Terraform拉取模块失败:Host key验证失败及Azure DevOps密钥配置咨询
解决Azure DevOps代理SSH密钥缺失导致Terraform模块拉取失败的方案
问题场景
尝试通过Terraform拉取Azure DevOps上的模块时出现以下错误:
Terraform模块配置
module "rsgr-05" { source = "git@ssh.dev.azure.com:v5/xxxx-devops/DevOps/terraform-azure?ref=firstversion" rsgr_loc = var.location infr-env = var.infr-env audit = var.audit seq_number = "002" }
错误信息
Could not download module "rsgr-05" (main.tf:12) source code from "git::ssh://git@ssh.dev.azure.com/v5/xxxx-devops/DevOps/terraform-azure?ref=firstversion": error downloading 'ssh://git@ssh.dev.azure.com/v5/xxxx-devops/DevOps/terraform-azure?ref=firstversion': /usr/bin/git exited with 128: Cloning into '.terraform/modules/rsgr-05'... Host key verification failed. fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
确认问题源于Azure DevOps代理缺少SSH密钥,可通过以下命令行流程生成并上传密钥:
步骤1:在代理机器生成SSH密钥对
打开代理机器的终端,执行密钥生成命令:
ssh-keygen -t ed25519 -C "azure-devops-agent@your-domain.com"- 按回车使用默认密钥存储路径(
~/.ssh/id_ed25519) - 如需无密码登录(适合代理服务场景),直接回车跳过密码设置;若需密码,输入后确认
- 按回车使用默认密钥存储路径(
查看并复制公钥内容:
cat ~/.ssh/id_ed25519.pub复制输出的全部文本内容。
步骤2:将公钥上传至Azure DevOps
- 登录你的Azure DevOps组织,点击右上角头像 → 个人资料 → SSH公钥
- 点击添加按钮,粘贴刚才复制的公钥内容,填写描述(如“Terraform代理专用密钥”),最后保存。
步骤3:验证代理机器的SSH连接
在代理机器终端执行以下命令,验证连接是否正常:
ssh -T git@ssh.dev.azure.com
若返回类似remote: Shell access is not supported.的提示,说明SSH连接已成功建立。
额外注意事项
- 如果代理以特定服务账户运行,需确保密钥生成在该账户的
~/.ssh目录下,而非当前登录用户目录 - 调整密钥目录及文件权限,避免权限错误:
chmod 700 ~/.ssh chmod 600 ~/.ssh/id_ed25519 chmod 644 ~/.ssh/id_ed25519.pub
内容的提问来源于stack exchange,提问作者cekodis681 cekodis681
相关产品推荐
相关产品推荐

