Jenkins Pipeline切换Git仓库至SSH访问后任务失败求助
Alright, let's work through this since you've already confirmed the SSH key itself is solid (direct clone/commit on the server works, Bitbucket permissions are set, key's in ssh-agent). Here are the most likely culprits and fixes:
1. Check Your Gradle Script for Leftover HTTP References
Even if your main repo is now on SSH, your build.gradle might still have dependencies, plugin repos, or submodules pointing to HTTP URLs. Look for lines like:
repositories { maven { url 'http://your-team/repo.git' } // Should switch to ssh:// or git@... format } // Or submodule upload configs uploadArchives { repositories { mavenDeployer { repository(url: 'http://old-http-repo-url') } } }
If you spot any HTTP links for Git-based repos, update them to SSH (e.g., git@bitbucket.org:your-team/your-dependency-repo.git).
2. Make Sure Jenkins Pipeline Uses SSH Agent Correctly
Just because the key's on the server's ssh-agent doesn't mean Jenkins is tapping into it. Wrap both your Git checkout and Gradle build steps with Jenkins' sshagent plugin in your pipeline:
pipeline { agent any stages { stage('Checkout Code') { steps { sshagent(['your-ssh-credential-id']) { // Use the ID from Jenkins Credentials git url: 'git@bitbucket.org:your-team/main-repo.git', branch: 'main' } } } stage('Build with Gradle') { steps { sshagent(['your-ssh-credential-id']) { // Wrap build too if it needs SSH access sh './gradlew clean build' } } } } }
Double-check the credential ID matches what's stored in Manage Jenkins > Credentials—it's easy to mix up IDs here.
3. Check Gradle's Git Credential Helper
Gradle might be clinging to an old credential helper set up for HTTPS. Run this on the Jenkins server to check:
git config --global credential.helper
If it returns something like manager-core or another HTTPS-focused helper, you can override it for the build by adding this step before running Gradle:
sh 'git config --local core.sshCommand "ssh -o StrictHostKeyChecking=no -i $SSH_AGENT_SOCK"'
(Disabling StrictHostKeyChecking is optional, but it can fix issues where Jenkins hasn't accepted Bitbucket's host key yet.)
4. Verify the Jenkins User Can Access the SSH Key
Jenkins usually runs under a dedicated jenkins user—maybe the key you tested with is for a different user. Switch to the Jenkins user and test:
su - jenkins ssh-add -l # Should list your RSA key git clone git@bitbucket.org:your-team/main-repo.git # Should clone without issues
If this fails, copy your SSH key to /var/lib/jenkins/.ssh/ (or whatever the Jenkins user's home is) and set correct permissions:
chmod 700 /var/lib/jenkins/.ssh chmod 600 /var/lib/jenkins/.ssh/id_rsa
5. Dig Into the Build Logs for Specific Errors
Don't skip this! Look for lines like:
Permission denied (publickey)
Host key verification failed
Could not resolve :your-dependency:1.0.0
These specific messages will tell you exactly what's broken—whether it's a leftover HTTP repo, a key not being picked up, or a host key issue.
内容的提问来源于stack exchange,提问作者Andrea Matera

