Ubuntu下Jenkins Gerrit Trigger插件SSH密钥文件无效问题求助
Let’s break down the most actionable fixes for this "invalid key file" issue—since you’ve already confirmed the key exists and permissions look correct, we’ll focus on less obvious checks:
Verify the key file is actually parsable
Run this command as the jenkins user to confirm the private key is structurally valid:su - jenkins -c "ssh-keygen -y -f /var/lib/jenkins/.ssh/id_rsa"If this outputs your matching public key, the key itself is fine. If it throws an error (like "invalid format"), your key might be in OpenSSH format instead of PEM (which some older Gerrit Trigger versions require). Convert it with:
su - jenkins -c "ssh-keygen -p -m PEM -f /var/lib/jenkins/.ssh/id_rsa"Follow the prompts (you can keep the same passphrase or remove it if preferred).
Confirm Jenkins is running as the correct user
Sometimes Jenkins might run under a different user than expected (especially if installed via apt or systemd). Check which user owns the Jenkins process:ps aux | grep jenkinsThen verify the key file’s owner matches that user:
stat /var/lib/jenkins/.ssh/id_rsaThe output should show
Uid: ( 111/ jenkins)andGid: ( 116/ jenkins), with permissions set to-rw-------(600). The.sshdirectory itself must bedrwx------(700).Test SSH connectivity manually
Rule out Gerrit-side issues by connecting directly from the jenkins user to your Gerrit server:su - jenkins -c "ssh -i /var/lib/jenkins/.ssh/id_rsa -p <gerrit-ssh-port> gerrit@<gerrit-server-host>"If this fails, you’ll get a specific error (e.g., "Permission denied" means your public key isn’t added to Gerrit’s authorized_keys; "Host key verification failed" means you need to trust the Gerrit server’s host key first). If it succeeds, the problem is isolated to the Gerrit Trigger plugin configuration.
Enable debug logging for Gerrit Trigger
Jenkins’ default logs might miss plugin-specific errors. Enable debug logging to get more details:- Go to Manage Jenkins > System Log
- Click Add new log recorder
- Name it "Gerrit Trigger Debug"
- Add a logger with name
com.sonyericsson.hudson.plugins.gerrit.triggerand set level toDEBUG - Save, then reattempt the SSH key configuration. Check the new log recorder for detailed rejection messages.
Check plugin compatibility
Outdated or mismatched plugin versions can cause format parsing bugs. Go to Manage Jenkins > Plugins:- Update the Gerrit Trigger plugin to the latest version compatible with your Jenkins release
- If updating doesn’t help, try downgrading to a version with known compatibility (check the plugin’s changelog for notes)
内容的提问来源于stack exchange,提问作者Visakh Viswambaren

