通过Codeship远程部署时SSH要求输入密码,连接故障求助
Let’s walk through some common (and easy-to-miss) checks to fix your SSH connection issue with Codeship—even after adding the public key and adjusting .ssh permissions:
Key Checks to Perform
Verify
authorized_keysfile permissions
You’ve fixed the directory permissions withchmod -R go-rwx ~/.ssh/, but the file itself needs strict permissions too. Run this command on your server:chmod 600 ~/.ssh/authorized_keysSSH servers reject public key authentication if this file is readable by other users.
Confirm the correct user account
Double-check that you added Codeship’s public key to the right user’sauthorized_keysfile. For example, if Codeship is trying to connect asdeploybut you added the key toroot’s.sshfolder, the connection will fail.Inspect SSH server configuration
Open/etc/ssh/sshd_configon your server and verify these settings:PubkeyAuthentication yes(ensures public key auth is enabled)AuthorizedKeysFile .ssh/authorized_keys(matches the path where you added the key)- If you have
PasswordAuthentication noenabled, make sure Codeship isn’t configured to use password login (but since you’re using keys, this is less likely to be the issue).
After making changes, restart the SSH service:
# Debian/Ubuntu sudo systemctl restart sshd # RHEL/CentOS sudo systemctl restart sshdCheck SSH logs for specific errors
This is the most effective step to pinpoint the problem. On your server, tail the auth log while triggering a connection from Codeship:# Debian/Ubuntu tail -f /var/log/auth.log # RHEL/CentOS tail -f /var/log/secureLook for lines mentioning
sshdand your Codeship IP—they’ll tell you exactly why authentication failed (e.g., "invalid key", "permission denied", "user not found").Validate the public key itself
Make sure you copied Codeship’s public key entirely and correctly intoauthorized_keys. No extra line breaks, missing characters (like thessh-rsaprefix), or trailing spaces—even a tiny typo will invalidate the key.Test public key auth manually
To rule out server-side issues, generate a temporary key pair on your local machine, add the public key to your server’sauthorized_keys, and run:ssh -i /path/to/private_key user@your_server_ipIf this works, the problem is likely specific to Codeship’s configuration (e.g., incorrect key, wrong user, or IP restrictions on your server).
Final Notes
Most SSH auth failures with CI tools like Codeship boil down to permission issues, incorrect key placement, or misconfigured SSH settings. The logs will almost always lead you to the root cause.
内容的提问来源于stack exchange,提问作者Ivica

