Story time.
I attempt to clone a repository. No big deal, I've done this a million times:
$ git clone git@bitbucket.org:[my-username]/[repo-i-want].git
Cloning into '[repo-i-want]'...
git@bitbucket.org: Permission denied (publickey).
fatal: Could not read from remote repository.
Huh. I could have sworn that I added my SSH public key to Bitbucket ages ago.
$ ssh -T git@bitbucket.org
git@bitbucket.org: Permission denied (publickey).
Huh. Guess not.
So, I go to Bitbucket, click on my cute-little-overly-cliche-gopher-profile-id picture in the lower-left corner, click "Personal Settings," navigate my way on down to SSH keys and I see my public key there. Well, really all I know is that there is a key there and it's supposedly descriptive name in my settings is claiming to be the key I need to use. Maybe it's just an old key, I'll just replace it.
$ cat ~/.ssh/id_rsa.pub | xclip -sel clip
Paste that into Bitbucket and:
$ ssh -T git@bitbucket.org
git@bitbucket.org: Permission denied (publickey).
Well, that's just rude. Maybe the id_rsa.pub file in my .ssh directory isn't actually the public key to my private key (seems like a stretch, but I guess it could happen, right?)
$ ssh-keygen -y -f ~/.ssh/id_rsa | xclip -sel clip
Paste that in. No joy. Maybe I need a new key. I evacuate my current creds to safety and then try:
$ ssh-keygen
[default answer to all prompts]
$ cat ~/.ssh/id_rsa.pub | xclip -sel clip
And, you guessed it, still no joy. I mean, maybe something could go wrong in the copy/paste process, right?
$ diff ~/.ssh/id_rsa.pub [file created from the key copied off of Bitbucket]
$
Yeah, okay, that was a stretch anyway.
Time to hit the Googles. I find advice to use ssh-add. All that does is tell SSH to add that key to the list of keys it should try. I'm trying to use id_rsa which is the default that the config already looks for, so this is redundant. Plus:
$ ssh -T -i ~/.ssh/id_rsa git@bitbucket.org
git@bitbucket.org: Permission denied (publickey).
So, that wouldn't do anything anyway. The other "advice" I find is to use HTTPS which isn't a solution, it's a workaround (one that I'm using right now so I can move forward with my project, but it meant disabling my MFA which I'm not super happy about). The other advice I have been able to find basically tells me to rehash the things I did above.
Clearly, I'm missing something here and it's probably painfully obvious but I'm just not seeing it. Anyone have any clarity on this?