GitHub actions workflow error: ssh: handshake failed: ssh: unable to authenticate, attempted methods [none password], no supported methods remain

Viewed 5433

title is pretty much self explainatory, ssh connection is failing. I have the physical server right next to me, its under a vpn which is connected previous to the ssh.

It seems like the server is refusing the user/password pair, but it works just fine on a terminal on my computer.

The sshd_config file has PasswordAuthentication yes and i restarted the ssh service with service ssh restart.

Here is the workflow:

name: Deployment
on:
  push:
    branches: [ master ]
jobs:
  deploy:
    runs-on: ubuntu-20.04
    steps:
      - name: Set up WireGuard
        uses: egor-tensin/setup-wireguard@v1
        with:
          endpoint: ${{ secrets.WIREGUARD_ENDPOINT }}
          endpoint_public_key: ${{ secrets.WIREGUARD_ENDPOINT_PUBLIC_KEY }}
          ips: ${{ secrets.SERVER_IP }}
          allowed_ips: ${{ secrets.WIREGUARD_ALLOWED_IPS }}
          private_key: ${{ secrets.WIREGUARD_PRIVATE_KEY }}
      - name: Deploy to server
        # don't run locally
        if: ${{ !env.ACT }}
        uses: appleboy/ssh-action@master
        with:
          host: ${{ secrets.SERVER_IP }}
          username: ${{ secrets.SERVER_USERNAME }}
          key: ${{ secrets.SERVER_PRIVATE_KEY }}
          port: ${{ secrets.DEPLOY_PORT }}
          script: |
            cd ${{ secrets.PROJECT_PATH }}
            git pull ${{secrets.REPO_URL}}
            docker-compose down 
            docker-compose up --build -d


Edit: I noticed an Authentication error when not using sudo reseting the ssh service: enter image description here

Edit2: I skipped PAM authentication, the restart works now but the ssh connection still doesn't.

1 Answers

I'm not sure about wire guard part, but appleboy/ssh-action@master needs key and passphrase

      - name: Deploy PROD environment images
    uses: appleboy/ssh-action@master
    if: env.CURRENT_BRANCH == 'master'
    with:
      host:       ${{ secrets.SSH_HOST_PROD }}
      port:       ${{ secrets.SSH_PORT }}
      username:   ${{ secrets.SSH_USERNAME }}
      key:        ${{ secrets.SSH_PRIVATE_KEY }}
      passphrase: ${{ secrets.SSH_PASSPHRASE }}
      script: |
        cd ${{ secrets.PROJECT_PATH }}
        git pull ${{secrets.REPO_URL}}
        docker-compose down 
        docker-compose up --build -d

and you can hide these commands into a script:

#!/bin/bash -x
git pull {LINK_TO_YOUR_REPO} && docker-compose down && docker-compose up --build -d

so that you will have:

  - name: Deploy PROD environment images
uses: appleboy/ssh-action@master
if: env.CURRENT_BRANCH == 'master'
with:
  host:       ${{ secrets.SSH_HOST_PROD }}
  port:       ${{ secrets.SSH_PORT }}
  username:   ${{ secrets.SSH_USERNAME }}
  key:        ${{ secrets.SSH_PRIVATE_KEY }}
  passphrase: ${{ secrets.SSH_PASSPHRASE }}
  script: |
    cd ${{ secrets.PROJECT_PATH }}
    ./your_script
Related