能否通过Bitbucket Pipelines执行pm2 deploy production部署?仅持PEM密钥
pm2 deploy production with an AWS EC2 PEM private key? Absolutely, this is feasible! You just need to adjust your SSH key setup and Pipeline configuration to work with your AWS EC2 PEM key. Let's break down the steps to make this work:
1. Generate the public key from your PEM private key
Since Bitbucket Pipelines requires both a public and private key, but you only have the PEM private key, you can generate the corresponding public key using ssh-keygen:
ssh-keygen -y -f myKey.pem > myKey.pub
This command extracts the public key from your PEM file. You'll need this public key for two critical places:
- Add it to your EC2 instance's
~/.ssh/authorized_keysfile (so the Pipeline can SSH into the instance) - Paste it into Bitbucket's SSH key configuration for your repository
2. Configure SSH access in Bitbucket Pipelines
Option A: Use repository SSH keys (recommended for simplicity)
Head to your Bitbucket repository's Settings > Pipelines > SSH keys:
- Paste the generated public key (
myKey.pubcontent) into the "Public key" field - Paste your full PEM private key content into the "Private key" field (don't omit the
-----BEGIN RSA PRIVATE KEY-----and-----END RSA PRIVATE KEY-----lines—they're part of the valid key format)
Option B: Use a secured repository variable (better for sensitive keys)
Instead of pasting the private key directly into the SSH keys section, store it as an encrypted variable:
- Go to Settings > Pipelines > Repository variables
- Create a variable named
SSH_PRIVATE_KEY, paste your PEM private key as the value, and mark it as "Secured" to encrypt it - In your Pipeline script, add these lines before running the deploy to save the key with correct permissions:
- echo "$SSH_PRIVATE_KEY" > ~/.ssh/myKey.pem - chmod 600 ~/.ssh/myKey.pem
The chmod 600 is non-negotiable—SSH will reject the key if it has overly open permissions.
3. Validate your PM2 deployment configuration
Your existing PM2 config is already set up correctly, but double-check that the key path (~/.ssh/myKey.pem) matches where you're storing the key in the Pipeline environment. If you used Option B above, this path is perfect.
Also, confirm the ubuntu user on your EC2 instance has your generated public key in their ~/.ssh/authorized_keys file. You can copy it manually or use the AWS Console to associate the key with the instance.
4. Update your Bitbucket Pipelines script
Your current script is missing a few key steps to make the deploy work in a non-interactive Pipeline environment:
script: - npm install - npm install pm2 -g # Install PM2 globally (required for the deploy CLI command) # Include these lines if you used Option B for SSH keys: - echo "$SSH_PRIVATE_KEY" > ~/.ssh/myKey.pem - chmod 600 ~/.ssh/myKey.pem # Add hosts to known_hosts to avoid SSH prompts - ssh-keyscan bitbucket.org >> ~/.ssh/known_hosts - ssh-keyscan ec2-xx-xxx-xxx-xx.us-east-2.compute.amazonaws.com >> ~/.ssh/known_hosts - npm run-script deploy
The ssh-keyscan commands prevent SSH from hanging on a prompt to add hosts to known_hosts—something that breaks non-interactive Pipeline runs.
5. Check EC2 security group settings
Make sure your EC2 instance's security group allows inbound SSH (port 22) from Bitbucket Pipelines' IP ranges. For testing, you can temporarily allow all IPs (not recommended for production) to confirm the connection works, then restrict it to Bitbucket's official IPs once you've validated the deploy.
Quick Troubleshooting Tips
- Test the deploy locally first to ensure your PM2 config works as expected
- Check Pipeline logs if something fails—they'll show detailed errors for SSH connections, git cloning, or PM2 command issues
- Ensure the
ubuntuuser on EC2 has write permissions to the/home/ubuntu/myProjectpath
内容的提问来源于stack exchange,提问作者Balasubramani M

