# Loading the jenkins shared library shows known host error

**URL:** <https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986>\
**Category:** Ask a question\
**Tags:** question\
**Created:** [December 16, 2022, 7:45am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986 "2022-12-16T07:45:44Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [December 16, 2022, 7:45am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/1 "2022-12-16T07:45:44Z")

</div>

Hi,

I am using the jenkins/jenkins:2.375.1-lts-jdk11 image as my jenkins instance. When I am using shared library, it gives me this:

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/a/a3b0e4841eca2d8f8e03f089d0848b45475768d4.png)

After I ran git clone xxxx.git, typed yes and saved the known host inside the container and the host, it could pull the code but still gives me this notification.

BR  
longkang

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [December 19, 2022, 3:45am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/2 "2022-12-19T03:45:01Z")

</div>

Is there anyone who can help?

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [January 5, 2023, 8:08am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/3 "2023-01-05T08:08:45Z")

</div>

Hi @longkang 👋

Are you using `docker-compose` or a simple `docker` command?  
What are your volumes?

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [January 9, 2023, 7:23am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/4 "2023-01-09T07:23:30Z")

</div>

Hi @poddingue

Thanks for your reply, I am using docker compose and this is my compose file:

version: ‘3’  
services:  
jenkins:  
image: jenkins/jenkins:2.375.1-lts-jdk11  
user : root  
volumes:  
- /etc/localtime:/etc/localtime:ro  
- /etc/timezone/timezone:/etc/timezone:ro  
- /home/jenkins\_home:/var/jenkins\_home  
- /var/run/docker.sock:/var/run/docker.sock  
ports:  
- 8080:8080  
- 50000:50000  
restart: always  
privileged: true  
environment:  
- “JENKINS\_JAVA\_OPTS=-Xmx8g -Xms8g”

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [January 9, 2023, 9:08am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/5 "2023-01-09T09:08:48Z")

</div>

Thanks @longkang .

Where is your agent, and how is it defined?  
Is it the agent which is bundled with the controller?

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [January 10, 2023, 2:18am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/6 "2023-01-10T02:18:26Z")

</div>

Hi @poddingue

This is the configuration of my agent:

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/9/9332cb599d5466f147cc51ef414c6ddc1b1ac2d3.png)  
 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/7/7c23ec77f99419202fa25b02fec4281ad51afdae.png)  
 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/7/7ac7f7e23d3223e466730633f00860e9b64fb359.png)

And I am not quite sure what this “Is it the agent which is bundled with the controller?” means…Sorry about that.

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [January 10, 2023, 7:15am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/7 "2023-01-10T07:15:56Z")

</div>

> [@longkang](#):
>
> bundled with the controller

“is it the Built-In Node?” is probably a better description

In this case it looks like no, its 33.168

I can’t cite anything because you used a screenshot instead of code, but the bluetext in your screenshot tells you whats going on.

(agent or Controller, but i don’t think agent is assigned yet) first tries to get branches/tags/etc from the remote, but known\_hosts (either $HOME/.ssh/known-hosts or /etc/ssh/known\_hosts) doesn’t exist on the controller.

You either want to have that file populated properly (ssh-keyscan will work), or as the error message says, setup host keys globally.

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [January 10, 2023, 8:21am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/8 "2023-01-10T08:21:32Z")

</div>

Hi @halkeye

Sorry about the screen shoots.

Same here I think the blue text part had not reached the agent part and it happened on the mast node( or controller). So I tried to get the ssh keys and known hosts ready both in the host and container.

Which now you can see I could clone/pull the code locally:

on container:  
root@4295fae0bd74:~# git clone ssh://git@192.168.111.48:23/roger/pipelines.git  
Cloning into ‘pipelines’…  
remote: Enumerating objects: 15701, done.  
remote: Counting objects: 100% (196/196), done.  
remote: Compressing objects: 100% (82/82), done.  
remote: Total 15701 (delta 93), reused 184 (delta 81), pack-reused 15505  
Receiving objects: 100% (15701/15701), 1.75 MiB | 2.87 MiB/s, done.  
Resolving deltas: 100% (8752/8752), done.  
root@4295fae0bd74:~# cd .ssh/  
root@4295fae0bd74:~/.ssh# ls  
authorized\_keys id\_rsa id\_rsa.pub id\_rsa.pub\_back id\_rsa\_back known\_hosts pipelines

