You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

构建Docker镜像时,pip从私有GitHub仓库装Python包遇权限问题

问题

为Jenkins自动化服务器编写了如下Dockerfile,已配置SSH使jenkins用户可访问GitHub执行meson构建命令,此前运行正常。但执行pip3 install --upgrade --user git+ssh://git@github.com/myrepos/myproj@master安装私有GitHub仓库的Python包时,出现git@github.com: Permission denied (publickey)错误,需调整Dockerfile配置以访问该私有仓库。

现有Dockerfile

################################################################################
# Ubuntu 22.10
FROM ubuntu:22.10
################################################################################
# Install packages
RUN apt-get update && apt-get install --yes --no-install-recommends \
  build-essential \
  gfortran \
  meson \
  pkg-config \
  sox \
  git \
  cmake \
  openssh-client \
  python3 \
  python3-pip \
  python3-numpy 
################################################################################
# Create a Jenkins user with proper host group id and user id
ARG UNAME=jenkins
# Get group and user ids from outside "docker build" command line
ARG GID=
ARG UID=
RUN groupadd --gid $GID $UNAME && \
    useradd --gid $GID --uid $UID --home-dir /home/$UNAME --create-home $UNAME
################################################################################
# Add github.com to the list of known ssh hosts for user Jenkins
USER $UNAME
RUN mkdir /home/$UNAME/.ssh/ && \
    touch /home/$UNAME/.ssh/known_hosts && \
    ssh-keyscan github.com >> /home/$UNAME/.ssh/known_hosts
################################################################################
# Install myproj from myrepos:
RUN pip3 install --upgrade --user git+ssh://git@github.com/myrepos/myproj@master
################################################################################

错误信息

git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.
Please make sure you have the correct access rights and the repository exists.

解决方案

方法1:构建时传入SSH私钥(临时构建场景)

通过构建参数传入有权限访问私有仓库的SSH私钥,写入jenkins用户的.ssh目录,安装完成后立即删除私钥,避免密钥留在镜像中。

修改后的Dockerfile相关片段:

################################################################################
# Add github.com to known hosts and configure SSH key
ARG SSH_PRIVATE_KEY
USER $UNAME
RUN mkdir /home/$UNAME/.ssh/ && \
    touch /home/$UNAME/.ssh/known_hosts && \
    ssh-keyscan github.com >> /home/$UNAME/.ssh/known_hosts && \
    echo "$SSH_PRIVATE_KEY" > /home/$UNAME/.ssh/id_rsa && \
    chmod 600 /home/$UNAME/.ssh/id_rsa
################################################################################
# Install myproj from myrepos, then clean up SSH key
RUN pip3 install --upgrade --user git+ssh://git@github.com/myrepos/myproj@master && \
    rm /home/$UNAME/.ssh/id_rsa
################################################################################

构建命令示例:

docker build --build-arg GID=xxx --build-arg UID=xxx --build-arg SSH_PRIVATE_KEY="$(cat ~/.ssh/id_rsa)" .

方法2:使用GitHub个人访问令牌(PAT)替代SSH密钥(CI环境推荐)

将SSH地址替换为HTTPS格式,利用GitHub PAT进行认证,无需处理SSH密钥权限问题,安全性更高。

修改后的Dockerfile相关片段:

################################################################################
# Add build arg for GitHub PAT
ARG GITHUB_PAT
USER $UNAME
################################################################################
# Install myproj using HTTPS with PAT
RUN pip3 install --upgrade --user git+https://${GITHUB_PAT}@github.com/myrepos/myproj@master
################################################################################

构建命令示例:

docker build --build-arg GID=xxx --build-arg UID=xxx --build-arg GITHUB_PAT="your_pat_here" .

方法3:复用Jenkins主机的SSH密钥(容器化Jenkins场景)

如果Jenkins容器运行时挂载了主机的.ssh目录,可在运行阶段安装包(而非构建阶段),直接复用主机已配置好的SSH密钥:

  1. 构建镜像时移除pip install步骤
  2. 运行容器时挂载主机的.ssh目录到jenkins用户的home目录:
docker run -v /path/to/jenkins/.ssh:/home/jenkins/.ssh your-image-name
  1. 在容器内或Jenkins任务中执行pip3 install命令

内容的提问来源于stack exchange,提问作者Danijel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 02:10:36