You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Packer创建的Azure镜像部署VMSS后无法SSH登录问题求助

Troubleshooting SSH Permission Denied for Packer-Built Azure Images in VMSS

Let's break down why you're hitting this Permission denied (publickey,gssapi-keyex,gssapi-with-mic) error, and walk through actionable fixes. The key clue here is that even a plain CentOS image built by Packer fails SSH, so the issue lies in how Packer interacts with Azure's Linux image lifecycle, not your Ansible provisioning.

Common Root Causes

  1. Azure Linux Agent (waagent) misconfiguration: Packer's build process might override settings that let Azure inject SSH keys into VMSS instances.
  2. SSHD configuration changes: Packer's temporary SSH setup during build could disable public key auth accidentally.
  3. Missing or misconfigured admin user: Custom images don't auto-create users like Azure's marketplace images do, so your VMSS-specified user might not exist or have incorrect permissions.

Step-by-Step Fixes

1. Fix Packer Builder SSH User Configuration

OpenLogic's CentOS 7.3 images use centos as the default SSH user. Packer might create a temporary user if you don't specify this, leading to cleanup that breaks SSH for future deployments. Update your Packer builder config:

"builders": [{
  "type": "azure-arm",
  // ... existing config ...
  "ssh_username": "centos", // Match the base image's default user
  // Optional: Use your own private key instead of Packer generating one
  // "ssh_private_key_file": "~/.ssh/id_rsa",
  // ... existing config ...
}]

2. Ensure Azure Linux Agent (waagent) Works for VMSS Provisioning

The waagent handles SSH key injection for Azure VMs/VMSS. Add a shell provisioner to your Packer config to reset critical settings:

"provisioners": [
  {
    "type": "shell",
    "inline": [
      # Enable provisioning to let Azure inject keys
      "sudo sed -i 's/Provisioning=n/Provisioning=y/' /etc/waagent.conf",
      # Disable cloud-init conflict (use waagent instead)
      "sudo sed -i 's/ProvisioningUseCloudInit=y/ProvisioningUseCloudInit=n/' /etc/waagent.conf",
      # Enforce key-based auth
      "sudo sed -i 's/PasswordAuthentication=y/PasswordAuthentication=n/' /etc/waagent.conf",
      "sudo sed -i 's/SSHPublicKey=n/SSHPublicKey=y/' /etc/waagent.conf",
      # Restart agent to apply changes
      "sudo systemctl restart waagent"
    ]
  },
  // ... your existing Ansible provisioner ...
]

3. Verify SSHD Public Key Auth is Enabled

Packer's build process might accidentally disable public key auth. Add another shell provisioner to fix sshd_config:

"provisioners": [
  {
    "type": "shell",
    "inline": [
      # Enable public key auth if commented/disabled
      "sudo sed -i 's/^#PubkeyAuthentication/PubkeyAuthentication/' /etc/ssh/sshd_config",
      "sudo sed -i 's/PubkeyAuthentication no/PubkeyAuthentication yes/' /etc/ssh/sshd_config",
      # Ensure authorized keys file path is correct
      "sudo sed -i 's/^#AuthorizedKeysFile/AuthorizedKeysFile/' /etc/ssh/sshd_config",
      # Restart SSH service
      "sudo systemctl restart sshd"
    ]
  },
  // ... other provisioners ...
]

4. Pre-Create Your VMSS Admin User in the Packer Image

Azure won't auto-create users in custom images. Add a shell provisioner to create the someuser account your Terraform config uses, with correct permissions:

"provisioners": [
  {
    "type": "shell",
    "inline": [
      # Create the admin user with a home directory
      "sudo useradd -m someuser",
      # Grant sudo access (optional but useful)
      "sudo usermod -aG wheel someuser",
      # Set up SSH directory with correct permissions
      "sudo mkdir -p /home/someuser/.ssh",
      "sudo chmod 700 /home/someuser/.ssh",
      "sudo touch /home/someuser/.ssh/authorized_keys",
      "sudo chmod 600 /home/someuser/.ssh/authorized_keys",
      "sudo chown -R someuser:someuser /home/someuser/.ssh"
    ]
  },
  // ... other provisioners ...
]

5. Validate the Fix

  1. Rebuild your image with the updated Packer config.
  2. First, deploy a single VM (not VMSS) from the new image to test SSH access directly. This confirms the image itself is working.
  3. If the single VM works, redeploy your VMSS with Terraform—SSH should now connect successfully.

内容的提问来源于stack exchange,提问作者Kostas Demiris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 16:39:05