on host:  
[root@localhost ~]# git clone ssh://git@192.168.111.48:23/roger/pipelines.git  
Cloning into ‘pipelines’…  
remote: Enumerating objects: 15701, done.  
remote: Counting objects: 100% (196/196), done.  
remote: Compressing objects: 100% (82/82), done.  
remote: Total 15701 (delta 93), reused 184 (delta 81), pack-reused 15505  
Receiving objects: 100% (15701/15701), 1.75 MiB | 937.00 KiB/s, done.  
Resolving deltas: 100% (8752/8752), done.  
[root@localhost ~]# cd .ssh/  
[root@localhost .ssh]# ls  
authorized\_keys id\_rsa id\_rsa\_back id\_rsa.pub id\_rsa.pub\_back known\_hosts pipelines

After this, I restarted Jenkins but I still got the same error.

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [January 10, 2023, 8:39am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/9 "2023-01-10T08:39:13Z")

</div>

How certain are you that jenkins is running as root?

I would check your assumptions on the system info page. Or configure it globally inside jenkins

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [January 10, 2023, 8:51am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/10 "2023-01-10T08:51:01Z")

</div>

OH! I forgot. Not sure about the user part but I remembered it run as the jenkins user? So do I need to create a user named ‘jenkins’ and then set up the known host and ssh key then give it a try?

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [January 10, 2023, 8:54am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/11 "2023-01-10T08:54:38Z")

</div>

I tried to assign the controller’s label as master, and run ‘whoami’.

this is the output:  
Started by user [roger](http://192.168.39.12:8080/user/roger) Replayed [#63](http://192.168.39.12:8080/job/simulator-setup/63/) [Pipeline] Start of Pipeline [Pipeline] node Running on [Jenkins](http://192.168.39.12:8080/manage/computer/(built-in)/) in /var/jenkins\_home/workspace/simulator-setup [Pipeline] { [Pipeline] sh + whoami root [Pipeline] } [Pipeline] // node [Pipeline] End of Pipeline Finished: SUCCESS

![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/9/96911acf9a5b39981287b602b0874c85740acdfc.png)

---

<div class="post-metadata">

**Author:** ![longkang](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@longkang](https://community.jenkins.io/u/longkang)\
**Post date:** [January 10, 2023, 9:03am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/12 "2023-01-10T09:03:19Z")

</div>

Hi @halkeye

Sorry, I missed your point, I am not sure which part of the info you want to confirm… So here is all of it:

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/4/459036afb106900a4b72b688e9d6b348d8668232.png)  
 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/2/2434f8f81eed0744654af20396a571b7028a61b7.png)

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/4/4d1009e605bd329b18cb9b6ae772a09f3910bce1.png)  
 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/9/98f2ca3becc5c65156dc31711b4b59ab6378b397.png)  
 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/8/8cf82b010dcbb5df8d00f18a6ecfbb752a462ea3.png)

I think at least you don’t want to see the plugins part. So no more pics…

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [January 10, 2023, 11:08pm UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/13 "2023-01-10T23:08:16Z")

</div>

it does say user.home is /root, and user.name is root, so its probably needing the known hosts on the agent, not the controller.

@MarkEWaite probably knows more.

I again suggest setting up the known hosts config in your global manage jenkins settings, instead of depending on whatever your agent is setup. Makes it easier to add and remove agents.

---

<div class="post-metadata">

**Author:** ![MarkEWaite](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/markewaite/32/20_2.png) [@MarkEWaite](https://community.jenkins.io/u/MarkEWaite)\
**Post date:** [January 11, 2023, 1:14am UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/14 "2023-01-11T01:14:58Z")

</div>

Running the Jenkins controller as the root user is a disaster waiting to happen. Don’t do that. Run the Jenkins controller as a normal user or as a service user so that your system cannot be destroyed by a mistake in a Jenkins job.

Don’t allow jobs to run on the Jenkins controller. That is also a disaster waiting to happen.

The combination of allowing jobs on the controller and running as the root user means that if a job made the mistake of running `rm -rf /` your system would be destroyed.

There are a few different solutions to the message about host keys.

If you’re running on an operating system with OpenSSH 7.6 or newer (FreeBSD, macOS, any supported Linux except CentOS 7), then you can configure the git plugin security settings to “Accept first connection” strategy for the “Git Host Key Verification Configuration” in the “Configure Global Security” settings.

