Jenkins无法通过SSH拉取GitHub代码的问题求助
问题:Jenkins Freestyle项目SSH拉取GitHub代码超时失败
构建时的错误日志:
Started by user Amith Sai Running as SYSTEM Building remotely on JenkinsAgent (gradle docker) in workspace /var/lib/jenkins/workspace/SSH POC PROJECT The recommended git tool is: NONE using credential SSHGITHUB Cloning the remote Git repository Cloning repository git@github.com:MRROBOT-124/POC-PROJECT.git > git init /var/lib/jenkins/workspace/SSH POC PROJECT # timeout=10 Fetching upstream changes from git@github.com:MRROBOT-124/POC-PROJECT.git > git --version # timeout=10 > git --version # 'git version 2.39.2' using GIT_SSH to set credentials GITHUB SSH KEYS Verifying host key using known hosts file, will automatically accept unseen keys > git fetch --tags --force --progress -- git@github.com:MRROBOT-124/POC-PROJECT.git +refs/heads/*:refs/remotes/origin/* # timeout=10 ERROR: Error cloning remote repo 'origin' hudson.plugins.git.GitException: Command "git fetch --tags --force --progress -- git@github.com:MRROBOT-124/POC-PROJECT.git +refs/heads/*:refs/remotes/origin/*" returned status code 128: stdout: stderr: ssh: connect to host github.com port 22: Connection timed out fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandIn(CliGitAPIImpl.java:2732) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl.launchCommandWithCredentials(CliGitAPIImpl.java:2109) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$1.execute(CliGitAPIImpl.java:623) at org.jenkinsci.plugins.gitclient.CliGitAPIImpl$2.execute(CliGitAPIImpl.java:850) at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler$GitCommandMasterToSlaveCallable.call(RemoteGitImpl.java:158) at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler$GitCommandMasterToSlaveCallable.call(RemoteGitImpl.java:151) at hudson.remoting.UserRequest.perform(UserRequest.java:211) at hudson.remoting.UserRequest.perform(UserRequest.java:54) at hudson.remoting.Request$2.run(Request.java:377) at hudson.remoting.InterceptingExecutorService.lambda$wrap$0(InterceptingExecutorService.java:78) at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264) at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136) at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635) at java.base/java.lang.Thread.run(Thread.java:833) Suppressed: hudson.remoting.Channel$CallSiteStackTrace: Remote call to JenkinsAgent at hudson.remoting.Channel.attachCallSiteStackTrace(Channel.java:1784) at hudson.remoting.UserRequest$ExceptionResponse.retrieve(UserRequest.java:356) at hudson.remoting.Channel.call(Channel.java:1000) at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler.execute(RemoteGitImpl.java:143) at jdk.internal.reflect.GeneratedMethodAccessor805.invoke(Unknown Source) at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.base/java.lang.reflect.Method.invoke(Method.java:568) at org.jenkinsci.plugins.gitclient.RemoteGitImpl$CommandInvocationHandler.invoke(RemoteGitImpl.java:129) at jdk.proxy66/jdk.proxy66.$Proxy161.execute(Unknown Source) at hudson.plugins.git.GitSCM.retrieveChanges(GitSCM.java:1226) at hudson.plugins.git.GitSCM.checkout(GitSCM.java:1309) at hudson.scm.SCM.checkout(SCM.java:540) at hudson.model.AbstractProject.checkout(AbstractProject.java:1240) at hudson.model.AbstractBuild$AbstractBuildExecution.defaultCheckout(AbstractBuild.java:649) at jenkins.scm.SCMCheckoutStrategy.checkout(SCMCheckoutStrategy.java:85) at hudson.model.AbstractBuild$AbstractBuildExecution.run(AbstractBuild.java:521) at hudson.model.Run.execute(Run.java:1900) at hudson.model.FreeStyleBuild.run(FreeStyleBuild.java:44) at hudson.model.ResourceController.execute(ResourceController.java:101) at hudson.model.Executor.run(Executor.java:442) ERROR: Error cloning remote repo 'origin' Finished: FAILURE
已完成的配置
- 切换至jenkins用户,生成带密码的ed25519 SSH密钥:
sudo su jenkins ssh-keygen -t ed25519 -C "myemail.com" - 将公钥添加至GitHub的Settings -> SSH and GPG keys中
- 将私钥配置到Jenkins的Manage Jenkins -> Manage Credentials中
- 尝试修改Git Host Key Verification Configuration为
Accept first connection和No Verification,均无效
注:使用用户名密码方式拉取代码可正常工作,但SSH方式始终报错
解决方法
1. 检查Jenkins代理节点的网络连通性
登录到远程代理节点(JenkinsAgent),执行命令测试GitHub SSH端口连通性:
telnet github.com 22 # 或使用nc命令 nc -zv github.com 22
如果超时,说明代理节点的防火墙/安全组禁止了22端口出站,需联系运维开放端口,或改用GitHub的SSH替代端口443。
2. 改用GitHub SSH的443端口
将Jenkins项目配置中的仓库URL修改为:
git@ssh.github.com:443/MRROBOT-124/POC-PROJECT.git
手动测试连接可执行:
sudo su jenkins ssh -T -p 443 git@ssh.github.com
3. 验证Jenkins用户的SSH密钥有效性
登录代理节点切换到jenkins用户,测试SSH连接GitHub:
sudo su jenkins ssh -T git@github.com
若提示权限问题,检查:
- 公钥是否正确添加到GitHub对应账户
- jenkins用户的私钥路径
~/.ssh/id_ed25519是否存在,权限需设置为600:chmod 600 ~/.ssh/id_ed25519 chmod 700 ~/.ssh - 若密钥设置了密码,需确保Jenkins凭据中正确填写了密钥密码,或生成无密码密钥测试。
4. 检查Jenkins Git插件配置
确保项目中选择的凭据类型为SSH Username with private key,用户名填写git,并正确关联配置好的私钥凭据。
内容的提问来源于stack exchange,提问作者Amith
相关产品推荐
相关产品推荐

