You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS上KOPS部署的Kubernetes集群主节点SSH连接被拒绝如何解决?

Troubleshooting SSH Connection Refusal to Kubernetes Master Node (Kops + Terraform on AWS)

Looks like you've already checked the basics—security group rules and admin key association—so let's dive into the less obvious fixes for your connection refusal issue:

  • Double-check your connection endpoint
    Kops typically deploys master nodes behind an Elastic Load Balancer (ELB), so using the direct master IP might not work if your cluster uses private subnets (even if you intended public access). Run this to get the correct master ELB DNS:

    kops get cluster --state ${KOPS_STATE_STORE}
    

    Use that DNS name instead of the raw IP for your SSH attempt.

  • Confirm EC2 node health and bootstrap status
    Head to the AWS EC2 console and verify your master nodes:

    • They’re in the running state
    • Both instance and system status checks pass
    • If you just created the cluster, give it 10-15 more minutes—Kops needs time to bootstrap the nodes, install packages, and start the SSH service.
  • Fix local SSH key permissions
    SSH enforces strict permissions on private keys to prevent unauthorized access. Run these commands on your local machine to fix permissions:

    chmod 600 ~/.ssh/id_rsa
    chmod 644 ~/.ssh/id_rsa.pub
    

    If your key has overly open permissions, SSH will refuse to use it, leading to the connection error you’re seeing.

  • Check VPC network ACLs
    Security groups are stateful, but VPC network ACLs are stateless—meaning you need to allow both inbound and outbound traffic on port 22. Even if your security group allows SSH, a restrictive network ACL can block the connection. Verify your VPC’s network ACL rules in the AWS console.

  • Inspect master node system logs
    From the EC2 console, select your master node, go to Actions > Monitor and troubleshoot > Get system log. Look for entries related to sshd (the SSH daemon):

    • Did sshd start successfully?
    • Is the admin user’s public key present in /home/admin/.ssh/authorized_keys?
      If the key is missing, reimport the SSH secret to Kops:
    kops create secret --name ${KOPS_NAME} --state ${KOPS_STATE_STORE} sshpublickey admin -i ~/.ssh/id_rsa.pub
    kops update cluster --name ${KOPS_NAME} --state ${KOPS_STATE_STORE} --yes
    

    This will force Kops to reapply the public key to the master nodes.

  • Use AWS SSM as a workaround
    If SSH still won’t connect, use AWS Systems Manager Session Manager to access the master node without needing port 22. Once connected, check the SSH service status directly:

    sudo systemctl status sshd
    

    This will tell you if sshd is running and if there are any configuration issues blocking connections.


内容的提问来源于stack exchange,提问作者Ju East

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:21:08