You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何不使用molecule login,通过SSH连接Vagrant部署的CentOS7 molecule实例

解决Molecule+Vagrant实例SSH连接的Host Key验证失败问题

嘿,这个问题我在测试环境折腾Molecule的时候也碰到过,给你一步步拆解解决办法:

首先先理清楚报错的核心原因:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is SHA256:wVk4Da5pWWNHLiypvEKAJuwzG/2FLOMgwPkrO4oFBZQ.
Please contact your system administrator.
Add correct host key in /Users/abel/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /Users/abel/.ssh/known_hosts:32
ECDSA host key for 192.168.33.111 has changed and you have requested strict checking.
Host key verification failed

这个错误是因为192.168.33.111这个IP之前被其他虚拟机使用过,你的~/.ssh/known_hosts文件里已经存储了该IP对应的旧主机密钥。现在Molecule创建的新VM复用了这个IP,SSH检测到密钥不匹配,触发了默认的安全拦截机制。

快速解决单次连接问题

直接删除known_hosts里对应IP的旧密钥记录,执行命令:

ssh-keygen -R 192.168.33.111

执行完成后,重新用SSH连接实例即可:

ssh vagrant@192.168.33.111

(Vagrant默认的用户名和密码都是vagrant;如果想用密钥登录,因为你在配置里加了ssh.insert_key = false,可以直接用Vagrant默认的私钥:

ssh -i ~/.vagrant.d/insecure_private_key vagrant@192.168.33.111
```)

### 适配测试环境的长期解决方案
由于Molecule/Vagrant的实例经常会销毁重建,每次手动删密钥太麻烦,你可以在SSH配置里针对这个IP禁用严格检查:
1. 编辑`~/.ssh/config`文件(如果没有就新建一个)
2. 添加以下内容:
```ssh-config
Host 192.168.33.111
    StrictHostKeyChecking no
    UserKnownHostsFile /dev/null

这样以后每次连接这个IP的VM,SSH都会自动跳过主机密钥检查,不会再弹出这个错误,非常适合测试环境频繁重建实例的场景。

补充:为什么molecule login能正常连接?

因为Molecule内部处理SSH连接时,已经自动跳过了主机密钥的严格检查,或者维护了独立的已知主机列表,所以不会触发这个报错。

内容的提问来源于stack exchange,提问作者Abel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:09:26