使用SSH密码或PEM密钥远程执行脚本遇错,求解决方案
无交互远程执行URL脚本:密码/PEM密钥方案
一、密码凭据方式
核心问题
- 未使用
*sudo -S*:sudo默认要求终端输入密码,*-S*参数允许从标准输入读取密码 - 进程替换
bash <(...)需要伪终端支持,缺少*-t*参数会导致/dev/fd/63错误
正确命令
ssh -t user@host.com 'echo "你的密码" | sudo -S bash <(wget -qO- http://host.com/do.sh)'
*-t*:强制分配伪终端,适配sudo和进程替换的环境要求- 单引号包裹远程命令,确保所有字符在远程主机上正确解析
若仍出现进程替换错误,可改用先下载再执行的方式:
ssh -t user@host.com 'echo "你的密码" | sudo -S sh -c "wget -qO /tmp/do.sh http://host.com/do.sh && bash /tmp/do.sh && rm -f /tmp/do.sh"'
二、PEM密钥方式
核心问题
- 密钥路径中的
~在双引号中无法展开,导致ssh找不到密钥文件 *-T*参数关闭伪终端,导致进程替换无法正常工作- 若远程用户未配置免密sudo,sudo仍会要求输入密码
正确命令
推荐:配置免密sudo后执行
先在远程主机上用*visudo*编辑/etc/sudoers,添加:
ubuntu ALL=(ALL) NOPASSWD: ALL
然后执行:
ssh -i ~/.ssh/keys/key.pem ubuntu@host 'sudo bash <(wget -qO- http://host.com/do.sh)'
- 密钥路径不要用双引号包裹,让本地shell自动展开
~ - 无需
*-T*,保持伪终端默认分配
需输入sudo密码的场景(不推荐)
ssh -t -i ~/.ssh/keys/key.pem ubuntu@host 'echo "你的sudo密码" | sudo -S bash <(wget -qO- http://host.com/do.sh)'
关键注意事项
- 生产环境禁止明文传递密码,优先采用密钥登录+免密sudo的组合
- 本地PEM密钥权限必须设为
*600*:chmod 600 ~/.ssh/keys/key.pem,否则ssh会拒绝使用 - 先单独验证ssh登录:
ssh -i ~/.ssh/keys/key.pem ubuntu@host,确保连接正常
内容的提问来源于stack exchange,提问作者TheMan68
相关产品推荐
相关产品推荐

