如何实现EC2控制节点以ec2-user身份免额外账号SSH登录其他EC2节点
Hey there! Let's walk through how to set up passwordless SSH access from your EC2 Controller instance to your nodes, using ec2-user on both ends (no extra user accounts needed). Here's the step-by-step breakdown:
1. Generate or Retrieve the Controller's SSH Public Key
First, make sure your Controller instance has an SSH keypair (if it doesn't already):
- Log into your Controller as
ec2-user, then run:
Press Enter through all prompts (no passphrase needed for passwordless access).ssh-keygen -t rsa -b 4096 - Grab the public key by running:
Copy the entire output string—you'll need this for every node.cat ~/.ssh/id_rsa.pub
2. Add the Controller's Public Key to Each Node's authorized_keys
You need to inject the Controller's public key into the ec2-user account's authorized_keys file on each node. Here are a few ways to do this:
Option A: Use ssh-copy-id (If You Can Temporarily Access the Node)
If you can already SSH into the node using its own private key, run this from the Controller:
ssh-copy-id -i ~/.ssh/id_rsa.pub -o "IdentityFile=/path/to/your-node-private-key.pem" ec2-user@<node-public-ip>
Replace /path/to/your-node-private-key.pem with the local path to the private key you use to access the node, and <node-public-ip> with the node's public IP address.
Option B: Manually Add the Key (For Nodes Without Public Access)
If your nodes don't have public IPs, use AWS Systems Manager Session Manager to connect to each node, then:
- Create the
.sshdirectory if it doesn't exist:mkdir -p ~/.ssh && chmod 700 ~/.ssh - Append the Controller's public key to
authorized_keys:echo "PASTE_THE_CONTROLLER_PUBLIC_KEY_HERE" >> ~/.ssh/authorized_keys - Set strict permissions for the file (critical for SSH to work):
chmod 600 ~/.ssh/authorized_keys && chown ec2-user:ec2-user ~/.ssh/authorized_keys
3. Verify Security Group Rules
Don't forget to update your AWS security groups:
- On your node security group: Allow inbound SSH (port 22) from your Controller's security group (or its public IP address, if you prefer).
- On your Controller security group: Allow outbound SSH (port 22) to your node security group (or 0.0.0.0/0 if you need broader access, though restricting to the node group is safer).
4. Test the Connection
From your Controller instance, run:
ssh ec2-user@<node-public-ip>
You should log into the node automatically, no password required! If your Controller's private key isn't the default id_rsa, specify it with:
ssh -i ~/.ssh/your-controller-private-key.pem ec2-user@<node-public-ip>
Troubleshooting Tips
- Connection refused: Double-check security group rules to ensure port 22 is open between Controller and nodes.
- Permission denied: Verify permissions on the node's
~/.sshdirectory (must be700) andauthorized_keys(must be600). Also ensure the Controller's private key has600permissions:chmod 600 ~/.ssh/id_rsa. - No such identity: Make sure you're pointing to the correct private key file path if using a non-default key.
内容的提问来源于stack exchange,提问作者LaR

