构建Docker镜像时,pip从私有GitHub仓库装Python包遇权限问题
问题
为Jenkins自动化服务器编写了如下Dockerfile,已配置SSH使jenkins用户可访问GitHub执行meson构建命令,此前运行正常。但执行pip3 install --upgrade --user git+ssh://git@github.com/myrepos/myproj@master安装私有GitHub仓库的Python包时,出现git@github.com: Permission denied (publickey)错误,需调整Dockerfile配置以访问该私有仓库。
现有Dockerfile
################################################################################ # Ubuntu 22.10 FROM ubuntu:22.10 ################################################################################ # Install packages RUN apt-get update && apt-get install --yes --no-install-recommends \ build-essential \ gfortran \ meson \ pkg-config \ sox \ git \ cmake \ openssh-client \ python3 \ python3-pip \ python3-numpy ################################################################################ # Create a Jenkins user with proper host group id and user id ARG UNAME=jenkins # Get group and user ids from outside "docker build" command line ARG GID= ARG UID= RUN groupadd --gid $GID $UNAME && \ useradd --gid $GID --uid $UID --home-dir /home/$UNAME --create-home $UNAME ################################################################################ # Add github.com to the list of known ssh hosts for user Jenkins USER $UNAME RUN mkdir /home/$UNAME/.ssh/ && \ touch /home/$UNAME/.ssh/known_hosts && \ ssh-keyscan github.com >> /home/$UNAME/.ssh/known_hosts ################################################################################ # Install myproj from myrepos: RUN pip3 install --upgrade --user git+ssh://git@github.com/myrepos/myproj@master ################################################################################
错误信息
git@github.com: Permission denied (publickey). fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
解决方案
方法1:构建时传入SSH私钥(临时构建场景)
通过构建参数传入有权限访问私有仓库的SSH私钥,写入jenkins用户的.ssh目录,安装完成后立即删除私钥,避免密钥留在镜像中。
修改后的Dockerfile相关片段:
################################################################################ # Add github.com to known hosts and configure SSH key ARG SSH_PRIVATE_KEY USER $UNAME RUN mkdir /home/$UNAME/.ssh/ && \ touch /home/$UNAME/.ssh/known_hosts && \ ssh-keyscan github.com >> /home/$UNAME/.ssh/known_hosts && \ echo "$SSH_PRIVATE_KEY" > /home/$UNAME/.ssh/id_rsa && \ chmod 600 /home/$UNAME/.ssh/id_rsa ################################################################################ # Install myproj from myrepos, then clean up SSH key RUN pip3 install --upgrade --user git+ssh://git@github.com/myrepos/myproj@master && \ rm /home/$UNAME/.ssh/id_rsa ################################################################################
构建命令示例:
docker build --build-arg GID=xxx --build-arg UID=xxx --build-arg SSH_PRIVATE_KEY="$(cat ~/.ssh/id_rsa)" .
方法2:使用GitHub个人访问令牌(PAT)替代SSH密钥(CI环境推荐)
将SSH地址替换为HTTPS格式,利用GitHub PAT进行认证,无需处理SSH密钥权限问题,安全性更高。
修改后的Dockerfile相关片段:
################################################################################ # Add build arg for GitHub PAT ARG GITHUB_PAT USER $UNAME ################################################################################ # Install myproj using HTTPS with PAT RUN pip3 install --upgrade --user git+https://${GITHUB_PAT}@github.com/myrepos/myproj@master ################################################################################
构建命令示例:
docker build --build-arg GID=xxx --build-arg UID=xxx --build-arg GITHUB_PAT="your_pat_here" .
方法3:复用Jenkins主机的SSH密钥(容器化Jenkins场景)
如果Jenkins容器运行时挂载了主机的.ssh目录,可在运行阶段安装包(而非构建阶段),直接复用主机已配置好的SSH密钥:
- 构建镜像时移除
pip install步骤 - 运行容器时挂载主机的
.ssh目录到jenkins用户的home目录:
docker run -v /path/to/jenkins/.ssh:/home/jenkins/.ssh your-image-name
- 在容器内或Jenkins任务中执行
pip3 install命令
内容的提问来源于stack exchange,提问作者Danijel
相关产品推荐
相关产品推荐