If you’re running CentOS 7 or one of its derivatives, I recommend an operating system upgrade. If that’s not possible, then see the [git client plugin documentation](https://plugins.jenkins.io/git-client/#plugin-content-ssh-host-key-verification) for other alternatives.

If you want to define the contents of your own known\_hosts file, you are welcome to do that as well. Here are the host keys for some common git providers:

```auto
bitbucket.org ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAubiN81eDcafrgMeLzaFPsw2kNvEcqTKl/VqLat/MaB33pZy0y3rJZtnqwR2qOOvbwKZYKiEO1O6VqNEBxKvJJelCq0dTXWT5pbO2gDXC6h6QDXCaHo6pOHGPUy+YBaGQRGuSusMEASYiWunYN0vCAI8QaXnWMXNMdFP3jHAJH0eDsoiGnLPBlBp4TNm6rYI74nMzgz3B9IikW4WVK+dc8KZJZWYjAuORU3jc1c/NPskD2ASinf8v3xnfXeukU0sJ5N6m5E8VLjObPEO+mN2t/FZTMZLiFqPWc/ALSqnMnnhwrNi2rbfg/rd/IpL8Le3pSBne8+seeFVBoGqzHM9yXw==
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
github.com ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAq2A7hRGmdnm9tUDbO9IDSwBK6TbQa+PXYPCPy6rbTrTtw7PHkccKrpp0yVhp5HdEIcKr6pLlVDBfOLX9QUsyCOV0wzfjIJNlGEYsdlLJizHhbn2mUjvSAHQqZETYP81eFzLQNnPHt4EVVUh7VfDESU84KezmD5QlWpXLmvU31/yMf+Se8xhHTvKSCZIFImWwoG6mbUoWf9nzpIoaSjB+weqqUUmpaaasXVal72J+UX2B+2RPW3RcT0eOzQgqlJL3RKrTJvdsjE3JEAvGq3lGHSZXy28G3skua2SmVi/w4yCE6gbODqnTWlg7+wC604ydGXA8VJiS5ap43JXiUFFAaQ==
gitlab.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFSMqzJeV9rUzU4kWitGjeR4PWSa29SPqJ1fVkhtj3Hw9xjLVXVYrU9QlYWrOLXBpQ6KWjbjTDTdDkoohFzgbEY=
gitlab.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAfuCHKVTjquxvt6CM6tdG4SLp1Btn/nOeHHE5UOzRdf
vs-ssh.visualstudio.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7Hr1oTWqNqOlzGJOfGJ4NakVyIzf1rXYd4d7wo6jBlkLvCA4odBlL0mDUyZ0/QUfTTqeu+tm22gOsv+VrVTMk6vwRU75gY/y9ut5Mb3bR5BV58dKXyq9A9UeB5Cakehn5Zgm6x1mKoVyf+FFn26iYqXJRgzIZZcZ5V6hrE0Qg39kZm4az48o0AUbf6Sp4SLdvnuMa2sVNwHBboS7EJkm57XQPVU3/QpyNLHbWDdzwtrlS+ez30S3AdYhLKEOxAG8weOnyrtLJAUen9mTkol8oII1edf7mWWbWVf0nBmly21+nZcmCTISQBtdcyPaEno7fFQMDD26/s0lfKob4Kw8H

```

---

<div class="post-metadata">

**Author:** ![rakibulinux](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/rakibulinux/32/7260_2.png) [@rakibulinux](https://community.jenkins.io/u/rakibulinux)\
**Post date:** [March 3, 2024, 1:12pm UTC](https://community.jenkins.io/t/loading-the-jenkins-shared-library-shows-known-host-error/4986/15 "2024-03-03T13:12:53Z")

</div>

I’m following these steps to make it work

`curl -L https://api.github.com/meta | jq -r '.ssh_keys | .[]' | sed -e 's/^/github.com /' >> ~/.ssh/known_hosts`

Next, verify that `/var/lib/jenkins/.ssh` exists. If it doesn’t, then create it like this:

```auto
# create directory
sudo mkdir /var/lib/jenkins/.ssh

# ensure the directory is owned by the Jenkins user
chown -R jenkins:jenkins /var/lib/.ssh

```

Copy your `known_hosts` file over:

`sudo cp ~/.ssh/known_hosts /var/lib/jenkins/.ssh`

At this point, your Jenkins pipeline job has access to the new `known_hosts` file so you should be able to run it without any problem.
