无法连接TPU-VM:ssh报错‘Network is unreachable’求解决方案
问题详情
在公司网络环境的Linux机器上尝试连接TPU虚拟机时持续失败,报错信息如下:
SSH: Attempting to connect to worker 0... ssh: connect to host 35.204.109.31 port 22: Network is unreachable Retrying: SSH command error: [/usr/bin/ssh] exited with return code [255]. ... SSH: Attempting to connect to worker 0... ssh: connect to host 35.204.109.31 port 22: Network is unreachable Retrying: SSH command error: [/usr/bin/ssh] exited with return code [255]. SSH: Attempting to connect to worker 0... ssh: connect to host 35.204.109.31 port 22: Network is unreachable ERROR: (gcloud.alpha.compute.tpus.tpu-vm.ssh) [/usr/bin/ssh] exited with return code [255].
当前使用的Google Cloud SDK版本:
Google Cloud SDK 405.0.1 alpha 2022.10.14 bq 2.0.78 bundled-python3-unix 3.9.12 core 2022.10.14 gsutil 5.14
已执行的排查操作:
- 创建TPU-VM时通过
--metadata-from-file参数配置由ssh-keygen -t rsa -b 2048 -C "usrname_gmail_com"生成的公钥文件 - 设置默认防火墙规则
allow-ssh - 修改代理配置
解决建议
排查公司网络出口限制
先用telnet 35.204.109.31 22或nc -zv 35.204.109.31 22测试连通性,确认是否是公司防火墙直接阻断了对该IP 22端口的访问。如果测试失败,需联系公司网络管理员开放对应IP和端口的访问权限,或申请使用VPN连接至Google Cloud私有网络。验证TPU-VM的网络配置
- 确认TPU-VM是否分配了公网IP:部分配置下TPU-VM仅拥有私有IP,此时需通过Cloud VPN、Cloud Interconnect或同VPC下的GCE跳板机进行访问。
- 检查VPC子网的路由和公网访问权限:确保子网已配置正确的路由规则,允许流量正常进出公网。
确认gcloud代理配置有效性
执行gcloud config list proxy查看当前代理设置,确认代理地址、端口及排除列表(若有)是否正确,避免代理拦截了对TPU IP的访问。也可临时在终端取消代理(执行unset http_proxy https_proxy)后重试ssh命令,排查是否是代理导致的问题。检查防火墙规则覆盖范围
执行gcloud compute firewall-rules describe allow-ssh查看规则详情,确认:- 规则方向为ingress,协议为tcp,端口包含22
- 目标范围覆盖TPU-VM的IP
- 来源IP包含公司网络出口IP或允许0.0.0.0/0(仅测试使用)
尝试内部IP连接或跳板机转发
若能访问Google Cloud私有网络,执行gcloud alpha compute tpus tpu-vm ssh <tpu-name> --zone <zone> --internal-ip通过内部IP连接;或先连接同VPC下的GCE实例,再从该实例中转连接TPU-VM。更新gcloud组件版本
当前使用的gcloud版本为2022年10月的旧版本,可能存在TPU-VM连接的已知问题。执行gcloud components update升级到最新版本后重试连接操作。
内容的提问来源于stack exchange,提问作者heyoma

