You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins容器SSH密钥连接SSH服务器容器失败求助

Fixing SSH Key Permission Denied in Jenkins Docker Container

Hey there, let's work through this SSH key issue you're facing with your Docker+Jenkins setup. The "Permission denied" error on your private key is almost always tied to overly open file permissions (SSH is strict about this) or incorrect ownership that the jenkins user can't modify directly. Here's how to fix it step by step:

First, Understand the Root Causes

  • SSH requires private keys to have read/write access only for the owner (permissions 600). Any broader access (like read permissions for other users) will trigger an error.
  • When you use docker cp to copy the key into /tmp of the Jenkins container, the file inherits ownership from your host machine's user UID/GID—this doesn't match the jenkins user inside the container. Plus, /tmp is often mounted with restrictions that prevent regular users from changing file ownership with chown.

Solution 1: Fix Permissions as Root in the Jenkins Container

Since the jenkins user can't modify the file's ownership on its own, jump into the container as root first:

  1. Get your Jenkins container's name or ID with:
    docker ps
    
  2. Exec into the container as root:
    docker exec -u root -it <jenkins-container-name> /bin/bash
    
  3. Update the ownership and set the strict required permissions for the private key:
    chown jenkins:jenkins /tmp/remote-key
    chmod 600 /tmp/remote-key
    
  4. Switch back to the jenkins user and test the SSH command again:
    su jenkins
    ssh -i /tmp/remote-key remote_user@remote_host
    

Solution 2: Mount the Private Key as a Volume (Better for Persistence)

Instead of using docker cp, mount your local private key directly into the Jenkins container at a path the jenkins user owns, and handle permissions upfront in your docker-compose.yml:

  1. Update your Jenkins service configuration in docker-compose.yml:
    services:
      jenkins:
        # ... your existing config ...
        volumes:
          # Mount local private key to Jenkins' .ssh directory
          - ./centos/remote-key:/var/jenkins_home/.ssh/remote-key
        # Optional: Ensure the container uses UID/GID matching your host user to avoid permission gaps
        user: "${UID}:${GID}"
        # Alternatively, set permissions on container start (for official Jenkins images)
        entrypoint: >
          bash -c "chown jenkins:jenkins /var/jenkins_home/.ssh/remote-key && chmod 600 /var/jenkins_home/.ssh/remote-key && /usr/local/bin/jenkins.sh"
    
  2. Create the .ssh directory in your local Jenkins volume mount (if missing) and lock down its permissions:
    mkdir -p ./jenkins_home/.ssh
    chmod 700 ./jenkins_home/.ssh
    
  3. Restart your containers:
    docker-compose down && docker-compose up -d
    
  4. Now inside the Jenkins container, you can use the key directly from /var/jenkins_home/.ssh/remote-key without permission issues.

Solution 3: Embed the Private Key in the Jenkins Image (Testing Only)

If this is just an experiment and you don't mind hardcoding the key (never do this for production), add it to a custom Jenkins Dockerfile:

  1. Create a custom Dockerfile for Jenkins:
    FROM jenkins/jenkins:lts
    USER root
    # Copy the private key from your local centos directory
    COPY centos/remote-key /var/jenkins_home/.ssh/remote-key
    # Set correct ownership and strict permissions
    RUN chown jenkins:jenkins /var/jenkins_home/.ssh/remote-key && chmod 600 /var/jenkins_home/.ssh/remote-key
    USER jenkins
    
  2. Update your docker-compose.yml to build this custom image instead of using the official one.
  3. Rebuild and restart your containers.

Quick Verification Step

After fixing permissions, always double-check with:

ls -l /tmp/remote-key # Or the path you're using for the key

You should see output like this (confirming only the owner has access):

-rw------- 1 jenkins jenkins 1679 Aug 20 12:34 /tmp/remote-key

Let me know if any of these steps resolve your issue!

内容的提问来源于stack exchange,提问作者Leem.fin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 11:08:10