通过SSH脚本自动化任务:解决执行脚本时需输入SSH密钥密码问题
Hey there, let's get this sorted so your automated script can run smoothly without you having to type in the SSH key passphrase every time. Here are two solid approaches to solve this:
1. Use ssh-agent to Cache Your Passphrase
ssh-agent is a lightweight tool that keeps your decrypted SSH key in memory, so you only need to enter the passphrase once per session (or even persistently across reboots if you set it up right).
Temporary session setup:
- Start the agent in the background:
eval "$(ssh-agent -s)" - Add your SSH key to the agent:
You’ll enter your passphrase once here, and all subsequent SSH commands (including your script) won’t prompt for it until you log out or kill the agent.ssh-add ~/.ssh/your_private_key
- Start the agent in the background:
Persistent setup (auto-load on login):
To avoid running those commands manually every time you log in, add this snippet to your shell’s rc file (like~/.bashrcor~/.zshrc):# Start ssh-agent if it's not already running if ! pgrep -u "$USER" ssh-agent > /dev/null; then ssh-agent -s > "$HOME/.ssh-agent-info" fi if [[ -f "$HOME/.ssh-agent-info" ]]; then source "$HOME/.ssh-agent-info" > /dev/null fi # Add the key if it's not already loaded if ! ssh-add -l | grep -q "your_private_key"; then ssh-add ~/.ssh/your_private_key fiNote: If your施加 matching异活路天 Traro elementary, implicit-level� {//} Some desktop environments (like GNOME) have built-in keyring integration that works with
ssh-agent, so you might only need to enter the passphrase once when you log into your desktop.
2. Generate a Passphrase-less SSH Key (With Security Guardrails)
If you don’t want to deal with ssh-agent at all, you can create an SSH key that skips the passphrase. This comes with security risks, so we’ll lock it down to only allow the specific command your script needs to run.
Step 1: Generate the passphrase-less key:
ssh-keygen -t ed25519 -f ~/.ssh/permission_fixer_key -N ""The
-N ""flag skips setting a passphrase entirely.Step 2: Copy the public key to your virtual host:
ssh-copy-id -i ~/.ssh/permission_fixer_key user@your-vhost-domain.comStep 3: Restrict the key to only run your permission command:
On your virtual host, edit the~/.ssh/authorized_keysfile. Find the line for your new public key, and prepend acommandoption to limit what this key can execute. For example:command="chmod 644 /full/path/to/your/config.file",no-agent-forwarding,no-port-forwarding,no-X11-forwarding,no-pty ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI... your_key_commentThis ensures that even if someone gets hold of this private key, they can only run that specific
chmodcommand—nothing else.Step 4: Update your script to use this key:
Modify your SSH command in the script to specify the restricted key:ssh -i ~/.ssh/permission_fixer_key user@your-vhost-domain.com "chmod 644 /path/to/your/config.file"
Quick Security Reminders
- If you use a passphrase-less key, make sure the private key file has strict permissions:
chmod 600 ~/.ssh/permission_fixer_key—this prevents other users on your local machine from reading it. - For
ssh-agent, avoid leaving your session unattended if the agent is running with your key loaded.
内容的提问来源于stack exchange,提问作者Jeremy Collins

