Jenkins流水线克隆Git代码失败:主机密钥验证错误求助
解决Jenkins流水线克隆GitLab代码时的ECDSA主机密钥验证失败问题
问题原因
Jenkins节点通过SSH克隆GitLab仓库时,gitlab.com的ECDSA主机密钥未被添加到节点的known_hosts文件中,且Git启用了严格主机密钥检查模式,导致连接被直接拒绝。
解决方案
方法1:手动添加GitLab主机密钥到Jenkins节点(推荐生产环境)
- 登录Jenkins运行的节点服务器,切换到Jenkins服务使用的系统用户(通常为
jenkins):sudo su - jenkins - 执行命令获取
gitlab.com的ECDSA主机密钥并追加到known_hosts文件:ssh-keyscan -t ecdsa gitlab.com >> ~/.ssh/known_hosts - 验证配置有效性:
出现ssh gitlab.comWelcome to GitLab, @xxx!或类似提示即说明密钥添加成功。
方法2:在流水线中配置主机密钥验证策略(临时测试场景可用)
如果是临时测试需求,可以通过流水线代码指定主机密钥或临时关闭严格检查:
- 指定已知密钥:
在Groovy流水线中添加主机密钥配置:git( url: 'git@gitlab.com:your-username/your-repo.git', credentialsId: 'your-ssh-credential-id', userRemoteConfigs: [[ url: 'git@gitlab.com:your-username/your-repo.git', credentialsId: 'your-ssh-credential-id', hostKeyVerificationStrategy: [ $class: 'ManuallyProvidedKeyVerificationStrategy', hostKey: 'ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=' ] ]] ) - 临时关闭严格检查(生产环境不推荐):
在Git步骤中配置无验证策略:git( url: 'git@gitlab.com:your-username/your-repo.git', credentialsId: 'your-ssh-credential-id', userRemoteConfigs: [[ url: 'git@gitlab.com:your-username/your-repo.git', credentialsId: 'your-ssh-credential-id', hostKeyVerificationStrategy: [$class: 'NonVerifyingKeyVerificationStrategy'] ]] )
方法3:通过Jenkins凭据管理主机密钥
- 安装Jenkins的SSH Credentials Plugin插件;
- 进入Jenkins「凭据」页面,选择「全局凭据」→「添加凭据」;
- 类型选择「SSH Host Key」,填写:
- 范围:全局
- 主机名:
gitlab.com - 密钥:填入
ssh-keyscan -t ecdsa gitlab.com输出的密钥内容;
- 在流水线的Git配置中,选择该主机密钥凭据即可自动完成验证。
内容的提问来源于stack exchange,提问作者B. Naga Lakshmi
相关产品推荐
相关产品推荐

