创建Docker镜像配置Jenkins及部署SSH公钥时遭遇touch命令错误
Hey there! Let's work through your Jenkins Docker image setup and fix those issues you're hitting. I'll break this down into clear, actionable steps.
First, let's tackle that touch command failure. The most common reason this happens is that the directory you're trying to touch a file in doesn't exist yet, or you've got incorrect permissions.
For example, if you tried to run touch /root/.ssh/authorized_keys without first creating the /root/.ssh directory, Docker will throw an error. Here's how to fix it:
# Create the .ssh directory first, set strict permissions (required for SSH) RUN mkdir -p /root/.ssh && chmod 700 /root/.ssh # Now you can safely touch the file (or skip touch and directly copy your pub key) RUN touch /root/.ssh/authorized_keys && chmod 600 /root/.ssh/authorized_keys
Pro tip: SSH will reject authorized_keys if its permissions are too open—600 is mandatory here.
Since you're on Windows, remember that your ~/.ssh/id_rsa.pub is actually located at C:\Users\<YourUsername>\.ssh\id_rsa.pub. To get this into your Docker image, you have two good options:
Option 1: Copy During Build
Copy the pub key into your build context (the same folder as your Dockerfile) first, then add this to your Dockerfile:
# Copy your Windows public key into the container's authorized_keys COPY id_rsa.pub /root/.ssh/authorized_keys # Set correct permissions (critical!) RUN chmod 600 /root/.ssh/authorized_keys
Option 2: Mount the Key at Runtime (More Secure)
Instead of baking the key into the image, mount it when you run the container. This keeps your key out of the image history:
docker run -d -p 8080:8080 \ -v C:/Users/<YourUsername>/.ssh/id_rsa.pub:/root/.ssh/authorized_keys \ your-jenkins-image
Just make sure to set permissions on the mounted file if needed—you can add a startup script to do this.
Your original Dockerfile is missing a few critical pieces, like a Java base image and SSH server setup (since you're dealing with SSH keys). Here's a polished version:
# Use a lightweight Java 8 base image (matches your Jenkins war version) FROM openjdk:8-jre-alpine # Install OpenSSH Server (required for SSH access) RUN apk add --no-cache openssh-server # Configure SSH directory and permissions RUN mkdir -p /root/.ssh && chmod 700 /root/.ssh # Copy your Windows public key (make sure id_rsa.pub is in your build folder) COPY id_rsa.pub /root/.ssh/authorized_keys RUN chmod 600 /root/.ssh/authorized_keys # Generate SSH host keys RUN ssh-keygen -A # Add and configure Jenkins war ADD http://mirrors.jenkins.io/war-stable/2.107.1/jenkins.war /opt/jenkins.war RUN chmod 644 /opt/jenkins.war ENV JENKINS_HOME /jenkins # Expose Jenkins port (8080) and SSH port (22) EXPOSE 8080 22 # Start both SSH server and Jenkins ENTRYPOINT ["sh", "-c", "/usr/sbin/sshd && java -jar /opt/jenkins.war"]
Docker containers can't directly launch apps on your host machine, but you can create a simple PowerShell script to do this after starting the container:
# Start the Jenkins container docker run -d -p 8080:8080 --name my-jenkins your-jenkins-image # Wait a few seconds for Jenkins to boot, then open the browser Start-Sleep -Seconds 10 Start-Process "http://localhost:8080"
Save this as start-jenkins.ps1 and run it to automatically launch Jenkins in your default browser.
内容的提问来源于stack exchange,提问作者Hithesh

