5

With the following Dockerfile:

FROM nexylan/php-dev:7.1-alpine

COPY entrypoint.sh /
RUN chmod u+x /entrypoint.sh
ENTRYPOINT ["/entrypoint.sh"]

WORKDIR /code

CMD ["tail", "-f", "/dev/null"]

(The entrypoint does nothing related to the issue).

The definition on docker-compose:

version: '2'

services:
  data:
    image: alpine
    volumes:
      - .:/code

  console:
    build: docker/php-console
    volumes_from:
      - data
    env_file:
      - .env

And the following commands on Gitlab CI commands:

image: docker

services:
  - docker:dind

before_script:
  - docker info
  - apk add --update bash python py-pip python-dev
  - pip install docker-compose
  - docker-compose up -d
  - docker-compose ps
  - docker-compose exec -T console make install

stages:
  - test

test:
  stage: test
  tags: [docker-privileged]
  script:
    - echo ${SSH_PRIVATE_KEY} > tests/fixtures/ssh/key
    - echo ${SSH_PUBLIC_KEY} > tests/fixtures/ssh/key.pub
    - chmod 600 tests/fixtures/ssh/*
    - docker-compose exec -T console ls -l tests/fixtures/ssh/
    - docker-compose exec -T console chmod 777 /dev/tty
    - docker exec -t flintci_console_1 ssh -o StrictHostKeyChecking=no -i tests/fixtures/ssh/key -T -vvv [email protected]

The SSH command is always prompting for a passphrase with the following log:

OpenSSH_7.2p2-hpn14v4, OpenSSL 1.0.2k  26 Jan 2017
debug1: Reading configuration data /etc/ssh/ssh_config
debug2: resolving "github.com" port 22
debug2: ssh_connect_direct: needpriv 0
debug1: Connecting to github.com [192.30.253.112] port 22.
debug1: Connection established.
debug1: permanently_set_uid: 0/0
debug1: identity file tests/fixtures/ssh/key type 1
debug1: key_load_public: No such file or directory
debug1: identity file tests/fixtures/ssh/key-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_7.2p2-hpn14v4
debug1: Remote protocol version 2.0, remote software version libssh_0.7.0
debug1: no match: libssh_0.7.0
debug2: fd 3 setting O_NONBLOCK
debug1: Authenticating to github.com:22 as 'git'
debug3: send packet: type 20
debug1: SSH2_MSG_KEXINIT sent
debug3: receive packet: type 20
debug1: SSH2_MSG_KEXINIT received
debug2: local client KEXINIT proposal
debug2: KEX algorithms: [email protected],ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,ext-info-c
debug2: host key algorithms: [email protected],[email protected],[email protected],[email protected],[email protected],ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa
debug2: ciphers ctos: [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected],aes128-cbc,aes192-cbc,aes256-cbc,3des-cbc
debug2: ciphers stoc: [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected],aes128-cbc,aes192-cbc,aes256-cbc,3des-cbc
debug2: MACs ctos: [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: none,[email protected],zlib
debug2: compression stoc: none,[email protected],zlib
debug2: languages ctos: 
debug2: languages stoc: 
debug2: first_kex_follows 0 
debug2: reserved 0 
debug2: peer server KEXINIT proposal
debug2: KEX algorithms: [email protected],ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
debug2: host key algorithms: ssh-dss,ssh-rsa
debug2: ciphers ctos: [email protected],aes256-ctr,aes192-ctr,aes128-ctr,aes256-cbc,aes192-cbc,aes128-cbc,blowfish-cbc
debug2: ciphers stoc: [email protected],aes256-ctr,aes192-ctr,aes128-ctr,aes256-cbc,aes192-cbc,aes128-cbc,blowfish-cbc
debug2: MACs ctos: hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: none,zlib,[email protected]
debug2: compression stoc: none,zlib,[email protected]
debug2: languages ctos: 
debug2: languages stoc: 
debug2: first_kex_follows 0 
debug2: reserved 0 
debug1: kex: algorithm: [email protected]
debug1: kex: host key algorithm: ssh-rsa
debug1: kex: server->client cipher: [email protected] MAC: <implicit> compression: none
debug1: kex: client->server cipher: [email protected] MAC: <implicit> compression: none
debug3: send packet: type 30
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug3: receive packet: type 31
debug1: Server host key: ssh-rsa SHA256:nThbg6kXUpJWGl7E1IGOCspRomTxdCARLviKw6E5SY8
Warning: Permanently added 'github.com,192.30.253.112' (RSA) to the list of known hosts.
debug3: send packet: type 21
debug2: set_newkeys: mode 1
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug3: receive packet: type 21
debug2: set_newkeys: mode 0
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS received
debug2: key: tests/fixtures/ssh/key (0x55b4bd4e81a0), explicit
debug3: send packet: type 5
debug3: receive packet: type 6
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug3: send packet: type 50
debug3: receive packet: type 51
debug1: Authentications that can continue: publickey
debug3: start over, passed a different list publickey
debug3: preferred publickey,keyboard-interactive,password
debug3: authmethod_lookup publickey
debug3: remaining preferred: keyboard-interactive,password
debug3: authmethod_is_enabled publickey
debug1: Next authentication method: publickey
debug1: Offering RSA public key: tests/fixtures/ssh/key
debug3: send_pubkey_test
debug3: send packet: type 50
debug2: we sent a publickey packet, wait for reply
debug3: receive packet: type 60
debug1: Server accepts key: pkalg ssh-rsa blen 279
debug2: input_userauth_pk_ok: fp SHA256:3aoR/R1oBDYb0QucuGCJfBgIWW4DE2P4DjuWwgtQg/k
debug3: sign_and_send_pubkey: RSA SHA256:3aoR/R1oBDYb0QucuGCJfBgIWW4DE2P4DjuWwgtQg/k
Enter passphrase for key 'tests/fixtures/ssh/key':

