You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Gitlab通过SSH可连接IP但无法连接FQDN问题求助

GitLab 14.10.4 SSH FQDN连接权限拒绝问题排查

问题描述

使用GitLab 14.10.4时出现以下异常:

  • 通过ssh -T git@IP_ADDRESS可正常连接服务器
  • 执行ssh -T git@FQDN时提示Permission denied (publickey,password)
  • 客户端使用同一密钥、同一机器,GitLab由独立Web服务器代理,即使直接给GitLab绑定FQDN对应IP,问题仍存在

调试日志如下:

debug1: Will attempt key: /home/user/.ssh/id_rsa RSA SHA256:VX3JDVrZYNtFpFUhiQR11IYdRCotA/yl/H0DodwKqRY agent
debug2: pubkey_prepare: done
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521>
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: Offering public key: /home/user/.ssh/id_rsa RSA SHA256:VX3JDVrZYNtFpFUhiQR11IYdRCotA/yl/H0DodwKqRY agent
debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: publickey,password
debug2: we did not send a packet, disable method
debug1: No more authentication methods to try.
git@fqdn: Permission denied (publickey,password).

可能遗漏的配置项

1. 客户端SSH配置文件缺失对应规则

检查客户端~/.ssh/config是否针对FQDN配置了正确的SSH参数,确保连接时使用指定密钥:

Host FQDN
  HostName 你的GitLab服务器IP
  User git
  IdentityFile ~/.ssh/id_rsa

替换占位符后保存,重新尝试连接。

2. 客户端已知主机密钥不匹配

客户端~/.ssh/known_hosts中存储的FQDN主机密钥可能与服务器不一致,执行以下命令移除旧条目后重新连接:

ssh-keygen -R FQDN
ssh -T git@FQDN

接受新的主机密钥后重试验证。

3. GitLab服务器authorized_keys文件异常

GitLab自动维护git用户的~/.ssh/authorized_keys文件,若手动修改过可能导致权限或内容错误:

  • 检查文件权限:确保~/.ssh目录权限为700,authorized_keys权限为600
  • 在GitLab后台(Admin Area -> Settings -> SSH Keys)触发密钥同步,重新生成该文件

4. Web代理服务器SSH转发配置错误

若使用Nginx等代理,需确保正确转发SSH流量:

  • 若代理使用非22端口,连接时需指定端口:ssh -T -p 自定义端口 git@FQDN
  • 检查代理的SSH转发规则,确保未过滤密钥认证相关数据包

5. GitLab外部URL配置不匹配

修改GitLab配置文件/etc/gitlab/gitlab.rb中的external_url为正确的FQDN:

external_url 'https://FQDN'

执行gitlab-ctl reconfigure使配置生效,确保GitLab识别该域名作为合法访问地址。

6. DNS解析异常

即使手动绑定IP,仍需确认客户端DNS解析结果正确:

nslookup FQDN
# 或
dig FQDN

确保解析结果指向GitLab服务器或代理服务器的正确IP。

内容的提问来源于stack exchange,提问作者carlbasabe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 15:35:39