Buildah构建容器时SSH密钥转发语法错误,无法克隆私有GitLab仓库
使用Buildah构建Celery容器时访问私有GitLab仓库的问题
我正尝试通过Dockerfile用Buildah构建运行Celery任务的自定义容器,容器需要访问本地GitLab实例私有仓库里的依赖库。把本地克隆好的库复制到容器里能正常工作,但希望直接在Dockerfile里完成克隆操作。不过Buildah构建时,Dockerfile里的git clone无法读取主机~/.ssh/id_rsa路径下的SSH密钥,导致克隆私有仓库失败。
尝试使用--ssh参数的过程
我参考Buildah手册中的--ssh参数说明:
--ssh=default|id[=socket>|key[,key] SSH agent socket or keys to expose to the build. The socket path can be left empty to use the value of default=$SSH_AUTH_SOCK To later use the ssh agent, use the --mount flag in a RUN instruction within a Containerfile: RUN --mount=type=secret,id=id mycmd
在Dockerfile中编写了如下指令:
RUN mkdir -p -m 0700 ~/.ssh && ssh-keyscan -t ed25519 gitlab.mycompany.com >> ~/.ssh/known_hosts RUN --mount=type=ssh git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library
执行构建命令:
buildah build --ssh=default -f celery/Dockerfile -t celery
但克隆步骤出现权限拒绝错误:
Permission denied, please try again. Permission denied, please try again. git@gitlab.mycompany.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password). fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. error building at STEP "RUN --mount=type=ssh git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library": error while running runtime: exit status 128 Finished
主机上用默认SSH密钥能正常克隆该仓库,但Buildah构建时无法正确访问密钥。
尝试使用--secret参数的过程
我改用--secret参数实现克隆:
Dockerfile指令:
RUN --mount=type=secret,id=id_rsa GIT_SSH_COMMAND="ssh -i /run/secrets/id_rsa" git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library
构建命令:
buildah build --secret id=id_rsa,src=/home/wile_e8/.ssh/id_rsa -f celery/Dockerfile -t celery
首次克隆成功,但后续执行git fetch时出现密钥权限过松的错误:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: UNPROTECTED PRIVATE KEY FILE! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ Permissions 0755 for '/run/secrets/id_rsa' are too open. It is required that your private key files are NOT accessible by others. This private key will be ignored. Load key "/run/secrets/id_rsa": bad permissions Permission denied, please try again. Permission denied, please try again. git@gitlab.mycompany.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password). fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
临时解决方法
后来我通过合并命令实现了多次Git操作:
ENV GIT_SSH_COMMAND="ssh -i /run/secrets/id_rsa" RUN --mount=type=secret,id=id_rsa git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library && \ cd /opt/library && \ git fetch --all --tags --prune && \ git checkout tags/1.0.0 -b 1.0.0
此方法可行,但仍希望找到--ssh参数的正确用法以简化操作。
环境信息
Buildah版本为RHEL8上的1.26.2:
$ buildah -v buildah version 1.26.2 (image-spec 1.0.2-dev, runtime-spec 1.0.2-dev)
内容的提问来源于stack exchange,提问作者wile_e8
相关产品推荐
相关产品推荐

