You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Buildah构建容器时SSH密钥转发语法错误,无法克隆私有GitLab仓库

使用Buildah构建Celery容器时访问私有GitLab仓库的问题

我正尝试通过Dockerfile用Buildah构建运行Celery任务的自定义容器,容器需要访问本地GitLab实例私有仓库里的依赖库。把本地克隆好的库复制到容器里能正常工作,但希望直接在Dockerfile里完成克隆操作。不过Buildah构建时,Dockerfile里的git clone无法读取主机~/.ssh/id_rsa路径下的SSH密钥,导致克隆私有仓库失败。

尝试使用--ssh参数的过程

我参考Buildah手册中的--ssh参数说明:

--ssh=default|id[=socket>|key[,key]

       SSH  agent socket or keys to expose to the build.  The socket path can be left empty to use the
       value of default=$SSH_AUTH_SOCK

       To later use the ssh agent, use the --mount flag in a RUN instruction within a Containerfile:

       RUN --mount=type=secret,id=id mycmd

在Dockerfile中编写了如下指令:

RUN mkdir -p -m 0700 ~/.ssh && ssh-keyscan -t ed25519 gitlab.mycompany.com >> ~/.ssh/known_hosts
RUN --mount=type=ssh git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library

执行构建命令:

buildah build --ssh=default -f celery/Dockerfile -t celery

但克隆步骤出现权限拒绝错误:

Permission denied, please try again.
Permission denied, please try again.
git@gitlab.mycompany.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.
error building at STEP "RUN --mount=type=ssh git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library": error while running runtime: exit status 128                                                       
Finished

主机上用默认SSH密钥能正常克隆该仓库,但Buildah构建时无法正确访问密钥。

尝试使用--secret参数的过程

我改用--secret参数实现克隆:
Dockerfile指令:

RUN --mount=type=secret,id=id_rsa GIT_SSH_COMMAND="ssh -i /run/secrets/id_rsa" git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library

构建命令:

buildah build --secret id=id_rsa,src=/home/wile_e8/.ssh/id_rsa -f celery/Dockerfile -t celery

首次克隆成功,但后续执行git fetch时出现密钥权限过松的错误:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0755 for '/run/secrets/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "/run/secrets/id_rsa": bad permissions
Permission denied, please try again.
Permission denied, please try again.
git@gitlab.mycompany.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

临时解决方法

后来我通过合并命令实现了多次Git操作:

ENV GIT_SSH_COMMAND="ssh -i /run/secrets/id_rsa" 
RUN --mount=type=secret,id=id_rsa git clone git@gitlab.mycompany.com:jdoe/library.git /opt/library && \
    cd /opt/library && \
    git fetch --all --tags --prune && \
    git checkout tags/1.0.0 -b 1.0.0

此方法可行,但仍希望找到--ssh参数的正确用法以简化操作。

环境信息

Buildah版本为RHEL8上的1.26.2:

$ buildah -v
buildah version 1.26.2 (image-spec 1.0.2-dev, runtime-spec 1.0.2-dev)

内容的提问来源于stack exchange,提问作者wile_e8

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 10:10:25