You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器需先SSH连接才能访问GitHub HTTPS的问题求助

问题:Docker容器中直接访问GitHub HTTPS超时,仅执行SSH连接后恢复

在运行CentOS 7或Ubuntu的Docker容器中,直接执行curl https://github.com -v -m 5会出现连接超时:

$ curl https://github.com -v -m 5
* About to connect() to github.com port 443 (#0)
*   Trying 20.248.137.48...
* Connected to github.com (20.248.137.48) port 443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
*   CAfile: /etc/pki/tls/certs/ca-bundle.crt
  CApath: none
* Operation timed out after 5001 milliseconds with 0 out of 0 bytes received
* Closing connection 0
curl: (28) Operation timed out after 5001 milliseconds with 0 out of 0 bytes received

但执行ssh github.com(即使返回Permission denied (publickey).)后,再次执行curl就能正常建立HTTPS连接:

$ curl https://github.com -v -m 5
* About to connect() to github.com port 443 (#0)
*   Trying 20.248.137.48...
* Connected to github.com (20.248.137.48) port 443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
*   CAfile: /etc/pki/tls/certs/ca-bundle.crt
  CApath: none
* SSL connection using TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
* Server certificate:
*       subject: CN=github.com,O="GitHub, Inc.",L=San Francisco,ST=California,C=US
*       start date: Feb 14 00:00:00 2023 GMT
*       expire date: Mar 14 23:59:59 2024 GMT
*       common name: github.com
*       issuer: CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1,O=DigiCert Inc,C=US
> GET / HTTP/1.1
> User-Agent: curl/7.29.0
> Host: github.com
> Accept: */*
>
< HTTP/1.1 200 OK

尝试用ssh-keyscan添加SSH密钥指纹无效果,known_hosts文件也不影响HTTPS连接,需要找到无需先执行SSH就能正常访问GitHub HTTPS的方法。


解决方案

1. 更换GitHub的解析IP

这种超时通常是当前解析到的GitHub IP存在网络路径问题,可手动绑定可用IP:

  • 编辑容器内/etc/hosts,添加一条映射(示例IP为GitHub常用可用IP,可根据实际网络调整):
    echo "140.82.113.4 github.com" >> /etc/hosts
    
  • 或者直接用curl指定IP并携带Host头访问:
    curl https://140.82.113.4 -H "Host: github.com" -v -m 5
    

2. 预热TCP连接(替代SSH操作)

用nc工具尝试建立到GitHub 22端口的TCP连接,无需完成SSH认证,仅打通网络路径即可:

nc -zv github.com 22 -w 2

执行后再运行curl,即可正常访问HTTPS服务。

3. 排查容器网络配置

  • 若使用自定义Docker网络,检查是否有防火墙/iptables规则限制了443端口的初始出站连接
  • 临时切换容器网络为host模式测试(生产环境不推荐):
    docker run --network host -it centos:7 /bin/bash
    
    若切换后问题消失,说明原容器网络的NAT或转发规则存在异常。

内容的提问来源于stack exchange,提问作者Subbeh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 21:37:25