You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Tekton git-clone忽略SSH配置问题求助

问题描述

按照Tekton官方克隆Git仓库的教程,尝试通过SSH克隆仓库时失败,使用HTTPS方式则可正常运行。日志显示已将包含SSH文件的Secret复制到/home/git/.ssh目录并设置了正确权限,但后续仍报错提示缺少SSH配置,最终出现Permission denied (publickey)错误。

相关配置文件

pipeline.yaml

apiVersion: tekton.dev/v1beta1
kind: Pipeline
metadata:
  name: clone-read
spec:
  description: | 
    This pipeline clones a git repo, then echoes the README file to the stout.
  params:
  - name: repo-url
    type: string
    description: The git repo URL to clone from.
  workspaces:
  - name: shared-data
    description: | 
      This workspace contains the cloned repo files, so they can be read by the
      next task.
  - name: git-credentials
    description: My ssh credentials
  tasks:
  - name: fetch-source
    taskRef:
      name: git-clone
    workspaces:
    - name: output
      workspace: shared-data
    - name: ssh-directory
      workspace: git-credentials
    params:
    - name: url
      value: $(params.repo-url)
    - name: verbose
      value: true
  - name: show-readme
    runAfter: ["fetch-source"]
    taskRef:
      name: show-readme
    workspaces:
    - name: source
      workspace: shared-data

pipelinerun.yaml

apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
  generateName: clone-read-run-
spec:
  pipelineRef:
    name: clone-read
  podTemplate:
    securityContext:
      fsGroup: 65532
  workspaces:
  - name: shared-data
    volumeClaimTemplate:
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 1Gi
  - name: git-credentials
    secret:
      secretName: git-credentials
  params:
  - name: repo-url
    value: git@github.com:tektoncd/website.git

secret.yaml

apiVersion: v1
kind: Secret
metadata:
  name: git-credentials
data:
  id_rsa: LS0tLS...
  id_rsa.pub: c3NoLXJ...
  known_hosts: Z2l0aH...

日志输出

$ tkn pipelinerun logs clone-read-run-72zlj -f
[fetch-source : clone] + '[' false '=' true ]
[fetch-source : clone] + '[' true '=' true ]
[fetch-source : clone] + cp -R /workspace/ssh-directory /home/git/.ssh
[fetch-source : clone] + chmod 700 /home/git/.ssh
[fetch-source : clone] + chmod -R 400 /home/git/.ssh/id_rsa /home/git/.ssh/id_rsa.pub /home/git/.ssh/known_hosts
[fetch-source : clone] + '[' false '=' true ]
[fetch-source : clone] + CHECKOUT_DIR=/workspace/output/
[fetch-source : clone] + '[' true '=' true ]
[fetch-source : clone] + cleandir
[fetch-source : clone] + '[' -d /workspace/output/ ]
[fetch-source : clone] + rm -rf '/workspace/output//*'
[fetch-source : clone] + rm -rf '/workspace/output//.[!.]*'
[fetch-source : clone] + rm -rf '/workspace/output//..?*'
[fetch-source : clone] + test -z
[fetch-source : clone] + test -z
[fetch-source : clone] + test -z
[fetch-source : clone] + git config --global --add safe.directory /workspace/output
[fetch-source : clone] + /ko-app/git-init '-url=git@github.com:tektoncd/website.git' '-revision=' '-refspec=' '-path=/workspace/output/' '-sslVerify=true' '-submodules=true' '-depth=1' '-sparseCheckoutDirectories='
[fetch-source : clone] {"level":"warn","ts":1671382236.5119827,"caller":"git/git.go:271","msg":"URL(\"git@github.com:tektoncd/website.git\") appears to need SSH authentication but no SSH credentials have been provided"}
[fetch-source : clone] {"level":"error","ts":1671382237.3406594,"caller":"git/git.go:53","msg":"Error running git [fetch --recurse-submodules=yes --depth=1 origin --update-head-ok --force ]: exit status 128\ngit@github.com: Permission denied (publickey).\r\nfatal: Could not read from remote repository.\n\nPlease make sure you have the correct access rights\nand the repository exists.\n","stacktrace":"github.com/tektoncd/pipeline/pkg/git.run\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:53\ngithub.com/tektoncd/pipeline/pkg/git.Fetch\n\tgithub.com/tektoncd/pipeline/pkg/git/git.go:156\nmain.main\n\tgithub.com/tektoncd/pipeline/cmd/git-init/main.go:53\nruntime.main\n\truntime/proc.go:250"}
[fetch-source : clone] {"level":"fatal","ts":1671382237.340791,"caller":"git-init/main.go:54","msg":"Error fetching git repository: failed to fetch []: exit status 128","stacktrace":"main.main\n\tgithub.com/tektoncd/pipeline/cmd/git-init/main.go:54\nruntime.main\n\truntime/proc.go:250"}

解决思路

  • 修正Secret的类型:在secret.yaml中添加type: kubernetes.io/ssh-auth,明确这是SSH认证类型的Secret,确保Tekton的git-clone任务能正确识别并加载凭证:

    apiVersion: v1
    kind: Secret
    metadata:
      name: git-credentials
    type: kubernetes.io/ssh-auth
    data:
      id_rsa: LS0tLS...
      id_rsa.pub: c3NoLXJ...
      known_hosts: Z2l0aH...
    
  • 验证私钥的完整性:对Secret中的id_rsa字段进行base64解码,确认是完整的PEM格式私钥,包含完整的-----BEGIN RSA PRIVATE KEY-----和-----END RSA PRIVATE KEY-----头尾部,且换行符未丢失。解码命令:

    echo "LS0tLS..." | base64 -d
    
  • 确认known_hosts的正确性:生成GitHub的主机密钥并替换现有内容,确保SSH连接时能正确验证主机身份:

    # 生成github.com的主机密钥
    ssh-keyscan github.com > known_hosts
    # 编码为base64
    cat known_hosts | base64 -w 0
    

    将输出替换secret.yaml中的known_hosts字段值。

  • 检查公钥权限:将id_rsa.pub解码后的内容添加到目标GitHub仓库的「Deploy keys」(需开启读取权限)或对应GitHub账号的「SSH keys」中,确保该公钥拥有仓库的读取权限。

  • 手动测试SSH连接:创建临时Pod挂载该Secret,手动测试SSH认证是否正常:

    kubectl run -it --rm test-ssh --image=alpine/git --overrides='{"spec":{"volumes":[{"name":"ssh-secret","secret":{"secretName":"git-credentials"}}],"containers":[{"name":"test","image":"alpine/git","command":["sh"],"volumeMounts":[{"name":"ssh-secret","mountPath":"/root/.ssh"}]}]}}'
    # 在Pod内执行
    chmod 700 /root/.ssh && chmod 400 /root/.ssh/*
    ssh git@github.com
    

    如果连接成功,说明凭证正常,问题出在Tekton任务的配置或环境;如果失败,排查凭证本身的问题。

内容的提问来源于stack exchange,提问作者BetaRide

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 11:35:23