Docker通过sshfs挂载远程卷失败求助:连接被对等方重置
Let's work through fixing that Connection reset by peer error you're hitting with the vieux/sshfs Docker plugin. I've tackled similar remote volume issues before, so here are the step-by-step checks and fixes to get your setup working:
The Docker plugin runs as the Docker daemon user (usually root), so you need to confirm this user can SSH into VM1 using your key without any prompts. On VM2:
- Switch to the Docker daemon user (if you're not already logged in as root):
su - root - Test the SSH connection directly:
ssh -i /home/csicari/data/Mega/lavoro/keys/vm-csicari.key debian@vm1
If this fails, your plugin will never work. Common issues here:
- Incorrect key permissions: SSH requires private keys to have
600permissions, and theauthorized_keysfile on VM1 (in/home/debian/.ssh/) must also be600, with the.sshdirectory set to700. Fix with:# On VM2, for your private key chmod 600 /home/csicari/data/Mega/lavoro/keys/vm-csicari.key # On VM1, for the authorized_keys file chmod 700 /home/debian/.ssh chmod 600 /home/debian/.ssh/authorized_keys - VM1 SSH restrictions: Check
/etc/ssh/sshd_configon VM1 to ensure:PasswordAuthenticationisn't blocking key auth (it's okay if it'sno, just make sure your key is inauthorized_keys)AllowUsersorAllowGroupsisn't excluding thedebianuser- Port 22 is open in VM1's firewall/security group
- SFTP is enabled: SSHFS relies on SFTP. Confirm
Subsystem sftp /usr/lib/openssh/sftp-serveris uncommented in/etc/ssh/sshd_configon VM1, then restart SSH:systemctl restart sshd
The path you specified for IdentityFile is in the csicari user's home directory, which the Docker daemon (running as root) might not have permission to access. Here's how to fix this:
- Copy the key to a location root can access, like
/root/.ssh/:cp /home/csicari/data/Mega/lavoro/keys/vm-csicari.key /root/.ssh/ chmod 600 /root/.ssh/vm-csicari.key - Delete the existing problematic volume and recreate it with the new key path:
docker volume rm remotevolume docker volume create --name remotevolume -d vieux/sshfs \ -o sshcmd=debian@vm1:/home/debian/sshfs300 \ -o IdentityFile=/root/.ssh/vm-csicari.key \ -o allow_other \ -o nonempty
Double-check that the directory you're trying to mount exists and has the right permissions on VM1:
# On VM1 ls -ld /home/debian/sshfs300
Ensure the debian user has read/write access to this directory (the output should show rwx for the user). If not, fix permissions with:
chmod u+rwx /home/debian/sshfs300
Since you installed the plugin with DEBUG=1, you can get detailed logs to pinpoint the exact issue:
# On VM2 docker logs vieux/sshfs
This will show the full sshfs command the plugin is running, along with any error messages that might not show up in the Docker run error. Look for clues like "Permission denied" or "No such file or directory" for the key or target directory.
To rule out Docker-specific issues, try mounting the remote directory directly on VM2 using sshfs:
mkdir -p /tmp/testmount sshfs debian@vm1:/home/debian/sshfs300 /tmp/testmount \ -o IdentityFile=/home/csicari/data/Mega/lavoro/keys/vm-csicari.key \ -o allow_other \ -o nonempty
If this works, the problem is definitely with the Docker plugin's configuration or permissions. If it fails, the error message will guide you to the root cause (e.g., network, key, or directory issues).
Once you've worked through these steps, try starting your container again with:
docker run -it -v remotevolume:/home -d ubuntu
内容的提问来源于stack exchange,提问作者Christian

