You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub更新后Actions触发server_deploy.sh部署失败求助

问题描述

我们的开发服务器部署了server_deploy.sh脚本,协作者创建PR时会自动触发该脚本将对应分支部署到开发服务器(每个分支有专属访问URL)。2023年3月23日GitHub更新RSA SSH主机密钥前,该流程运行正常。

更新后出现以下问题:

  1. 首次报错因Git克隆失败,导致脚本找不到storage和bootstrap/cache目录:
======CMD======
sudo /home/***/.server_deploy.sh $PUSHED_BRANCH_NAME
======END======
out: Deploying application ..... branch = lg-30rvkhp
out: Now using node v12.16.3 (npm v6.14.4)
err: chmod: cannot access 'storage': No such file or directory
err: chmod: cannot access 'bootstrap/cache': No such file or directory
2023/03/27 07:45:20 Process exited with status 1
  1. 修复服务器known_hosts后,手动执行脚本正常,但GitHub Actions触发仍失败,报错为API仓库克隆时主机密钥验证失败:
======CMD======
sudo /home/***/.server_deploy.sh $PUSHED_BRANCH_NAME
======END======
out: Deploying application ..... branch = lg-85zruc0ph
out: Cloning API Repo...
err: Cloning into 'api'...
err: Host key verification failed.
err: fatal: Could not read from remote repository.
err: Please make sure you have the correct access rights
err: and the repository exists.
2023/04/04 06:41:41 Process exited with status 128

我们已按GitHub官方更新说明操作,也尝试了社区方案,但仅手动执行有效,Actions触发始终失败。

排查方向与解决方案

1. 确认脚本执行用户的known_hosts配置

手动执行脚本用的是当前用户,但Actions触发时用sudo切换到了其他用户(如root或专属服务用户),该用户的~/.ssh/known_hosts未添加更新后的GitHub RSA主机密钥:

  • 切换到脚本执行用户,执行命令添加密钥:
    sudo -u <脚本执行用户> ssh-keyscan github.com >> /home/<脚本执行用户>/.ssh/known_hosts
    
  • 或者在server_deploy.sh开头添加逻辑,自动检查并添加密钥(避免重复写入):
    if ! grep -q "github.com" ~/.ssh/known_hosts; then
        ssh-keyscan github.com >> ~/.ssh/known_hosts
        chmod 600 ~/.ssh/known_hosts
    fi
    

2. 检查SSH密钥的权限与归属

Actions触发时,sudo切换用户后可能无法访问手动执行用户的SSH密钥:

  • 确认部署用的SSH密钥(如id_rsa)权限为600,所属用户为脚本执行用户
  • 若使用仓库部署密钥,确保密钥已添加到GitHub仓库的部署密钥列表,且执行用户拥有密钥读取权限

3. 避免不必要的sudo

如果sudo不是部署必须的,直接去掉sudo执行脚本,使用Actions触发的用户环境(该环境的known_hosts可能已正确配置)。若必须用sudo,添加-E参数保留当前用户环境变量:

sudo -E /home/***/.server_deploy.sh $PUSHED_BRANCH_NAME

4. 验证脚本执行用户的SSH连接

手动切换到脚本执行用户,尝试克隆API仓库,确认连接正常:

sudo -u <脚本执行用户> git clone git@github.com:<你的API仓库路径>.git

若失败,直接在该用户环境下修复known_hosts和SSH密钥问题,直到手动克隆成功,再通过Actions触发测试

内容的提问来源于stack exchange,提问作者Bhat Andleeb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 03:47:33