Docker容器中Jenkins Job执行git pull失败(SSH密钥已配置)
Jenkins流水线git pull报错
Permission denied (publickey)的排查与解决 在Docker容器中运行的Jenkins任务,能通过SSH密钥凭证从Gerrit拉取代码(checkout),但执行git pull时出现以下错误:
gerrit@xxxx: Permission denied (publickey).
fatal: Could not read from remote repository.Please make sure you have the correct access rights
and the repository exists.
可能的原因
- SSH密钥作用域不匹配:Checkout阶段使用Jenkins凭证管理的密钥,但
git pull执行时,容器内Jenkins进程未加载该密钥,或执行命令的用户身份与Checkout阶段不一致 - Git远程地址配置错误:Checkout后本地仓库的remote地址与凭证匹配的地址不符,或remote使用HTTPS协议而非SSH
- Docker容器内SSH环境异常:Jenkins的SSH凭证依赖的代理环境未在容器内正确配置,或
~/.ssh目录、密钥文件权限不符合SSH要求(权限过宽会被拒绝)
对应的解决方案
- 明确指定凭证执行
git pull:用Jenkins的withCredentials步骤包裹git pull,确保命令使用正确的SSH密钥,示例流水线代码:withCredentials([sshUserPrivateKey(credentialsId: '你的GerritSSH凭证ID', keyFileVariable: 'SSH_KEY')]) { sh """ ssh-agent bash -c 'ssh-add \$SSH_KEY; git pull' """ } - 检查并修正Git远程地址:在流水线中添加命令确认远程地址格式,不符合则修正:
sh "git remote -v" sh "git remote set-url origin gerrit@xxxx:你的仓库路径.git" - 修正容器内SSH文件权限:确保Jenkins用户的
~/.ssh目录权限为700,密钥文件权限为600:sh "chmod 700 ~/.ssh && chmod 600 ~/.ssh/id_rsa" - 测试容器内SSH连通性:添加命令验证与Gerrit的SSH连接是否正常(端口根据实际情况调整):
sh "ssh -i \$SSH_KEY gerrit@xxxx -p 29418 -T"
内容的提问来源于stack exchange,提问作者fantasy.deng
相关产品推荐
相关产品推荐

