You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Tekton git-clone任务克隆Bitbucket私有仓库遇SSH认证失败

解决Tekton git-clone任务SSH认证失败问题

问题描述

使用Tekton Hub提供的git-clone任务克隆Bitbucket私有仓库时,反复遇到no SSH credentials have been provided警告,最终触发git@bitbucket.org: Permission denied (publickey)权限拒绝错误。已在fetebird-tekton命名空间创建SSH密钥Secret、Pipeline及PipelineRun资源,但认证始终失败。

已配置资源

Kubernetes Secret(git-ssh-key-secret)

apiVersion: v1
kind: Secret
metadata:
  name: git-ssh-key-secret
  namespace: fetebird-tekton
  annotations:
    tekton.dev/git-0: bitbucket.org
type: kubernetes.io/ssh-auth
stringData:
  ssh-privatekey: |
      -----BEGIN OPENSSH PRIVATE KEY-----
      .........
      -----END OPENSSH PRIVATE KEY-----
  known_hosts: |
          bitbucket.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIazEu89wgQZ4bqs3d63QSMzYVa0MuJ2e2gKTKqu+UUO
          bitbucket.org ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPIQmuzMBuKdWeF4+a2sjSSpBK0iqitSQ+5BM9KhpexuGt20JpTVM7u5BDZngncgrqDMbWdxMWWOGtZ9UgbqgZE=
          bitbucket.org ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQeJzhupRu0u0cdegZIa8e86EG2qOCsIsD1Xw0xSeiPDlCr7kq97NLmMbpKTX6Esc30NuoqEEHCuc7yWtwp8dI76EEEB1VqY9QJq6vk+aySyboD5QF61I/1WeTwu+deCbgKMGbUijeXhtfbxSxm6JwGrXrhBdofTsbKRUsrN1WoNgUa8uqN1Vx6WAJw1JHPhglEGGHea6QICwJOAr/6mrui/oB7pkaWKHj3z7d1IC4KWLtY47elvjbaTlkN04Kc/5LFEirorGYVbt15kAUlqGM65pk6ZBxtaO3+30LVlORZkxOh+LKL/BvbZ/iRNhItLqNyieoQj/uh/7Iv4uyH/cV/0b4WDSd3DptigWq84lJubb9t/DnZlrJazxyDCulTmKdOR7vs9gMTo+uoIrPSb8ScTtvw65+odKAlBj59dhnVp9zd7QUojOpXlL62Aw56U4oO+FALuevvMjiWeavKhJqlR7i5n9srYcrNV7ttmDw7kf/97P5zauIhxcjX+xHv4M=

Pipeline(ft-common)

apiVersion: tekton.dev/v1beta1
kind: Pipeline
metadata:
  name: ft-common
  namespace: fetebird-tekton
spec:
  params:
    - name: repo-url
      type: string
      description: The git repository URL to clone from.
  workspaces:
    - name: shared-data
      description: |
        cloned git repo.
    - name: git-credentials
      description: |
        This workspace contains SSH key.

  tasks:
    - name: fetch-repo
      taskRef:
        name: git-clone
      workspaces:
        - name: output
          workspace: shared-data
        - name: ssh-directory
          workspace: git-credentials
      params:
        - name: url
          value: "$(params.repo-url)"

PipelineRun(ft-common-run)

apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
  name: ft-common-run
  namespace: fetebird-tekton
spec:
  pipelineRef:
    name: ft-common
  podTemplate:
    securityContext:
      fsGroup: 65532
  workspaces:
    - name: shared-data
      volumeClaimTemplate:
        spec:
          accessModes:
            - ReadWriteOnce
          resources:
            requests:
              storage: 1Gi
    - name: git-credentials
      secret:
        secretName: git-ssh-key-secret
  params:
    - name: repo-url
      value: git@bitbucket.org:anandjaisy/common.git

