Skip to content

fix(claude-code): install openssh-client for SSH-format commit signing - #111

Merged
gatezh merged 1 commit into
masterfrom
fix/110-openssh-client-ssh-signing
Jun 8, 2026
Merged

gatezh merged 1 commit into
masterfrom
fix/110-openssh-client-ssh-signing

Conversation

@gatezh

@gatezh gatezh commented Jun 8, 2026

Copy link
Copy Markdown
Owner

Summary

The claude-code base image ships without openssh-client, so ssh-keygen is
absent and any container using SSH-format commit signing (gpg.format=ssh +
commit.gpgsign=true) fails to commit with
error: cannot run ssh-keygen: No such file or directory. This is commonly
triggered by VS Code's dev.containers.copyGitConfig, which copies the host
signing config into the container.

Root cause: the shared base apt block uses --no-install-recommends, which
drops git's Recommends on ssh-client (provided by openssh-client).

Fix

Add openssh-client to the shared base stage apt block, so both the default
and sandbox targets get ssh-keygen/ssh/ssh-add in one place.

  • Must be in base: the sandbox firewall blocks deb.debian.org, so it
    can't be apt-installed at runtime (same reasoning already documented for
    chromium).
  • openssh-client hard-Depends on libfido2-1, so FIDO2 hardware keys
    (YubiKey sk-ssh-ed25519) sign too — this holds even under
    --no-install-recommends.

Verification

  • Confirmed against packages.debian.org (trixie): openssh-client provides
    /usr/bin/ssh-keygen, /usr/bin/ssh, /usr/bin/ssh-add; libfido2-1 (>= 1.8.0)
    is a hard Depends, not a Recommends.
  • Hadolint clean against the project's .hadolint.yaml.

Closes #110

The shared `base` stage installs packages with --no-install-recommends,
which drops git's Recommends on ssh-client (provided by openssh-client).
The image therefore ships without ssh-keygen, so any container whose
gitconfig uses SSH-format commit signing (gpg.format=ssh +
commit.gpgsign=true, commonly copied in by VS Code's
dev.containers.copyGitConfig) fails to commit:

    error: cannot run ssh-keygen: No such file or directory

Add openssh-client to the base apt block so both the default and sandbox
targets get ssh-keygen/ssh/ssh-add. It must live in base: the sandbox
firewall blocks deb.debian.org, so it can't be apt-installed at runtime
(same reasoning as chromium). openssh-client hard-depends on libfido2, so
FIDO2 hardware keys (YubiKey sk-ssh-ed25519) sign too, even under
--no-install-recommends.

Closes #110
@gatezh
gatezh merged commit 3819277 into master Jun 8, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

claude-code image missing openssh-client breaks SSH-format commit signing

1 participant