07-22T04:22:38.369294044Z + /ko-app/git-init '-url=git@bitbucket.org:anandjaisy/common.git' '-revision=' '-refspec=' '-path=/workspace/output/' '-sslVerify=true' '-submodules=true' '-depth=1' '-sparseCheckoutDirectories=' 2023-07-22T04:22:38.383720460Z {"level":"warn","ts":1689999758.383478,"caller":"git/git.go:271","msg":"URL(\"git@bitbucket.org:anandjaisy/common.git\") appears to need SSH authentication but no SSH credentials have been provided"} 2023-07-22T04:22:39.859510128Z {"level":"error","ts":1689999759.8580627,"caller":"git/git.go:53","msg":"Error running git [fetch --recurse-submodules=yes --depth=1 origin --update-head-ok --force ]: exit status 128\ngit@bitbucket.org: Permission denied (publickey).\r\nfatal: Could not read from remote repository.\n\nPlease make sure you have the correct access rights\nand the repository exists.\n","stacktrace":"github.com/tektoncd/pipeline/pkg/git.run\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:53\ngithub.com/tektoncd/pipeline/pkg/git.Fetch\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:156\nmain.main\n\tgithub.com/tektoncd/pipeline/cmd/git-init/main.go:53\nruntime.main\n\truntime/proc.go:250"}
解决步骤
1. 验证SSH密钥有效性
- 本地测试密钥能否访问Bitbucket:
ssh -i /path/to/your-private-key git@bitbucket.org - 确认该密钥对应的公钥已添加到Bitbucket仓库的Access keys列表中(仓库设置→Access keys)。
2. 修正Secret挂载逻辑
git-clone任务的ssh-directory workspace要求Secret中的密钥文件直接位于挂载目录下,而非嵌套结构。检查Secret的type: kubernetes.io/ssh-auth是否正确,确保ssh-privatekey和known_hosts内容格式无错误(无多余空格、换行符正确)。
3. 改用ssh-key参数传递密钥(推荐)
放弃ssh-directory workspace,直接通过参数传递SSH密钥,避免挂载问题:
- 修改Pipeline的
fetch-repo任务:tasks: - name: fetch-repo taskRef: name: git-clone workspaces: - name: output workspace: shared-data params: - name: url value: "$(params.repo-url)" - name: ssh-key value: $(secrets.git-ssh-key-secret.ssh-privatekey) - 更新PipelineRun,添加Secret引用:
spec: ... secrets: - name: git-ssh-key-secret secretName: git-ssh-key-secret
4. 检查Pod权限配置
- 确认
fsGroup: 65532设置正确,Tekton默认使用该用户组运行任务,确保Secret文件能被该组读取。 - 若仍有问题,可手动指定Secret的
defaultMode:apiVersion: v1 kind: Secret metadata: name: git-ssh-key-secret namespace: fetebird-tekton annotations: tekton.dev/git-0: bitbucket.org type: kubernetes.io/ssh-auth stringData: # ... 原有内容 data: {} defaultMode: 0600
5. 更新git-clone任务版本
旧版本git-clone可能存在SSH认证bug,安装最新版本:
tkn hub task install git-clone -n fetebird-tekton
6. 添加SSH配置文件(可选)
在Secret中添加config文件,强制指定Bitbucket的密钥使用规则:
stringData: # ... 原有ssh-privatekey和known_hosts内容 config: | Host bitbucket.org IdentityFile ~/.ssh/ssh-privatekey IdentitiesOnly yes
内容的提问来源于stack exchange,提问作者San Jaisy
相关产品推荐
相关产品推荐