The key has no passphrase, and the same docker command works well on my local laptop, not on GitLab CI.

What I'm missing?

Soullivaneuh
  • 286
  • 3
  • 15
  • Clearly, SSH *thinks* it is encrypted for some reason. Are you able to test the key with [openssh?](https://serverfault.com/questions/426394/how-to-check-if-a-rsa-public-private-key-pair-matched) (on the server you are SSH-ing FROM) Was the key generated on that server? – James Shewey Jan 02 '18 at 19:03
  • The key is just a text file. If it is encrypted the first few lines will tell. – bbaassssiiee Jan 06 '18 at 19:21
  • @JamesShewey I don't have any control of the concerned server, it's github.com. And it works well on my computer using the exact same key. – Soullivaneuh Jan 07 '18 at 14:24
  • @Soullivaneuh - but you do have control over the client, which is where you should be testing your key. – James Shewey Jan 07 '18 at 16:44
  • You might be using `ssh-agent` on your other machine? which means you wouldn't have to enter the passphrase there but your key would never the less be encrypted so when you move it to docker is asks for passphrase? – jdwolf Jan 08 '18 at 02:12
  • btw you don't have to disable HostKeyChecking, you could replace it with `ssh-keyscan -t rsa git.example.org >> ~/.ssh/known_hosts` – yellowsir Mar 28 '18 at 10:37
  • See also https://serverfault.com/a/1024258/22361 – Ex Umbris Jul 06 '20 at 19:04

1 Answers1

0

set the proper directory permission

chmod 700 tests/fixtures/ssh

add the line above between these two:

echo ${SSH_PUBLIC_KEY} > tests/fixtures/ssh/key.pub
chmod 700 tests/fixtures/ssh
chmod 600 tests/fixtures/ssh/*
D'Arcy Nader
  • 1,818
  • 2
  • 15
  • 20
  • Why not readonly? – bbaassssiiee Jan 06 '18 at 19:24
  • root can always change the permissions from readonly to writable so what's the difference? – D'Arcy Nader Jan 07 '18 at 10:10
  • Preventing accidental change. – bbaassssiiee Jan 07 '18 at 10:46
  • i'm quoting from the ssh manual `~/.ssh/ This directory is the default location for all user-specific configuration and authentication information. There is no general requirement to keep the entire contents of this directory secret, but the recommended permissions are read/write/execute for the user, and not accessible by others.` – D'Arcy Nader Jan 07 '18 at 10:53
  • Until you run a rogue program that adds a key to authorized_keys – bbaassssiiee Jan 07 '18 at 11:02
  • yes and a program like that it doesn't check for writable directory first and change the permission from readable to writable? i don't have time for this . – D'Arcy Nader Jan 07 '18 at 11:08
  • This does not solve the issue, sorry. Same result. – Soullivaneuh Jan 07 '18 at 13:49
  • perhaps on your local machine where it works you are using ssh-agent? while on your docker tests it doesn't run or perhaps it's not present. – D'Arcy Nader Jan 07 '18 at 16:14
  • It may be safer to use `chmod -R og-rwx u+rw tests/fixtures/ssh` as the non-octal version knows the difference between a file and a directory and applies the correct `6` or `7` for you. Nothing like making something crucial like your `.ssh` directory unusable by applying the wrong permissions and not being able to recover because it is on a system where you don't have `sudo` access. – dragon788 Jul 20 '18 at 03:40