使用Packer创建的Azure镜像部署VMSS后无法SSH登录问题求助
Let's break down why you're hitting this Permission denied (publickey,gssapi-keyex,gssapi-with-mic) error, and walk through actionable fixes. The key clue here is that even a plain CentOS image built by Packer fails SSH, so the issue lies in how Packer interacts with Azure's Linux image lifecycle, not your Ansible provisioning.
Common Root Causes
- Azure Linux Agent (waagent) misconfiguration: Packer's build process might override settings that let Azure inject SSH keys into VMSS instances.
- SSHD configuration changes: Packer's temporary SSH setup during build could disable public key auth accidentally.
- Missing or misconfigured admin user: Custom images don't auto-create users like Azure's marketplace images do, so your VMSS-specified user might not exist or have incorrect permissions.
Step-by-Step Fixes
1. Fix Packer Builder SSH User Configuration
OpenLogic's CentOS 7.3 images use centos as the default SSH user. Packer might create a temporary user if you don't specify this, leading to cleanup that breaks SSH for future deployments. Update your Packer builder config:
"builders": [{ "type": "azure-arm", // ... existing config ... "ssh_username": "centos", // Match the base image's default user // Optional: Use your own private key instead of Packer generating one // "ssh_private_key_file": "~/.ssh/id_rsa", // ... existing config ... }]
2. Ensure Azure Linux Agent (waagent) Works for VMSS Provisioning
The waagent handles SSH key injection for Azure VMs/VMSS. Add a shell provisioner to your Packer config to reset critical settings:
"provisioners": [ { "type": "shell", "inline": [ # Enable provisioning to let Azure inject keys "sudo sed -i 's/Provisioning=n/Provisioning=y/' /etc/waagent.conf", # Disable cloud-init conflict (use waagent instead) "sudo sed -i 's/ProvisioningUseCloudInit=y/ProvisioningUseCloudInit=n/' /etc/waagent.conf", # Enforce key-based auth "sudo sed -i 's/PasswordAuthentication=y/PasswordAuthentication=n/' /etc/waagent.conf", "sudo sed -i 's/SSHPublicKey=n/SSHPublicKey=y/' /etc/waagent.conf", # Restart agent to apply changes "sudo systemctl restart waagent" ] }, // ... your existing Ansible provisioner ... ]
3. Verify SSHD Public Key Auth is Enabled
Packer's build process might accidentally disable public key auth. Add another shell provisioner to fix sshd_config:
"provisioners": [ { "type": "shell", "inline": [ # Enable public key auth if commented/disabled "sudo sed -i 's/^#PubkeyAuthentication/PubkeyAuthentication/' /etc/ssh/sshd_config", "sudo sed -i 's/PubkeyAuthentication no/PubkeyAuthentication yes/' /etc/ssh/sshd_config", # Ensure authorized keys file path is correct "sudo sed -i 's/^#AuthorizedKeysFile/AuthorizedKeysFile/' /etc/ssh/sshd_config", # Restart SSH service "sudo systemctl restart sshd" ] }, // ... other provisioners ... ]
4. Pre-Create Your VMSS Admin User in the Packer Image
Azure won't auto-create users in custom images. Add a shell provisioner to create the someuser account your Terraform config uses, with correct permissions:
"provisioners": [ { "type": "shell", "inline": [ # Create the admin user with a home directory "sudo useradd -m someuser", # Grant sudo access (optional but useful) "sudo usermod -aG wheel someuser", # Set up SSH directory with correct permissions "sudo mkdir -p /home/someuser/.ssh", "sudo chmod 700 /home/someuser/.ssh", "sudo touch /home/someuser/.ssh/authorized_keys", "sudo chmod 600 /home/someuser/.ssh/authorized_keys", "sudo chown -R someuser:someuser /home/someuser/.ssh" ] }, // ... other provisioners ... ]
5. Validate the Fix
- Rebuild your image with the updated Packer config.
- First, deploy a single VM (not VMSS) from the new image to test SSH access directly. This confirms the image itself is working.
- If the single VM works, redeploy your VMSS with Terraform—SSH should now connect successfully.
内容的提问来源于stack exchange,提问作者Kostas Demiris

