Jenkins容器SSH密钥连接SSH服务器容器失败求助
Hey there, let's work through this SSH key issue you're facing with your Docker+Jenkins setup. The "Permission denied" error on your private key is almost always tied to overly open file permissions (SSH is strict about this) or incorrect ownership that the jenkins user can't modify directly. Here's how to fix it step by step:
First, Understand the Root Causes
- SSH requires private keys to have read/write access only for the owner (permissions
600). Any broader access (like read permissions for other users) will trigger an error. - When you use
docker cpto copy the key into/tmpof the Jenkins container, the file inherits ownership from your host machine's user UID/GID—this doesn't match thejenkinsuser inside the container. Plus,/tmpis often mounted with restrictions that prevent regular users from changing file ownership withchown.
Solution 1: Fix Permissions as Root in the Jenkins Container
Since the jenkins user can't modify the file's ownership on its own, jump into the container as root first:
- Get your Jenkins container's name or ID with:
docker ps - Exec into the container as root:
docker exec -u root -it <jenkins-container-name> /bin/bash - Update the ownership and set the strict required permissions for the private key:
chown jenkins:jenkins /tmp/remote-key chmod 600 /tmp/remote-key - Switch back to the
jenkinsuser and test the SSH command again:su jenkins ssh -i /tmp/remote-key remote_user@remote_host
Solution 2: Mount the Private Key as a Volume (Better for Persistence)
Instead of using docker cp, mount your local private key directly into the Jenkins container at a path the jenkins user owns, and handle permissions upfront in your docker-compose.yml:
- Update your Jenkins service configuration in
docker-compose.yml:services: jenkins: # ... your existing config ... volumes: # Mount local private key to Jenkins' .ssh directory - ./centos/remote-key:/var/jenkins_home/.ssh/remote-key # Optional: Ensure the container uses UID/GID matching your host user to avoid permission gaps user: "${UID}:${GID}" # Alternatively, set permissions on container start (for official Jenkins images) entrypoint: > bash -c "chown jenkins:jenkins /var/jenkins_home/.ssh/remote-key && chmod 600 /var/jenkins_home/.ssh/remote-key && /usr/local/bin/jenkins.sh" - Create the
.sshdirectory in your local Jenkins volume mount (if missing) and lock down its permissions:mkdir -p ./jenkins_home/.ssh chmod 700 ./jenkins_home/.ssh - Restart your containers:
docker-compose down && docker-compose up -d - Now inside the Jenkins container, you can use the key directly from
/var/jenkins_home/.ssh/remote-keywithout permission issues.
Solution 3: Embed the Private Key in the Jenkins Image (Testing Only)
If this is just an experiment and you don't mind hardcoding the key (never do this for production), add it to a custom Jenkins Dockerfile:
- Create a custom Dockerfile for Jenkins:
FROM jenkins/jenkins:lts USER root # Copy the private key from your local centos directory COPY centos/remote-key /var/jenkins_home/.ssh/remote-key # Set correct ownership and strict permissions RUN chown jenkins:jenkins /var/jenkins_home/.ssh/remote-key && chmod 600 /var/jenkins_home/.ssh/remote-key USER jenkins - Update your
docker-compose.ymlto build this custom image instead of using the official one. - Rebuild and restart your containers.
Quick Verification Step
After fixing permissions, always double-check with:
ls -l /tmp/remote-key # Or the path you're using for the key
You should see output like this (confirming only the owner has access):
-rw------- 1 jenkins jenkins 1679 Aug 20 12:34 /tmp/remote-key
Let me know if any of these steps resolve your issue!
内容的提问来源于stack exchange,提问作者Leem.fin

