forwarding ssh-agent on vagrant to other user than vagrant

Viewed 123

I am currently setting up a virtual machine for my company's testing environment in vagrant. Of course, this machine needs to be able to pull from our github repositories. This should be achieved using the host machine's ssh keys. I have already set

config.ssh.forward_agent = true

in my vagrantfile, and connecting to github works fine in the vagrant user. However, since that machine needs to run jenkins, this needs to work for the jenkins user as well. Running ssh-add as jenkins does not add the host's key, though.

I found several semi-related discussions here on stackoverflow and on superuser, but none seemed to address or even solve the issue. I have no idea how to make this work, or whether this is possible at all in vagrant, so I am grateful for any pointers.

2 Answers

As you have not included any exact errors and what you have tried,

Let's say you are on the VM, and you want to git pull from a remote git repo

You also have a ssh private key on the VM, that is authorized to pull from the git repo via ssh:

Try this on the VM's cli:

git config core.sshCommand 'ssh -i /root/.ssh/git_private.key -F /dev/null' && ssh-agent sh -c 'ssh-add /root/.ssh/git_private.key; git pull'

and of course reference the correct path to the private ssh key that you would use to auth to git repo

I ran su command to switch to root. Using default password: vagrant.

From there su jenkins - switching user to jenkins, no password this time.

ran ssh-keygen - to generate the keys. Stored them in the default folder suggested: /var/lib/jenkins/ (actually overwrote the existing ones). That is the home folder of this jenkins user, because it is not a regular user/account, but so called "service account" I believe.

After that I just uploaded that .pub key to my bitbucket account, and everything ran fine, my jenkins could authenticate.

Related