ci: fix SSH deploy by switching to alpine + openssh-client and PEM key conversion

This commit is contained in:
mediabot-pt
2026-06-29 12:08:22 +08:00
parent c6f371af0f
commit 7a83b1cc31

View File

@@ -228,7 +228,7 @@ steps:
# ===================== Test:部署到测试服务器 =====================
- name: deploy-test
image: 192.168.31.253/library/alpine-openssh:latest
image: 192.168.31.253/library/alpine:latest
environment:
DEPLOY_IMAGE: "192.168.31.253/yescent/${DRONE_REPO_NAME}"
APP_PORT: "9012"
@@ -243,12 +243,20 @@ steps:
echo "====== 部署测试环境 ======"
source /drone/src/.version.env
# 安装新版 openssh-client
apk add --no-cache openssh-client
mkdir -p ~/.ssh
echo "$SSH_KEY" > ~/.ssh/id_rsa
chmod 700 ~/.ssh
# 使用 printf 确保换行符正确写入
printf '%s\n' "$SSH_KEY" > ~/.ssh/id_rsa
chmod 600 ~/.ssh/id_rsa
# 如果私钥是 OpenSSH 新格式,尝试转换为 PEM 格式
ssh-keygen -p -m PEM -N "" -f ~/.ssh/id_rsa 2>/dev/null || true
export IMG="$DEPLOY_IMAGE:$BUILD_VERSION"
ssh -o StrictHostKeyChecking=no $SSH_USER@$SSH_HOST "
ssh -o StrictHostKeyChecking=no -o IdentitiesOnly=yes -i ~/.ssh/id_rsa $SSH_USER@$SSH_HOST "
docker pull $IMG
docker stop par-server 2>/dev/null || true
docker rm -f par-server 2>/dev/null || true
@@ -306,7 +314,7 @@ steps:
branch: [main]
- name: deploy-main
image: 192.168.31.253/library/alpine-openssh:latest
image: 192.168.31.253/library/alpine:latest
environment:
DEPLOY_IMAGE: "192.168.31.253/yescent/${DRONE_REPO_NAME}"
APP_PORT: "9012"
@@ -321,12 +329,20 @@ steps:
echo "====== 部署生产环境 ======"
source /drone/src/.version.env
# 安装新版 openssh-client
apk add --no-cache openssh-client
mkdir -p ~/.ssh
echo "$SSH_KEY" > ~/.ssh/id_rsa
chmod 700 ~/.ssh
# 使用 printf 确保换行符正确写入
printf '%s\n' "$SSH_KEY" > ~/.ssh/id_rsa
chmod 600 ~/.ssh/id_rsa
# 如果私钥是 OpenSSH 新格式,尝试转换为 PEM 格式
ssh-keygen -p -m PEM -N "" -f ~/.ssh/id_rsa 2>/dev/null || true
export IMG="$DEPLOY_IMAGE:$BUILD_VERSION"
ssh -o StrictHostKeyChecking=no $SSH_USER@$SSH_HOST "
ssh -o StrictHostKeyChecking=no -o IdentitiesOnly=yes -i ~/.ssh/id_rsa $SSH_USER@$SSH_HOST "
docker pull $IMG
docker stop par-server 2>/dev/null || true
docker rm -f par-server 2>/dev/null || true