Docker/流水线因Ubuntu源404失败,无法安装openssh-client
解决Bitbucket流水线ssh命令缺失&apt源404问题
问题根源
你使用的php:7.3.18-apache镜像基于Debian 10(Buster),而Debian 10的官方源已从stable转为oldstable归档状态,原默认源地址失效,导致apt-get update返回404,无法正常安装openssh-client。
修复步骤
1. 替换Debian 10的apt源为归档源
在执行apt-get update前,先替换系统源列表:
# 备份原源文件 cp /etc/apt/sources.list /etc/apt/sources.list.bak # 写入oldstable归档源地址 echo "deb http://archive.debian.org/debian buster main contrib non-free" > /etc/apt/sources.list echo "deb http://archive.debian.org/debian-security buster/updates main contrib non-free" >> /etc/apt/sources.list # 忽略过期签名验证(归档源的GPG签名已失效) apt-get update --allow-insecure-repositories
2. 重新安装openssh-client
源替换完成后执行安装命令:
apt-get install -y openssh-client
3. 整合到Bitbucket流水线配置
修改bitbucket-pipelines.yml中的对应步骤,将源替换逻辑提前:
pipelines: default: - step: name: 初始化环境 image: php:7.3.18-apache script: - # 替换Debian 10归档源 - cp /etc/apt/sources.list /etc/apt/sources.list.bak - echo "deb http://archive.debian.org/debian buster main contrib non-free" > /etc/apt/sources.list - echo "deb http://archive.debian.org/debian-security buster/updates main contrib non-free" >> /etc/apt/sources.list - apt-get update --allow-insecure-repositories - apt-get install -y openssh-client - # 后续流水线业务命令
4. 可选:预构建自定义镜像(优化流水线速度)
如果不想每次流水线都执行源替换操作,可以构建包含openssh-client的自定义镜像:
Dockerfile内容:
FROM php:7.3.18-apache RUN cp /etc/apt/sources.list /etc/apt/sources.list.bak && \ echo "deb http://archive.debian.org/debian buster main contrib non-free" > /etc/apt/sources.list && \ echo "deb http://archive.debian.org/debian-security buster/updates main contrib non-free" >> /etc/apt/sources.list && \ apt-get update --allow-insecure-repositories && \ apt-get install -y openssh-client && \ rm -rf /var/lib/apt/lists/*
构建完成后推送到容器仓库(如Docker Hub或Bitbucket容器库),后续流水线直接使用该自定义镜像即可。
注意事项
--allow-insecure-repositories参数不可省略,否则会因归档源签名过期导致update失败。- 该方案无需大幅升级PHP版本,完全兼容现有业务环境。
内容的提问来源于stack exchange,提问作者Gammer
相关产品推荐
相关产品推荐

