You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何登录AKS集群节点并进入Shell?寻求AKS节点SSH登录步骤及节点间SSH互通方法

How to Access AKS Nodes via SSH & Node-to-Node SSH Access

1. Logging into an AKS Node and Accessing Its Shell

First, you’ll need the Azure CLI installed and authenticated to your Azure account. Here’s the step-by-step breakdown:

  • Authenticate with Azure: Run az login and follow the prompts to sign in. If you have multiple subscriptions, switch to the correct one with az account set --subscription <your-subscription-id>.
  • Locate your AKS node details:
    • List your node pools to get the pool name: az aks nodepool list --resource-group <your-resource-group> --cluster-name <your-aks-cluster-name> --query "[].name" -o tsv
    • Grab the target node’s name and private IP: az aks node show --resource-group <your-resource-group> --cluster-name <your-aks-cluster-name> --nodepool-name <your-nodepool-name> --name <node-name> --query "{name:name, privateIp:privateIpAddress}" -o table
  • SSH into the node (preferred method): Use the Azure CLI’s built-in az aks ssh command—this works even if nodes don’t have public IPs. You’ll need the private key that matches the SSH public key you specified when creating the AKS cluster:
    az aks ssh --resource-group <your-resource-group> --name <your-aks-cluster-name> --node-name <node-name> --ssh-key <path-to-your-private-key-file>
    
  • Alternative: Direct SSH (if node has public IP): If your node was configured with a public IP (not recommended for production), connect directly with:
    ssh azureuser@<node-public-ip> -i <path-to-your-private-key-file>
    
    Note: The default username for all AKS nodes is azureuser.

2. SSH Login Steps & Node-to-Node SSH Access

SSH Login Recap

To quickly recap the core SSH workflow:

  1. Authenticate your Azure CLI to the correct subscription.
  2. Retrieve the target node’s name or private IP.
  3. Use az aks ssh (best practice) or direct SSH with your private key to connect as azureuser.

Can You SSH Between AKS Nodes with ssh <user>@<node-address>?

By default, this won’t work out of the box for two key reasons:

  1. No SSH key trust: Nodes don’t have each other’s public keys stored in their ~/.ssh/authorized_keys files, so authentication will fail.
  2. Network restrictions: While AKS nodes share the same VNet, you may need to confirm the node pool’s network security group (NSG) allows inbound SSH (port 22) traffic from other cluster nodes.

If you need to enable node-to-node SSH access, here’s how to set it up:

  • Copy your SSH key to target nodes: Once logged into a node, use ssh-copy-id to add your public key to the target node’s azureuser account:
    ssh-copy-id azureuser@<target-node-private-ip>
    
    You’ll need to authenticate with your private key or the azureuser password (if you set one) for this first transfer.
  • Verify NSG rules: Check the NSG attached to your AKS node pool and ensure there’s an inbound rule allowing port 22 traffic from the cluster’s VNet address space.

After these steps, you’ll be able to run ssh azureuser@<target-node-private-ip> from any cluster node to connect directly.


内容的提问来源于stack exchange,提问作者sanjeeth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 19:17:33