Rancher创建Azure CentOS节点池失败:等待SSH可用超时
Hey there, sorry to hear you're stuck with this Rancher Node Pool deployment issue. Let's break down the problem and walk through some targeted troubleshooting steps based on your Azure environment details.
Your Setup Recap
First, let's confirm what you're working with to make sure we're aligned:
- VPN CIDR:
192.168.0.0/16 - Rancher server VM: RancherOS running
rancher/server:preview(subnet192.168.2.0/29) - Node Pool VMs: CentOS, in subnet
192.168.0.0/24 - Error: Rancher retries 60 times to establish SSH to the Node Pool VMs before timing out with
Waiting for SSH to be available…
Troubleshooting Steps to Try
1. Test Direct SSH from Rancher VM to Node Pool VM
First, let's rule out basic connectivity issues. Log into your Rancher VM via SSH, then:
- Grab the private IP of one of your Node Pool VMs from the Azure Portal.
- Try pinging it:
ping <node-private-ip>. If this fails, you've got a network routing or NSG block. - If ping works, test SSH directly with the key you provided to Rancher:
If this times out or throws an auth error, that's the root cause we need to fix.ssh -i /path/to/your/ssh-private-key centos@<node-private-ip>
2. Check Network Security Group (NSG) Rules
Azure NSGs are the most common culprit here.
- For your Node Pool subnet's NSG: Add an inbound rule allowing port 22 from your Rancher subnet (
192.168.2.0/29). Make sure the priority is higher (lower number) than any deny rules. - For your Rancher VM's NSG: Ensure outbound rules allow connections to port 22 on the Node Pool subnet (
192.168.0.0/24). The default outbound rule usually allows this, but double-check if you've customized it.
3. Verify SSH Key Injection
Rancher relies on having the correct SSH key to access the CentOS VMs.
- Log into one of your Node Pool VMs via Azure Portal's serial console (under "Support + troubleshooting").
- Check the
centosuser's authorized keys:
Make sure this matches the public key you configured in Rancher for the Node Pool. If it's missing or incorrect, cloud-init probably failed to inject it during VM deployment.cat /home/centos/.ssh/authorized_keys
4. Inspect Cloud-Init and Boot Logs
CentOS VMs on Azure use cloud-init to set up SSH and other configs. Let's check if it's working:
- From the serial console, look at cloud-init logs:
Look for errors related to SSH key setup, network configuration, or package installs—these could prevent SSH from being ready when Rancher tries to connect.cat /var/log/cloud-init.log cat /var/log/cloud-init-output.log
5. Validate Subnet Routing
Since both subnets are in the same /16 VPN, they should be able to communicate by default, but custom routes might be blocking traffic:
- In Azure Portal, check the route tables attached to both the Rancher subnet and Node Pool subnet.
- Ensure there's no route that denies traffic between
192.168.2.0/29and192.168.0.0/24. The default VNet route should allow this, but if you've added custom routes, verify they don't override that.
6. Dig Into Rancher Server Logs
Rancher's logs might give you more specific details about why SSH is failing. On your Rancher VM:
- Get the Rancher container ID:
docker ps - View the logs:
docker logs <container-id> - Look for entries around the time of the timeout—you might see errors like "connection refused", "authentication failed", or DNS resolution issues that aren't obvious from the UI error.
内容的提问来源于stack exchange,提问作者Rob Callahan

