请求协助:将Windows下带RSA密钥的Git拉取Puppet代码转Chef代码
Hey there! I get that switching from Puppet to Chef can feel a bit bumpy when you're just starting out, especially with Windows-specific workflows like using RSA keys for Git pulls. Let’s walk through how to replicate that Puppet logic in Chef, step by step.
1. Deploy the RSA Key Pair
First, we need to get your RSA private and public keys onto the Windows node. Chef's file resource is perfect for this, and we have to make sure file permissions are tight—Git will reject keys that are accessible to too many users.
# Deploy private key to the user's .ssh folder file 'C:\Users\Administrator\.ssh\id_rsa' do content node['git_deploy']['private_key'] # Store this in a Chef data bag/encrypted attribute, not hardcoded! rights :full_control, 'Administrator' rights :read, 'Everyone', :deny => true # Lock down access to only the admin user action :create end # Optional: Deploy public key if needed for other Git operations file 'C:\Users\Administrator\.ssh\id_rsa.pub' do content node['git_deploy']['public_key'] rights :full_control, 'Administrator' action :create end
2. Configure Git to Use the Key
Next, we need to tell Git to use this specific RSA key when connecting to your repository. We'll use execute resources to set Git's global config, and also handle adding the Git host to known_hosts to avoid interactive prompts during the pull.
# Point Git to our RSA key execute 'configure git ssh command' do command 'git config --global core.sshCommand "ssh -i C:\\Users\\Administrator\\.ssh\\id_rsa"' user 'Administrator' not_if 'git config --global core.sshCommand' # Only run if this config isn't already set end # Optional: Set Git user identity (required if you plan to commit changes later) execute 'set git user name' do command 'git config --global user.name "Your Name"' user 'Administrator' not_if 'git config --global user.name' end execute 'set git user email' do command 'git config --global user.email "your.email@example.com"' user 'Administrator' not_if 'git config --global user.email' end # Add Git host (e.g., GitHub) to known_hosts to skip manual verification execute 'add github to known_hosts' do command 'ssh-keyscan github.com >> C:\\Users\\Administrator\\.ssh\\known_hosts' user 'Administrator' not_if { ::File.exist?('C:\\Users\\Administrator\\.ssh\\known_hosts') && ::File.read('C:\\Users\\Administrator\\.ssh\\known_hosts').include?('github.com') } end
3. Pull the Git Repository
Finally, use Chef's built-in git resource to sync your repository. This resource handles cloning the repo if it doesn't exist, or pulling the latest changes if it does.
# Sync the Git repository to the target path git 'C:\Projects\my-repo' do repository 'git@github.com:your-username/your-repo.git' # SSH URL for your repo revision 'main' # Use your desired branch, tag, or commit hash action :sync user 'Administrator' # Make sure this matches the user we set up the keys for end
Quick Notes to Keep in Mind
- Secure Your Keys: Never hardcode RSA keys in your Chef recipes. Use encrypted data bags or Chef Vault to store sensitive values like private keys.
- User Context: If Chef is running as a service, ensure it's using the same user account we configured the keys and Git settings for—otherwise, it won't pick up the config.
- Path Escaping: Windows paths need double backslashes (
\\) in Ruby strings to avoid being interpreted as escape characters.
内容的提问来源于stack exchange,提问作者ToastMan

