如何使用Docker BuildKit为非root用户提供SSH密钥?
非root用户使用BuildKit的
RUN --mount=type=ssh权限问题 我在以非root用户身份使用BuildKit的RUN --mount=type=ssh时遇到权限问题。
使用以下命令执行构建:
eval $(ssh-agent) ssh-add ~/.ssh/id_ed25519 DOCKER_BUILDKIT=1 docker build --ssh default=${SSH_AUTH_SOCK} .
对应的Dockerfile内容:
FROM docker.io/apache/airflow USER root RUN apt update && apt install -y git openssh-client # 取消注释此行会导致失败 #USER airflow RUN mkdir -m 700 ~/.ssh RUN ssh-keyscan github.com > ~/.ssh/known_hosts RUN --mount=type=ssh ssh -vvvT git@github.com
正常运行情况
当不切换到airflow用户时,配置可以正常运行,输出内容如下:
> [5/5] RUN --mount=type=ssh ssh -vvvT git@github.com: ... #8 0.931 debug1: Will attempt key: matt@ChoedanKal ED25519 SHA256:2IGNbnSt122LtFaH5Z6u5eQf9B+aG0khsfNUxOKfHJU agent #8 0.931 debug1: Will attempt key: /root/.ssh/id_rsa #8 0.931 debug1: Will attempt key: /root/.ssh/id_dsa #8 0.931 debug1: Will attempt key: /root/.ssh/id_ecdsa #8 0.931 debug1: Will attempt key: /root/.ssh/id_ecdsa_sk #8 0.931 debug1: Will attempt key: /root/.ssh/id_ed25519 #8 0.931 debug1: Will attempt key: /root/.ssh/id_ed25519_sk #8 0.931 debug1: Will attempt key: /root/.ssh/id_xmss #8 0.917 debug2: pubkey_prepare: done #8 0.917 debug3: send packet: type 5 #8 0.961 debug3: receive packet: type 7 ... #8 1.056 debug1: Offering public key: matt@ChoedanKal ED25519 SHA256:2IGNbnSt122LtFaH5Z6u5eQf9B+aG0khsfNUxOKfHJU agent #8 1.056 debug3: send packet: type 50 #8 1.056 debug2: we sent a publickey packet, wait for reply #8 1.111 debug3: receive packet: type 60 #8 1.111 debug1: Server accepts key: matt@ChoedanKal ED25519 SHA256:2IGNbnSt122LtFaH5Z6u5eQf9B+aG0khsfNUxOKfHJU agent #8 1.111 debug3: sign_and_send_pubkey: ED25519 SHA256:2IGNbnSt122LtFaH5Z6u5eQf9B+aG0khsfNUxOKfHJU #8 1.111 debug3: sign_and_send_pubkey: signing using ssh-ed25519 SHA256:2IGNbnSt122LtFaH5Z6u5eQf9B+aG0khsfNUxOKfHJU #8 1.122 debug3: send packet: type 50 #8 1.176 debug3: receive packet: type 52 #8 1.176 debug1: Authentication succeeded (publickey). #8 1.176 Authenticated to github.com ([140.82.113.3]:22). ... #8 1.271 Hi MatrixManAtYrService! You've successfully authenticated, but GitHub does not provide shell access.
切换非root用户后的失败情况
如果取消USER airflow行的注释,配置就会失败,输出内容如下:
> [5/5] RUN --mount=type=ssh ssh -vvvT git@github.com: ... #8 0.941 debug1: pubkey_prepare: ssh_get_authentication_socket: Permission denied #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_rsa #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_dsa #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_ecdsa #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_ecdsa_sk #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_ed25519 #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_ed25519_sk #8 0.941 debug1: Will attempt key: /home/airflow/.ssh/id_xmss #8 0.941 debug2: pubkey_prepare: done #8 0.941 debug3: send packet: type 5 #8 0.991 debug3: receive packet: type 7 #8 0.991 debug1: SSH2_MSG_EXT_INFO received #8 0.991 debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256,ssh-rsa> #8 1.042 debug3: receive packet: type 6 #8 1.042 debug2: service_accept: ssh-userauth #8 1.042 debug1: SSH2_MSG_SERVICE_ACCEPT received #8 1.042 debug3: send packet: type 50 #8 1.092 debug3: receive packet: type 51 #8 1.092 debug1: Authentications that can continue: publickey #8 1.092 debug3: start over, passed a different list publickey ... #8 1.092 git@github.com: Permission denied (publickey).
核心错误信息
问题的核心是这条权限拒绝错误:
ssh_get_authentication_socket: Permission denied
需求与临时方案
我需要用以下命令通过SSH密钥安装私有GitHub仓库的Python包:
pip install git+ssh://git@github.com/someuser/somerepo.git
但不建议以root身份执行pip。目前我有一个临时解决方法:以root身份创建虚拟环境、安装包,再用chown -R将虚拟环境的归属改为airflow用户,想了解是否有更直接的解决方案。
内容的提问来源于stack exchange,提问作者MatrixManAtYrService
相关产品推荐
相关产品推荐

