Common causes
- No SSH key exists on this machine or server (common on a new cPanel account or VPS)
- A key exists but its public half was never added to your account or as a deploy key
- SSH offers the wrong key because the key has a non-default name and ~/.ssh/config does not point to it
- The private key file has loose permissions, so SSH refuses to use it
- Running git with sudo or as a different user (cron, www-data, deploy) that has its own empty ~/.ssh
- The deploy key is attached to a different repository, or is read-only and you are pushing
How to fix it
- Test the connection. Run ssh -T [email protected] (or [email protected]). Success prints 'Hi username! You've successfully authenticated'. Add -v to see which key files are tried.
- Create a key if there is none. Run ssh-keygen -t ed25519 -C "[email protected]" and accept the default path ~/.ssh/id_ed25519. On cPanel you can also use SSH Access > Manage SSH Keys.
- Add the public key to the host. Copy the contents of ~/.ssh/id_ed25519.pub (never the private file) to GitHub Settings > SSH and GPG keys, or to the repository's Deploy keys for a server; tick 'Allow write access' only if the server must push.
- Point SSH at the right key. If the key has a custom name, add a Host block in ~/.ssh/config with IdentityFile and IdentitiesOnly yes, or load it with ssh-add ~/.ssh/mykey.
- Fix file permissions. Run chmod 700 ~/.ssh and chmod 600 ~/.ssh/id_ed25519; SSH ignores private keys other users can read.
- Run git as the right user. Do not use sudo git. For cron or deploy scripts, set up the key under the account that runs them, or check the remote with git remote -v in case it should use HTTPS with a token.
~/.ssh/config
Host github.com
HostName github.com
User git
IdentityFile ~/.ssh/id_ed25519_site
IdentitiesOnly yes How to stop it happening again
- Use one deploy key per server and repository, read-only unless pushing is required
- Keep ~/.ssh at 700 and private keys at 600, and protect personal keys with a passphrase
- Document which system user runs deploys and keep its key in that user's ~/.ssh