You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置SSH自动建立隧道访问私有GitLab服务器问题求助

解决GitLab通过Jumpbox自动建立SSH隧道的问题

问题诊断

从错误日志和你的配置来看,有几个关键问题导致连接失败:

  • IdentityFile配置错误:你指定的是.pub公钥文件,但SSH认证需要使用私钥文件(公钥是放在远程服务器authorized_keys中的,本地无需指定公钥路径)。
  • 配置冗余冲突:同时使用ProxyJump和LocalForward,且LocalForward的目标IP(10.90.209.68)与手动操作时的GitLab内部IP(172.12.0.15)不一致,造成转发目标混乱。
  • Hosts映射冲突:之前手动操作时修改/etc/hosts把gitlab.example.com指向127.0.0.1,会干扰ProxyJump直接解析GitLab内部IP的逻辑。

修正后的SSH配置

先删除/etc/hosts中gitlab.example.com的映射条目,再修改~/.ssh/config如下:

Host jumpbox
    HostName jumpbox.example.com
    Port 22000
    User myUser
    PasswordAuthentication yes
    IdentityAgent "~/example/ssh/agent.sock"
    IdentityFile ~/.ssh/jumpbox  # 改为私钥文件,移除.pub后缀
    IdentitiesOnly yes

Host gitlab.example.com
    HostName 172.12.0.15  # GitLab服务器内部IP
    Port 22
    User git
    IdentityAgent "~/example/ssh/agent.sock"
    IdentityFile ~/.ssh/gitlab_git_via_ssh  # 改为私钥文件,移除.pub后缀
    IdentitiesOnly yes
    ProxyJump jumpbox  # 仅保留ProxyJump,自动通过jumpbox转发连接

验证与后续操作

  1. 测试连接:
ssh -v gitlab.example.com

成功时会显示GitLab的欢迎信息(如Welcome to GitLab, @your_username!)。
2. 权限修正:确保私钥文件权限为600,否则SSH会拒绝使用:

chmod 600 ~/.ssh/jumpbox ~/.ssh/gitlab_git_via_ssh
  1. 此时直接执行git push/git pull即可,无需手动建立隧道。

补充说明

  • ProxyJump是OpenSSH 7.3+支持的特性,会自动在后台通过jumpbox建立转发通道,替代手动ssh -L操作,无需维护本地端口转发和hosts映射。
  • 确保jumpbox服务器能正常访问GitLab的内部IP(172.12.0.15:22),这是ProxyJump生效的前提(你手动操作时已验证此连通性)。

内容的提问来源于stack exchange,提问作者clowa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 13:08:09