Bitbucket容器SSH连接Ubuntu服务器失败,本地测试正常求助
问题解决:Bitbucket流水线SSH连接失败(RSA密钥算法不被支持)
问题现象
- Bitbucket流水线执行命令
ssh -i id_rsa user@ip时出现以下错误:Pseudo-terminal will not be allocated because stdin is not a terminal.
Permission denied (publickey). - 远程Ubuntu服务器的
/var/log/auth.log日志显示密钥算法不被允许:Oct 30 12:51:14 i-xxxx sshd[162440]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Oct 30 12:51:15 i-xxxx sshd[162440]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] - 本地用相同的Linux Alpine Docker容器、同一私钥文件连接远程服务器完全正常,远程日志显示:
Oct 30 12:51:44 i-xxxx sshd[162442]: Accepted publickey for ubuntu from xx.xx.xx.xx port 63823 ssh2: RSA SHA256:<hash>
原因分析
远程服务器的sshd配置默认禁用了老旧的ssh-rsa签名算法,本地SSH客户端会自动切换到更安全的RSA-SHA2系列算法(如rsa-sha2-256),但Bitbucket流水线环境的SSH客户端可能只默认尝试ssh-rsa,导致密钥验证被拒绝。
解决方法
方法1:修改Bitbucket流水线的SSH命令(推荐)
在SSH连接命令中强制指定兼容的签名算法,覆盖客户端默认行为:
ssh -i id_rsa -o PubkeyAcceptedAlgorithms=rsa-sha2-256,rsa-sha2-512 user@ip
如果需要兼容更旧的配置,也可以临时启用ssh-rsa:
ssh -i id_rsa -o PubkeyAcceptedAlgorithms=+ssh-rsa -o HostKeyAlgorithms=+ssh-rsa user@ip
方法2:修改远程服务器的sshd配置(长期兼容)
如果需要让服务器默认支持ssh-rsa算法,编辑远程服务器的/etc/ssh/sshd_config文件,添加或修改以下配置:
PubkeyAcceptedAlgorithms +ssh-rsa HostKeyAlgorithms +ssh-rsa
保存配置后重启sshd服务:
sudo systemctl restart sshd
内容的提问来源于stack exchange,提问作者Broshi
相关产品推荐
相关产品推荐

