Jenkins通过SSH插件连接AWS EC2实例失败的问题排查与解决咨询
Hey there! Let's walk through the common pitfalls and fixes for getting Jenkins' SSH plugin connected to your AWS EC2 instance—since you already added credentials, there are a few key areas to check:
1. Verify EC2 Instance Security Group Rules
- Make sure your security group allows inbound SSH (port 22) from your Jenkins server's public IP address. Don't just open it to
0.0.0.0/0unless it's a test environment—lock it down to the Jenkins instance's specific IP to keep things secure. - Double-check outbound rules allow basic traffic flow (though this is less likely to block the initial SSH connection, it's worth confirming no strict outbound restrictions are in place).
2. Validate Jenkins SSH Credential Setup
- Confirm you're using the right credential type: If you're using an EC2 key pair, select SSH Username with private key instead of a password credential.
- When pasting your private key, ensure you include the entire block—from
-----BEGIN RSA PRIVATE KEY-----all the way to-----END RSA PRIVATE KEY-----. Missing even a single character or extra whitespace will break authentication. - Match the username to your EC2 AMI's default user: For Amazon Linux 2 it's
ec2-user, Ubuntu usesubuntu, RHEL typically usesec2-userorroot(depending on your setup). Using the wrong username will fail the connection instantly.
3. Test Manual SSH from Jenkins Server
- Log into your Jenkins server's terminal and try connecting to the EC2 instance directly with the same credentials:
If this manual connection fails, the issue is outside Jenkins—fix that first (e.g., network issues, key permissions) before troubleshooting the plugin.ssh -i /path/to/your/private-key.pem username@ec2-public-ip-or-dns - If manual SSH works but Jenkins doesn't, check if the Jenkins system user (usually
jenkins) has access to the private key file (if you're using a file-based key instead of pasting it into credentials). Runsudo chmod 600 /path/to/key.pemandsudo chown jenkins:jenkins /path/to/key.pemto set proper permissions.
4. Check EC2 Instance's SSH Daemon Config
- Log into your EC2 instance and verify SSH daemon settings:
- Edit
/etc/ssh/sshd_configand ensure:- For key-based auth:
PubkeyAuthentication yesis uncommented - For password auth:
PasswordAuthentication yesis uncommented (only if you're using password credentials)
- For key-based auth:
- Restart the SSH service to apply changes:
# For systemd-based distros (Amazon Linux 2, Ubuntu 18.04+) sudo systemctl restart sshd # For older init-based distros sudo service ssh restart
- Edit
- Also, confirm your public key is present in the target user's
~/.ssh/authorized_keysfile (for key-based auth).
5. Jenkins SSH Plugin Specific Checks
- In the plugin's remote host configuration, double-check that you've selected the correct credential from the dropdown—sometimes credentials can be mislabeled, so verify the username/key matches what you tested manually.
- Enable verbose logging to get detailed failure info:
- Go to Manage Jenkins > System Log > Add new log recorder
- Add
com.cloudbees.jenkins.plugins.sshwith log levelFINEST - Run your job again and check the logs—they'll show exactly where the connection fails (authentication timeout, permission denied, etc.)
Work through these steps one by one, and you should be able to pinpoint the missing piece!
内容的提问来源于stack exchange,提问作者Sunita Muneshwar
相关产品推荐
相关产品推荐

