I would like to use SSH in Bitbucket Pipelines to clone another repository from Bitbucket.
There is today an official way to use keys without env variables
https://confluence.atlassian.com/bitbucket/use-ssh-keys-in-bitbucket-pipelines-847452940.html
Up to date as of 04/04/2018.
For example. I want to clone repo-2 into a build from repo-1
To use SSH to clone another repository from Bitbucket you need to do the following.
An example bitbucket-pipelines.yml is:
image: ubuntu:16.04pipelines: default: - step: - apt-get update -y - apt-get install -y git - git clone <your_repo_here> # For example, git@bitbucket.org:username/repo-2.git
Out of date response. Content here still works, but is much more work to set up.
See this for an up to date solution: https://community.atlassian.com/t5/Bitbucket-questions/Re-How-can-I-use-SSH-in-Bitbucket-Pipelines/qaq-p/764824/comment-id/25670#M25670
--------------------------
Old method
There's a few steps required to do this.
First, you need to generate a key-pair to use for Bitbucket.
Generate a new SSH key-pair for use in Bitbucket.
$ ssh-keygen -t rsa -b 4096 -C "
Do not use a passphrase, when prompted.
Once you have generated the key-pair, add the public key to your account:
https://confluence.atlassian.com/display/BITBUCKET/Add+an+SSH+key+to+an+account
If you already had an SSH key, and skipped the set up, start reading from here.
Now, we can set up SSH in Bitbucket Pipelines:
First, we will add the SSH key as an environment variable.
As of right now, Pipelines does not support line breaks in the environment variable, so we need to encode the private key first:
$ base64 <path>/<to>/id_rsa | pbcopy # probably path is ~/.ssh/id_rsa
Now create a secured environment variable in Bitbucket Pipelines called PRIVATE_KEY, with the contents of the base64 encoded private key:
https://confluence.atlassian.com/display/BITBUCKET/Environment+variables+in+Bitbucket+Pipelines
Now, create a bitbucket-pipelines.yml with the following content (I can't find the original source of this example sorry, share if you know ):
# You can use a Docker image from Docker Hub or your own container # registry for your build environment. pipelines: default: - step: script: # Modify the commands below to build your repository. - echo $PRIVATE_KEY > ~/.ssh/id_rsa.tmp - base64 -d ~/.ssh/id_rsa.tmp > ~/.ssh/id_rsa - chmod 600 ~/.ssh/id_rsa - base64 ~/.ssh/id_rsa - git clone git@bitbucket.org:<account_name>/<repo_name>.git
You should see that the build successfully cloned your repository.
Troubleshooting
Q: The clone asks for a passphrase:
A: There are two things you should double check. When you created the SSH key-pair, did you create them without a passphrase? (If there's a passphrase, things get much more complicated than expected). If you did not have a passphrase, double check that the key (the private key) you have stored is base64 encoded.
------------------------
See: https://community.atlassian.com/t5/Bitbucket-questions/Re-How-can-I-use-SSH-in-Bitbucket-Pipelines/qaq-p/764824/comment-id/25670#M25670
This line is superfluous and can be deleted: - base64 ~/.ssh/id_rsa
For a slightly more general guide for using ssh and ssh-based tools from a pipeline (not just for cloning another Bitbucket repository) see this other question:
https://answers.atlassian.com/questions/39429257
It is similar to Philip's answer but also covers server key fingerprints and uploading your public key to other types of servers.
I added the above to my config file but on the first statement, echo $PRIVATE_KEY > ~/.ssh/id_rsa.tmp, I received the following: bash: /root/.ssh/id_rsa.tmp: No such file or directory
Add this statement before you echo the PRIVATE_KEY:
mkdir ~/.ssh
Does that help?
Great, this worked. Thanks!
I'm attempting to use `npm` packages installed from private repositories in the same team account as the pipelines repo is running. I tried the steps for adding ssh but no luck any advice?
How do you actually use that key in a command?
The keys are injected into your build and should be available to commands that need them (in a similar way to how it would run locally).
Note that you'll still need to add the corresponding public key to whichever service you're trying to contact.
Yeah ive dropped the pipeline pub key onto my server in .ssh/authorized_keysA simple "ssh -i user@domain.com" doesn't workIll keep trying
I have the same issue when I'm trying to install a dependency from a private repo. Did you find the solution?
Hi Philip,
I followed your steps above to add submodule from another bitbucket repo to my pipeline, but unfortunately encounter error:
<span>Host key verification failed.</span><span>fatal: Could not read from remote repository.</span>
<span>Host key verification failed.</span>
<span>fatal: Could not read from remote repository.</span>
<span> </span>
Hi @Philip Hodder! I work at my client's office and they have provided me access to their private repositories. All repositories that i have access to are private. I am trying to run a pipeline in repo A and want to checkout some build scripts from repo B so i could use them during the pipeline run in repo A. I followed your steps described above and added public key (from the key-pair i generated in repo A) to "Access keys" section in repo B. Now when i try building code, i get the following message in pipeline for repo A:
+ git clone -b dev git@bitbucket.org:company_name/devops.gitCloning into 'devops'...Warning: Permanently added the RSA host key for IP address '18.205.93.0' to the list of known hosts.To access this repository, add your IP address to the whitelist. For details, see https://confluence.atlassian.com/x/TY5qMwfatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
I checked the link mentioned in the log but it seems whitelisting is a Premium feature. When i checked settings in my avatar, it shows free account. Is there no way i can access one private repo's content in another repo's pipeline without a Premium account?
Hi @GC,
The IP whitelist needs to be configured on your client's account (the one that owns the repository you're trying to clone). Not on your own user account.
The IPs that need to be whitelisted are listed here: https://confluence.atlassian.com/bitbucket/what-are-the-bitbucket-cloud-ip-addresses-i-should-use-to-configure-my-corporate-firewall-343343385.html
Specifically the "Valid IP addresses for Bitbucket Pipelines build environments" section.
Thanks,
Phil
Please support SSH key of ed25519 type.
Hi,
Can you please open a feature request for that here: https://bitbucket.org/site/master/issues/new
@Philip Hodder any ideas on how we could solve this?
Can you list out the steps you've tried for setting this up at the moment? It'll make it easier for me to see if you've missed anything in particular.
From the error message, it looks like NPM isn't using SSH. It's calling an HTTPS URL, and mentions an invalid username and password, rather than an invalid SSH key.
It looks like you're new here. Sign in or register to get started.