错误日志

2023-07-22T04:22:38.350474002Z + '[' false '=' true ]
2023-07-22T04:22:38.350605085Z + '[' true '=' true ]
2023-07-22T04:22:38.350614877Z + cp -R /workspace/ssh-directory /home/git/.ssh
2023-07-22T04:22:38.353488627Z + chmod 700 /home/git/.ssh
2023-07-22T04:22:38.355256585Z + chmod -R 400 /home/git/.ssh/known_hosts /home/git/.ssh/ssh-privatekey
2023-07-22T04:22:38.357084710Z + '[' false '=' true ]
2023-07-22T04:22:38.357117169Z + CHECKOUT_DIR=/workspace/output/
2023-07-22T04:22:38.357124877Z + '[' true '=' true ]
2023-07-22T04:22:38.357130419Z + cleandir
2023-07-22T04:22:38.357135127Z + '[' -d /workspace/output/ ]
2023-07-22T04:22:38.357589919Z + rm -rf '/workspace/output//*'
2023-07-22T04:22:38.359449752Z + rm -rf /workspace/output//.git
2023-07-22T04:22:38.362385919Z + rm -rf '/workspace/output//..?*'
2023-07-22T04:22:38.363630044Z + test -z 
2023-07-22T04:22:38.363649377Z + test -z 
2023-07-22T04:22:38.363655377Z + test -z 
2023-07-22T04:22:38.363702419Z + git config --global --add safe.directory /workspace/output
2023-07-22T04:22:38.369294044Z + /ko-app/git-init '-url=git@bitbucket.org:anandjaisy/common.git' '-revision=' '-refspec=' '-path=/workspace/output/' '-sslVerify=true' '-submodules=true' '-depth=1' '-sparseCheckoutDirectories='
2023-07-22T04:22:38.383720460Z {"level":"warn","ts":1689999758.383478,"caller":"git/git.go:271","msg":"URL(\"git@bitbucket.org:anandjaisy/common.git\") appears to need SSH authentication but no SSH credentials have been provided"}
2023-07-22T04:22:39.859510128Z {"level":"error","ts":1689999759.8580627,"caller":"git/git.go:53","msg":"Error running git [fetch --recurse-submodules=yes --depth=1 origin --update-head-ok --force ]: exit status 128\ngit@bitbucket.org: Permission denied (publickey).\r\nfatal: Could not read from remote repository.\n\nPlease make sure you have the correct access rights\nand the repository exists.\n","stacktrace":"github.com/tektoncd/pipeline/pkg/git.run\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:53\ngithub.com/tektoncd/pipeline/pkg/git.Fetch\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:156\nmain.main\n\tgithub.com/tektoncd/pipeline/cmd/git-init/main.go:53\nruntime.main\n\truntime/proc.go:250"}

解决步骤

1. 验证SSH密钥有效性

  • 本地测试密钥能否访问Bitbucket:
    ssh -i /path/to/your-private-key git@bitbucket.org
    
  • 确认该密钥对应的公钥已添加到Bitbucket仓库的Access keys列表中(仓库设置→Access keys)。

2. 修正Secret挂载逻辑

git-clone任务的ssh-directory workspace要求Secret中的密钥文件直接位于挂载目录下,而非嵌套结构。检查Secret的type: kubernetes.io/ssh-auth是否正确,确保ssh-privatekey和known_hosts内容格式无错误(无多余空格、换行符正确)。

3. 改用ssh-key参数传递密钥(推荐)

放弃ssh-directory workspace,直接通过参数传递SSH密钥,避免挂载问题:

  • 修改Pipeline的fetch-repo任务:
    tasks:
      - name: fetch-repo
        taskRef:
          name: git-clone
        workspaces:
          - name: output
            workspace: shared-data
        params:
          - name: url
            value: "$(params.repo-url)"
          - name: ssh-key
            value: $(secrets.git-ssh-key-secret.ssh-privatekey)
    
  • 更新PipelineRun,添加Secret引用:
    spec:
      ...
      secrets:
        - name: git-ssh-key-secret
          secretName: git-ssh-key-secret
    

4. 检查Pod权限配置

  • 确认fsGroup: 65532设置正确,Tekton默认使用该用户组运行任务,确保Secret文件能被该组读取。
  • 若仍有问题,可手动指定Secret的defaultMode:
    apiVersion: v1
    kind: Secret
    metadata:
      name: git-ssh-key-secret
      namespace: fetebird-tekton
      annotations:
        tekton.dev/git-0: bitbucket.org
    type: kubernetes.io/ssh-auth
    stringData:
      # ... 原有内容
    data: {}
    defaultMode: 0600
    

5. 更新git-clone任务版本

旧版本git-clone可能存在SSH认证bug,安装最新版本:

tkn hub task install git-clone -n fetebird-tekton

6. 添加SSH配置文件(可选)

在Secret中添加config文件,强制指定Bitbucket的密钥使用规则:

stringData:
  # ... 原有ssh-privatekey和known_hosts内容
  config: |
      Host bitbucket.org
        IdentityFile ~/.ssh/ssh-privatekey
        IdentitiesOnly yes

内容的提问来源于stack exchange,提问作者San Jaisy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 19:50:53