如何登录AKS集群节点并进入Shell?寻求AKS节点SSH登录步骤及节点间SSH互通方法
How to Access AKS Nodes via SSH & Node-to-Node SSH Access
1. Logging into an AKS Node and Accessing Its Shell
First, you’ll need the Azure CLI installed and authenticated to your Azure account. Here’s the step-by-step breakdown:
- Authenticate with Azure: Run
az loginand follow the prompts to sign in. If you have multiple subscriptions, switch to the correct one withaz account set --subscription <your-subscription-id>. - Locate your AKS node details:
- List your node pools to get the pool name:
az aks nodepool list --resource-group <your-resource-group> --cluster-name <your-aks-cluster-name> --query "[].name" -o tsv - Grab the target node’s name and private IP:
az aks node show --resource-group <your-resource-group> --cluster-name <your-aks-cluster-name> --nodepool-name <your-nodepool-name> --name <node-name> --query "{name:name, privateIp:privateIpAddress}" -o table
- List your node pools to get the pool name:
- SSH into the node (preferred method): Use the Azure CLI’s built-in
az aks sshcommand—this works even if nodes don’t have public IPs. You’ll need the private key that matches the SSH public key you specified when creating the AKS cluster:az aks ssh --resource-group <your-resource-group> --name <your-aks-cluster-name> --node-name <node-name> --ssh-key <path-to-your-private-key-file> - Alternative: Direct SSH (if node has public IP): If your node was configured with a public IP (not recommended for production), connect directly with:
Note: The default username for all AKS nodes isssh azureuser@<node-public-ip> -i <path-to-your-private-key-file>azureuser.
2. SSH Login Steps & Node-to-Node SSH Access
SSH Login Recap
To quickly recap the core SSH workflow:
- Authenticate your Azure CLI to the correct subscription.
- Retrieve the target node’s name or private IP.
- Use
az aks ssh(best practice) or direct SSH with your private key to connect asazureuser.
Can You SSH Between AKS Nodes with ssh <user>@<node-address>?
By default, this won’t work out of the box for two key reasons:
- No SSH key trust: Nodes don’t have each other’s public keys stored in their
~/.ssh/authorized_keysfiles, so authentication will fail. - Network restrictions: While AKS nodes share the same VNet, you may need to confirm the node pool’s network security group (NSG) allows inbound SSH (port 22) traffic from other cluster nodes.
If you need to enable node-to-node SSH access, here’s how to set it up:
- Copy your SSH key to target nodes: Once logged into a node, use
ssh-copy-idto add your public key to the target node’sazureuseraccount:
You’ll need to authenticate with your private key or thessh-copy-id azureuser@<target-node-private-ip>azureuserpassword (if you set one) for this first transfer. - Verify NSG rules: Check the NSG attached to your AKS node pool and ensure there’s an inbound rule allowing port 22 traffic from the cluster’s VNet address space.
After these steps, you’ll be able to run ssh azureuser@<target-node-private-ip> from any cluster node to connect directly.
内容的提问来源于stack exchange,提问作者sanjeeth
相关产品推荐
相关产品推荐

