You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Linux主机PGP密钥生成失败,求解决(目标为Function App)

Solution for GPG Key Generation Failures in Azure Linux Web SSH/Kudu Console

Let's break down why you're hitting those agent errors and fix them step by step. The core issue here is that Azure's non-interactive console environments (Web SSH and Kudu Bash) don't have a proper TTY for GPG's pinentry tool to run, and the gpg-agent doesn't start automatically in these contexts. Here's how to get key generation working:

Step 1: Fix Directory Permissions

GPG enforces strict permissions on its home directory to keep keys secure. First, make sure your target directory has the right access controls:

mkdir -p "$homeDir"
chmod 700 "$homeDir"

This ensures only your user can read/write to the directory, which GPG requires to proceed.

Step 2: Update Your PGP Params File

Your pgp-params.txt needs to explicitly use loopback pinentry mode—since there's no interactive prompt available in these console environments. Add this line to your parameters file:

Pinentry-Mode: loopback

Here's a complete example of a valid params file:

%echo Generating a new GPG key
Key-Type: RSA
Key-Length: 2048
Subkey-Type: RSA
Subkey-Length: 2048
Name-Real: Your Full Name
Name-Email: your.email@example.com
Expire-Date: 0  # Sets key to never expire (adjust if needed)
Passphrase: your-secure-passphrase-here
Pinentry-Mode: loopback
%commit
%echo Key generation complete

Step 3: Manually Start and Configure the GPG Agent

In non-interactive sessions, gpg-agent won't launch automatically. Run these commands before generating the key to set up the agent properly:

# Start the agent with loopback pinentry allowed
gpg-agent --homedir="$homeDir" --daemon --allow-loopback-pinentry

# Export the agent socket path so GPG can connect to it
export GPG_AGENT_INFO=$(gpgconf --homedir="$homeDir" --list-dirs agent-socket):0:1

Step 4: Run the Key Generation Command

Now execute the key generation command as before—this time it should connect to the agent successfully:

gpg --homedir="$homeDir" --batch --gen-key pgp-params.txt

Notes for Azure Function App

When you move this workflow to an Azure Function App, keep these critical points in mind:

  • Persistent Storage: Use a mounted Azure Files share for $homeDir instead of the function's temporary directory. Temporary storage gets cleared when the function scales or restarts, so your keys would be lost.
  • Script Wrapping: Package the agent startup, environment variable setup, and key generation into a single shell script that your function executes.
  • Permissions: Ensure the function's managed identity has write access to the storage directory you're using.

After following these steps, you should see the full set of GPG key files (including the private key in private-keys-v1.d) generated successfully in your target directory.

内容的提问来源于stack exchange,提问作者Donny Kwitty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 18:15:36