04/04/2018 update
We've updated the SSH functionality in Bitbucket Pipelines, and I would suggest you following the documentation here: https://confluence.atlassian.com/bitbucket/use-ssh-keys-in-bitbucket-pipelines-847452940.html
The responses here are still valid, but are much more complicated to set up than the above documentation.
Firstly, here's an overview of what you need to accomplish:
Generate a public/private key pair.
Store the private key in a secure Pipelines environment variable.
Upload the public key to the server that you want to communicate with from your pipeline.
Add a "known_hosts" file to your repository that includes the server's public ssh key.
Add some commands to the beginning of your pipeline script to tie everything together.
And now the details:
ssh-keygen -t rsa -N '' -f my_ssh_key
This will create two files - a private key named "my_ssh_key" (without a password) and a public key named "my_ssh_key.pub".
Store the private key in a secure Pipelines environment variable. We'll base-64 encode it to make sure it survives the trip through the Pipelines UI.
base64 < my_ssh_key
Just copy and paste the output of this command into a Pipelines environment variable (be sure to tick the "secure" checkbox). I'll assumed you've named the variable "MY_SSH_KEY".IMPORTANT: Please be aware that ticking the "secure" checkbox will not prevent someone who has push access to your repository (and thus can control what happens when a pipeline is executed) from retrieving the key.
Upload the public key to the server that you want to communicate with from your pipeline. There are various ways to do this and if you're using a fully managed service you may be able to upload the key via a web page or similar UI. However if you have ssh access to the server then the simplest method is probably using the ssh-copy-id tool.
ssh-copy-id -i my_ssh_key.pub username@server.example.com
This uploads your new public key to the right location so that the ssh server will trust it for accessing the specified user's account. Typically that means appending the key to the ~/.ssh/authorized_keys file on the server.At this point it may be worth verifying that you can ssh into the server using the new key without having to enter a password (assuming that you expect to have full ssh access to the server).
ssh -i my_ssh_key username@server.example.com
Add a "known_hosts" file to your repository that includes the server's public ssh key. One way to do this is using the "ssh-keyscan" utility:
ssh-keyscan -t rsa server.example.com > my_known_hosts
Commit the my_known_hosts file to your repository so that it can be accessed from your pipeline. If you don't have the ssh-keyscan utility then another method is to just copy an existing known_hosts file from the ~/.ssh directory of a user that has previously accessed the server via ssh. It is a simple text file containing one line per server - you should be able to copy the file and delete all the lines except the single line for the server you want to connect to.
Add the following commands to the beginning of your pipeline script to tie everything together.
- mkdir -p ~/.ssh - cat my_known_hosts >> ~/.ssh/known_hosts - (umask 077; echo $MY_SSH_KEY | base64 --decode > ~/.ssh/id_rsa)
Now you should be able to run ssh-based commands without passwords. Here's an example of uploading a file using sftp:
- sftp username@server.example.com <<< $'put file-to-upload.txt'
In case you should run into this error:
base64: invalid input
Then just add -i at your base64 decoding command, like this:
- (umask 077; echo $MY_SSH_KEY | base64 --decode -i > ~/.ssh/id_rsa)
I follow your tutorial but still it asking password.
Did you mean to comment on this answer or on my answer above? Are you sure that you used an empty password when you created the keypair? (the -N '' argument to the ssh-keygen command).
-N ''
ssh-keygen
If you post your pipeline's script and the exact log output we might be able to help further.
in my testing, the "echo $MY_SSH_KEY" statement always returns "$MY_SSH_KEY" which fits with the Bitbucket pipelines documentation - secured variables can't be echoed... so the example doesn't work?
Would be nice to edit with @Antonello Moro's comment
@Steven Vaccarella, I followed you above tutorial step by step, and I was successful in getting file (my war file). But when i try to get that file on my local setup (through FTP), which is windows, it takes too much time i.e 3 hours. Is there any way that we can transfer our file from pipeline to windows server instead of linux ?
I'm not sure I understand your question. In your current setup are you uploading the file from your pipeline to an external Linux server and then downloading the file from that server to your local Windows machine? If that's the case then your download time is going to be affected primarily by your internet connection speed. I'm not sure how uploading the file to a Windows server instead is going to help.
At any rate it should be possible to upload to a Windows machine by following a similar process if it is running an ssh-based file server. You'll need to consult the documentation of the file server to work out how to do step 3 (configure the file server to trust your ssh key) and step 4 (obtain the server's public ssh key to add to your known hosts file).
@Steven Vaccarella , I am following same steps mentioned by you, but here I am transferring War file to Windows server instead of Linux.
For generating public/private keys I am using puttyGen software and then I saved private key to Pipeline Environment variable. But while this step:-sftp xxx@205.216.163.91 <<< $'put xxx.war'
it throws an error of"Host key verification failed.Couldn't read packet: Connection reset by peer."
Can you please help me out ?
One more thing, I was not able to do step no 3 through command line i.essh-copy-id -i my_ssh_key.pub xxx@205.216.163.91
Actually When I run this command It do some processing then throws an error of"Umask" command not recognized.
For SSH/SFTP server setting on windows, I was following this URL :-https://winscp.net/eng/docs/guide_windows_openssh_server#installing_sftp_ssh_server
How can i use java_home from pipeline gradle script.Actually I need rt.jar for compiling my one project, I cannot commit rt.jar because its size is very big, so I was just finding any other possible way of how I can compile my project without commiting rt.jar.Is there any way that i can refer rt.jar from java_home of pipeline ?
Hello, I followed your tutorial exactly as you said but it still asks for passwrod, although I created the key as you said (ssh-keygen -t rsa -N '' -f my_ssh_key):
ssh_askpass: exec(/usr/bin/ssh-askpass): No such file or directory
The only thing I changed is the last line (which gives me the error) :
ssh -T $USER_DEV@$IP_ADDRESS -p $PORT
in order to be directly on the server and make a git clone from there.
Didn't try sftp though...
But this doesn't work. Am I doing something wrong ?
Even bitbucket suggests things that does not work...
I am using windows.I have followed above partial steps. Partial steps means, I cannot do step 3 and 4. When I try to run these two step i did not get any error but I cannot get key and known host file .But here is my issue.I have accesss one of the remote server, there i setted up FTP.I also setted up key base authentication to that FTP. With key base authentication, I can login with putty/winscp to my FTP server.Now I added base64 version of my private key to environment variable of pipeline, and then also committed my_known_host file, which only contains public key contents. Nut I am not able to send war to my FTP.Will you please help me.
Use sftp -o StrictHostKeyChecking=no -o port="22" -o IdentityFile="~/.ssh/id_rsa"
Just typed the following into terminal and I get: command not found. Using Terminal and MacOS if that makes a difference
base64 < my_ssh_key
This did not work for me. Is there anything that I can miss?
Can you open a new question with some specific error messages you're getting. Then send me a link to it here. Thanks.
It looks like you're new here. Sign in or register to get started.