Tekton git-clone忽略SSH配置问题求助
问题描述
按照Tekton官方克隆Git仓库的教程,尝试通过SSH克隆仓库时失败,使用HTTPS方式则可正常运行。日志显示已将包含SSH文件的Secret复制到/home/git/.ssh目录并设置了正确权限,但后续仍报错提示缺少SSH配置,最终出现Permission denied (publickey)错误。
相关配置文件
pipeline.yaml
apiVersion: tekton.dev/v1beta1 kind: Pipeline metadata: name: clone-read spec: description: | This pipeline clones a git repo, then echoes the README file to the stout. params: - name: repo-url type: string description: The git repo URL to clone from. workspaces: - name: shared-data description: | This workspace contains the cloned repo files, so they can be read by the next task. - name: git-credentials description: My ssh credentials tasks: - name: fetch-source taskRef: name: git-clone workspaces: - name: output workspace: shared-data - name: ssh-directory workspace: git-credentials params: - name: url value: $(params.repo-url) - name: verbose value: true - name: show-readme runAfter: ["fetch-source"] taskRef: name: show-readme workspaces: - name: source workspace: shared-data
pipelinerun.yaml
apiVersion: tekton.dev/v1beta1 kind: PipelineRun metadata: generateName: clone-read-run- spec: pipelineRef: name: clone-read podTemplate: securityContext: fsGroup: 65532 workspaces: - name: shared-data volumeClaimTemplate: spec: accessModes: - ReadWriteOnce resources: requests: storage: 1Gi - name: git-credentials secret: secretName: git-credentials params: - name: repo-url value: git@github.com:tektoncd/website.git
secret.yaml
apiVersion: v1 kind: Secret metadata: name: git-credentials data: id_rsa: LS0tLS... id_rsa.pub: c3NoLXJ... known_hosts: Z2l0aH...
日志输出
$ tkn pipelinerun logs clone-read-run-72zlj -f [fetch-source : clone] + '[' false '=' true ] [fetch-source : clone] + '[' true '=' true ] [fetch-source : clone] + cp -R /workspace/ssh-directory /home/git/.ssh [fetch-source : clone] + chmod 700 /home/git/.ssh [fetch-source : clone] + chmod -R 400 /home/git/.ssh/id_rsa /home/git/.ssh/id_rsa.pub /home/git/.ssh/known_hosts [fetch-source : clone] + '[' false '=' true ] [fetch-source : clone] + CHECKOUT_DIR=/workspace/output/ [fetch-source : clone] + '[' true '=' true ] [fetch-source : clone] + cleandir [fetch-source : clone] + '[' -d /workspace/output/ ] [fetch-source : clone] + rm -rf '/workspace/output//*' [fetch-source : clone] + rm -rf '/workspace/output//.[!.]*' [fetch-source : clone] + rm -rf '/workspace/output//..?*' [fetch-source : clone] + test -z [fetch-source : clone] + test -z [fetch-source : clone] + test -z [fetch-source : clone] + git config --global --add safe.directory /workspace/output [fetch-source : clone] + /ko-app/git-init '-url=git@github.com:tektoncd/website.git' '-revision=' '-refspec=' '-path=/workspace/output/' '-sslVerify=true' '-submodules=true' '-depth=1' '-sparseCheckoutDirectories=' [fetch-source : clone] {"level":"warn","ts":1671382236.5119827,"caller":"git/git.go:271","msg":"URL(\"git@github.com:tektoncd/website.git\") appears to need SSH authentication but no SSH credentials have been provided"} [fetch-source : clone] {"level":"error","ts":1671382237.3406594,"caller":"git/git.go:53","msg":"Error running git [fetch --recurse-submodules=yes --depth=1 origin --update-head-ok --force ]: exit status 128\ngit@github.com: Permission denied (publickey).\r\nfatal: Could not read from remote repository.\n\nPlease make sure you have the correct access rights\nand the repository exists.\n","stacktrace":"github.com/tektoncd/pipeline/pkg/git.run\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:53\ngithub.com/tektoncd/pipeline/pkg/git.Fetch\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:156\nmain.main\n\tgithub.com/tektoncd/pipeline/cmd/git-init/main.go:53\nruntime.main\n\truntime/proc.go:250"} [fetch-source : clone] {"level":"fatal","ts":1671382237.340791,"caller":"git-init/main.go:54","msg":"Error fetching git repository: failed to fetch []: exit status 128","stacktrace":"main.main\n\tgithub.com/tektoncd/pipeline/cmd/git-init/main.go:54\nruntime.main\n\truntime/proc.go:250"}
解决思路
修正Secret的类型:在
secret.yaml中添加type: kubernetes.io/ssh-auth,明确这是SSH认证类型的Secret,确保Tekton的git-clone任务能正确识别并加载凭证:apiVersion: v1 kind: Secret metadata: name: git-credentials type: kubernetes.io/ssh-auth data: id_rsa: LS0tLS... id_rsa.pub: c3NoLXJ... known_hosts: Z2l0aH...验证私钥的完整性:对Secret中的
id_rsa字段进行base64解码,确认是完整的PEM格式私钥,包含完整的-----BEGIN RSA PRIVATE KEY-----和-----END RSA PRIVATE KEY-----头尾部,且换行符未丢失。解码命令:echo "LS0tLS..." | base64 -d确认known_hosts的正确性:生成GitHub的主机密钥并替换现有内容,确保SSH连接时能正确验证主机身份:
# 生成github.com的主机密钥 ssh-keyscan github.com > known_hosts # 编码为base64 cat known_hosts | base64 -w 0将输出替换
secret.yaml中的known_hosts字段值。检查公钥权限:将
id_rsa.pub解码后的内容添加到目标GitHub仓库的「Deploy keys」(需开启读取权限)或对应GitHub账号的「SSH keys」中,确保该公钥拥有仓库的读取权限。手动测试SSH连接:创建临时Pod挂载该Secret,手动测试SSH认证是否正常:
kubectl run -it --rm test-ssh --image=alpine/git --overrides='{"spec":{"volumes":[{"name":"ssh-secret","secret":{"secretName":"git-credentials"}}],"containers":[{"name":"test","image":"alpine/git","command":["sh"],"volumeMounts":[{"name":"ssh-secret","mountPath":"/root/.ssh"}]}]}}' # 在Pod内执行 chmod 700 /root/.ssh && chmod 400 /root/.ssh/* ssh git@github.com如果连接成功,说明凭证正常,问题出在Tekton任务的配置或环境;如果失败,排查凭证本身的问题。
内容的提问来源于stack exchange,提问作者BetaRide

