Repository navigation
fix(claude-code): install openssh-client for SSH-format commit signing - #111
Merged
Merged
Conversation
The shared `base` stage installs packages with --no-install-recommends,
which drops git's Recommends on ssh-client (provided by openssh-client).
The image therefore ships without ssh-keygen, so any container whose
gitconfig uses SSH-format commit signing (gpg.format=ssh +
commit.gpgsign=true, commonly copied in by VS Code's
dev.containers.copyGitConfig) fails to commit:
error: cannot run ssh-keygen: No such file or directory
Add openssh-client to the base apt block so both the default and sandbox
targets get ssh-keygen/ssh/ssh-add. It must live in base: the sandbox
firewall blocks deb.debian.org, so it can't be apt-installed at runtime
(same reasoning as chromium). openssh-client hard-depends on libfido2, so
FIDO2 hardware keys (YubiKey sk-ssh-ed25519) sign too, even under
--no-install-recommends.
Closes #110
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
claude-codebase image ships withoutopenssh-client, sossh-keygenisabsent and any container using SSH-format commit signing (
gpg.format=ssh+commit.gpgsign=true) fails to commit witherror: cannot run ssh-keygen: No such file or directory. This is commonlytriggered by VS Code's
dev.containers.copyGitConfig, which copies the hostsigning config into the container.
Root cause: the shared
baseapt block uses--no-install-recommends, whichdrops git's Recommends on
ssh-client(provided byopenssh-client).Fix
Add
openssh-clientto the sharedbasestage apt block, so both thedefaultand
sandboxtargets getssh-keygen/ssh/ssh-addin one place.base: the sandbox firewall blocksdeb.debian.org, so itcan't be apt-installed at runtime (same reasoning already documented for
chromium).openssh-clienthard-Depends onlibfido2-1, so FIDO2 hardware keys(YubiKey
sk-ssh-ed25519) sign too — this holds even under--no-install-recommends.Verification
openssh-clientprovides/usr/bin/ssh-keygen,/usr/bin/ssh,/usr/bin/ssh-add;libfido2-1 (>= 1.8.0)is a hard
Depends, not a Recommends..hadolint.yaml.Closes #110