如何在AKS集群节点上配置持久化SSH访问?
Great question—this is exactly what AKS's Node Pool Custom Data feature is designed for. It lets you run initialization scripts during node provisioning, just like AWS user data in launch templates, so you don't need to rely on DaemonSets for this setup. Let's walk through the steps:
Step 1: Write Your SSH Configuration Script
First, create a bash script that configures the SSH access you need. For example, this script adds your public SSH key to the default azureuser account's authorized keys (the standard admin user on AKS nodes):
#!/bin/bash # Create .ssh directory if it doesn't exist mkdir -p /home/azureuser/.ssh # Add your public SSH key to authorized_keys echo "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQ..." >> /home/azureuser/.ssh/authorized_keys # Set correct permissions (critical for SSH to work) chown -R azureuser:azureuser /home/azureuser/.ssh chmod 700 /home/azureuser/.ssh chmod 600 /home/azureuser/.ssh/authorized_keys # Optional: Tweak SSH daemon settings if needed (e.g., enable password auth) # sed -i 's/PasswordAuthentication no/PasswordAuthentication yes/' /etc/ssh/sshd_config # systemctl restart sshd
Save this as ssh-setup.sh—make sure to replace the example public key with your actual one.
Step 2: Inject the Script When Creating/Updating a Node Pool
When creating a new node pool, use the --custom-data flag in the Azure CLI to pass your script. The CLI automatically handles base64 encoding (which Azure requires for custom data) if you reference the file with @:
az aks nodepool create \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name myCustomNodePool \ --node-count 2 \ --custom-data @ssh-setup.sh
If you have an existing node pool, keep in mind custom data only applies to new nodes. To apply it to existing nodes, you'll need to reimage them (this will replace the node with a fresh one running your script):
# Reimage a specific node (replace the node name with your actual node's name) az aks nodepool reimage \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name myCustomNodePool \ --node-name aks-mycustomnodepool-12345678-vmss000000
Step 3: Verify the Setup
Once the node is provisioned, grab its public IP (from the Azure Portal or by running az vmss list-instances on the node pool's VM scale set) and test SSH access:
ssh azureuser@<node-public-ip> -i /path/to/your/private-key.pem
You should be able to connect without issues, and the access will persist across node reboots since the changes are saved to the node's filesystem.
Important Notes
- The custom data script runs as
root, so you don't needsudocommands in your script. - This approach is one-time during node initialization—if you need to update the SSH config later, you'll have to reimage nodes or run the script manually on existing ones.
- Don't store sensitive data directly in the script; if you need secrets, consider using Azure Key Vault to retrieve them during initialization.
内容的提问来源于stack exchange,提问作者KernelPanic1978

