You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置K8s环境下OpenSSH服务的无日志污染健康探针

Kubernetes部署OpenSSH健康探针导致冗余日志解决方法

问题现象

在Kubernetes集群中部署运行OpenSSH服务,服务启动后日志立刻持续输出如下重复错误:

Server listening on 0.0.0.0 port 2022.
Server listening on :: port 2022.
kex_exchange_identification: Connection closed by remote host
Connection closed by 10.134.250.6 port 32816
kex_exchange_identification: Connection closed by remote host
Connection closed by 10.134.250.6 port 47940
kex_exchange_identification: Connection closed by remote host
Connection closed by 10.134.250.6 port 47988
kex_exchange_identification: Connection closed by remote host
Connection closed by 10.134.250.6 port 37452

经排查,上述日志由配置的livenessProbe、readinessProbe健康检查触发,当前探针配置如下:

livenessProbe:
  failureThreshold: 3
  initialDelaySeconds: 1
  periodSeconds: 10
  successThreshold: 1
  tcpSocket:
    port: ssh
  timeoutSeconds: 1

readinessProbe:
  failureThreshold: 3
  initialDelaySeconds: 1
  periodSeconds: 10
  successThreshold: 1
  tcpSocket:
    port: ssh
  timeoutSeconds: 1

当前SSH服务启动命令为:

/usr/bin/sshd -D -e

问题原因

当前使用的tcpSocket类型探针仅会完成TCP三次握手验证端口存活,连接建立成功后会直接主动断开,不会走后续SSH协议的密钥交换握手流程。sshd收到这类未完成完整握手就断开的连接时,默认会输出kex_exchange_identification: Connection closed by remote host类提示;加上启动参数里的*-e*配置会让sshd把所有日志直接输出到标准错误流,正好被容器日志采集组件收集,最终造成冗余日志持续刷屏。

可行调整方案

可以根据自身日志需求二选一:

  • 方案1:替换探针类型为exec探针,避免异常连接触发日志
    将原有TCP探针替换为exec类型探针,在容器内主动发起完整的本地SSH校验,不会触发半连接断开的日志。如果镜像内自带ssh客户端,可以参考如下配置:
    livenessProbe:
      failureThreshold: 3
      initialDelaySeconds: 2
      periodSeconds: 10
      successThreshold: 1
      exec:
        command:
        - ssh
        - -o
        - ConnectTimeout=1
        - -o
        - StrictHostKeyChecking=no
        - -p
        - "2022"
        - localhost
        - exit
      timeoutSeconds: 2
    
    readinessProbe:
      failureThreshold: 3
      initialDelaySeconds: 2
      periodSeconds: 10
      successThreshold: 1
      exec:
        command:
        - ssh
        - -o
        - ConnectTimeout=1
        - -o
        - StrictHostKeyChecking=no
        - -p
        - "2022"
        - localhost
        - exit
      timeoutSeconds: 2
    
    如果镜像没有ssh客户端,也可以用netcat等轻量工具做端口检测后主动正常断开连接,注意匹配对应镜像内工具的参数即可。
  • 方案2:调整sshd日志级别,过滤低优先级日志
    这个方案改动最小,不需要调整探针配置,只需要修改sshd启动参数,将日志级别从默认的INFO调整为ERROR,就不会再输出这类半连接断开的提示信息,修改后的启动命令如下:
    /usr/bin/sshd -D -e -l ERROR
    
    注意:该方案会同时过滤掉所有INFO级别的sshd日志,包括普通用户登录连接的审计日志,如果有安全审计需求优先选择方案1。

内容的提问来源于stack exchange,提问作者user5580578

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 21:09:34