You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过SSH拉取内部仓库时go mod tidy执行失败求助

问题:GitHub Actions中执行go mod tidy访问私有仓库失败(SSH认证已通过)

问题现象

在使用GitHub内部私有仓库时,单独测试SSH认证显示成功,但执行go mod tidy访问内部仓库时,抛出权限拒绝错误。

错误信息

git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.
Please make sure you have the correct access rights and the repository exists.

GitHub Action配置

steps:
    # Checks-out the repository under $GITHUB_WORKSPACE, so the job can access it
    - uses: actions/checkout@v3

    # Set up Go
    - name: Set up Go
      uses: actions/setup-go@v4
      with:
          go-version: 1.20.2
          cache: false

    - name: Add private key to SSH agent
      env:
        PRIVATE_KEY: ${{ secrets.SHARED_DEPLOY_PRIVATE_KEY }}
      run: |
        echo "${{ env.PRIVATE_KEY }}" > key.pem
        chmod 600 key.pem
        eval "$(ssh-agent -s)"
        ssh-add key.pem
        ssh-add -l -E sha256
        ssh -T git@github.com 2>&1 || true    ### tests ssh auth

    # Install dependencies
    - name: Install dependencies
      run: |
          git config --global url."git@github.com:".insteadOf "https://github.com/"
          go clean -modcache  
          go env -w GOPRIVATE=github.com/my-org/*
          go env -w GONOPROXY=github.com/my-org/*
          go env
          go mod tidy

各步骤日志

「Add private key」步骤日志

Agent pid 1766
Identity added: key.pem (_REDACTED_)
3072 SHA256:_REDACTED_ _REDACTED_ (RSA)
Hi my-org/observability-go! You've successfully authenticated, but GitHub does not provide shell access.

「Install dependencies」步骤日志

go: downloading github.com/pmezard/go-difflib v1.0.0
go: downloading github.com/mattn/go-isatty v0.0.17
go: downloading golang.org/x/sync v0.1.0
github.com/my-org/clan-service/cmd/clanservice imports
    github.com/my-org/observability-go/logging: github.com/my-org/observability-go@v0.0.0-20230623103942-2be438a81907: invalid version: git ls-remote -q origin in /home/runner/go/pkg/mod/cache/vcs/d0c7f50097d6054d27fc7949420737cdb6036d1246584bb05f13c6fe75577be2: exit status 128:
    git@github.com: Permission denied (publickey).
    fatal: Could not read from remote repository.
    Please make sure you have the correct access rights
    and the repository exists.

go env输出

GO111MODULE=""
GOARCH="amd64"
GOBIN=""
GOCACHE="/home/runner/.cache/go-build"
GOENV="/home/runner/.config/go/env"
GOEXE=""
GOEXPERIMENT=""
GOFLAGS=""
GOHOSTARCH="amd64"
GOHOSTOS="linux"
GOINSECURE=""
GOMODCACHE="/home/runner/go/pkg/mod"
GONOPROXY="github.com/my-org/*"
GONOSUMDB="github.com/my-org/*"
GOOS="linux"
GOPATH="/home/runner/go"
GOPRIVATE="github.com/my-org/*"
GOPROXY="https://proxy.golang.org,direct"
GOROOT="/opt/hostedtoolcache/go/1.20.2/x64"
GOSUMDB="sum.golang.org"
GOTMPDIR=""
GOTOOLDIR="/opt/hostedtoolcache/go/1.20.2/x64/pkg/tool/linux_amd64"
GOVCS=""
GOVERSION="go1.20.2"
GCCGO="gccgo"
GOAMD64="v1"
AR="ar"
CC="gcc"
CXX="g++"
CGO_ENABLED="1"
GOMOD="/home/runner/work/clan-service/clan-service/go.mod"
GOWORK=""
CGO_CFLAGS="-O2 -g"
CGO_CPPFLAGS=""
CGO_CXXFLAGS="-O2 -g"
CGO_FFLAGS="-O2 -g"
CGO_LDFLAGS="-O2 -g"
PKG_CONFIG="pkg-config"
GOGCCFLAGS="-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -fdebug-prefix-map=/tmp/go-build4021260014=/tmp/go-build -gno-record-gcc-switches"

解决方案

核心问题

GitHub Actions的每个步骤是独立的shell进程,手动启动的SSH Agent仅在当前步骤生效,后续步骤无法继承其环境变量,导致go mod tidy无法复用已认证的SSH连接。

修复步骤

  1. 使用专业SSH Agent Action
    替换手动启动SSH Agent的步骤,使用webfactory/ssh-agent action,它会自动在所有后续步骤中保留SSH Agent的环境变量:

    - name: Set up SSH agent
      uses: webfactory/ssh-agent@v0.7.0
      with:
        ssh-private-key: ${{ secrets.SHARED_DEPLOY_PRIVATE_KEY }}
    
  2. 确保Git配置生效
    保持git config --global url."git@github.com:".insteadOf "https://github.com/"配置,确保Go模块拉取时使用SSH而非HTTPS协议。

  3. 补充完整私有仓库配置(可选)
    确保私有仓库的校验和不被公共sumdb检查,已在go env中配置GONOSUMDB可忽略此步,未配置则添加:

    go env -w GONOSUMDB=github.com/my-org/*
    

完整修复后的配置示例

steps:
    - uses: actions/checkout@v3

    - name: Set up Go
      uses: actions/setup-go@v4
      with:
          go-version: 1.20.2
          cache: false

    - name: Set up SSH agent
      uses: webfactory/ssh-agent@v0.7.0
      with:
        ssh-private-key: ${{ secrets.SHARED_DEPLOY_PRIVATE_KEY }}

    - name: Install dependencies
      run: |
          git config --global url."git@github.com:".insteadOf "https://github.com/"
          go clean -modcache  
          go env -w GOPRIVATE=github.com/my-org/*
          go env -w GONOPROXY=github.com/my-org/*
          go env -w GONOSUMDB=github.com/my-org/*
          ssh -T git@github.com 2>&1 || true
          go mod tidy

额外排查点

  • 确认私有密钥对应的GitHub账号拥有目标私有仓库的读取权限
  • 检查密钥是否设置密码(部署密钥通常不设密码,若有需额外处理)
  • 确认GOPRIVATE的匹配规则覆盖所有需要访问的私有仓库路径

内容的提问来源于stack exchange,提问作者gingerbreadboy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 11:58:09