通过浏览器前端访问Google Cloud实例终端失败:无法连接SSH 22端口
Hey there, let’s work through this SSH port 22 issue you’re hitting with your Google Cloud instance—this is a super common pain point, but we can troubleshoot it step by step to get you connected.
1. Verify the Instance is Running & Has a Valid External IP
- Head over to the GCP Console’s VM Instances page and double-check your instance status: it needs to be marked Running. If it’s stopped or terminated, start it up first.
- Confirm the instance has an external IP (either static or ephemeral). Ephemeral IPs can change if you stop/restart the instance, so refresh your browser SSH tab to pick up the latest IP if needed.
2. Check Firewall Rules Allow SSH Traffic (Port 22)
Firewall blocks are the #1 culprit here:
- Go to VPC Network > Firewall Rules and look for the default
default-allow-sshrule. Make sure it’s:- Enabled (not disabled)
- Targeted to
all instances in network(or tagged with a label your instance has) - Set to allow ingress traffic on
tcp:22 - Source IP range includes your current public IP (or
0.0.0.0/0for broad access, though not ideal for production)
- If the default rule is missing or broken, create a new one:
- Direction: Ingress
- Action on match: Allow
- Targets: Select "Specified target tags" and add a tag like
allow-ssh(then add this tag to your instance under "Tags" in its details page) - Source IP ranges: Enter your public IP (find it via
curl ifconfig.melocally) or0.0.0.0/0 - Protocols and ports: Select "tcp" and enter
22
3. Ensure the SSH Service (sshd) is Running on the Instance
If the firewall is open but SSH still fails, the sshd service might be down:
- Use the Serial Console (found in your instance’s details page under "Connect > Serial console") to access the instance without SSH:
- Once logged in, check the service status with:
sudo systemctl status sshd - If it shows "inactive (dead)", start it up and enable it to run on boot:
sudo systemctl start sshd sudo systemctl enable sshd
- Once logged in, check the service status with:
- Double-check the
sshdconfig file to make sure port 22 isn’t disabled:
Look for the linesudo nano /etc/ssh/sshd_configPort 22—if it’s commented out (starts with#), remove the#and save the file, then restart the service withsudo systemctl restart sshd.
4. Validate SSH Key Configuration
Browser SSH relies on keys stored in GCP metadata—let’s make sure those are set up correctly:
- Go to your instance’s details page > Metadata > SSH Keys tab. Check if your public key is listed here (format should be
ssh-rsa AAAAB3NzaC1yc2E... your-username@domain).- If it’s missing, click "Add item" and paste your local public key (or let the browser generate a new one when you try to connect again).
- From the Serial Console, verify the key is present in your user’s
authorized_keysfile:
If it’s not there, manually add it, then fix file permissions (critical for SSH to trust the keys):cat ~/.ssh/authorized_keyschmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys sudo systemctl restart sshd
5. Rule Out Network or Resource Issues
- Try connecting from your local terminal instead of the browser to get more detailed error messages:
This might tell you if it’s a key issue, timeout, or permission problem.ssh your-username@instance-external-ip - Check instance resource usage (CPU, memory) in the GCP Console’s Monitoring tab. If CPU is spiking to 100%, the instance might be too overloaded to respond to SSH—restart the instance to free up resources.
- If the instance was just created, wait 2-3 minutes for full initialization. Sometimes
sshdtakes a moment to start up during the first boot.
If none of these steps resolve the issue, you might need to create a new instance (copying over disk data if needed) or check for more advanced VPC configuration issues (like routing tables or NAT gateways), but 9 times out of 10, one of the above fixes will get you connected.
内容的提问来源于stack exchange,提问作者Sanjay Kumar

