AWS上KOPS部署的Kubernetes集群主节点SSH连接被拒绝如何解决?
Looks like you've already checked the basics—security group rules and admin key association—so let's dive into the less obvious fixes for your connection refusal issue:
Double-check your connection endpoint
Kops typically deploys master nodes behind an Elastic Load Balancer (ELB), so using the direct master IP might not work if your cluster uses private subnets (even if you intended public access). Run this to get the correct master ELB DNS:kops get cluster --state ${KOPS_STATE_STORE}Use that DNS name instead of the raw IP for your SSH attempt.
Confirm EC2 node health and bootstrap status
Head to the AWS EC2 console and verify your master nodes:- They’re in the
runningstate - Both instance and system status checks pass
- If you just created the cluster, give it 10-15 more minutes—Kops needs time to bootstrap the nodes, install packages, and start the SSH service.
- They’re in the
Fix local SSH key permissions
SSH enforces strict permissions on private keys to prevent unauthorized access. Run these commands on your local machine to fix permissions:chmod 600 ~/.ssh/id_rsa chmod 644 ~/.ssh/id_rsa.pubIf your key has overly open permissions, SSH will refuse to use it, leading to the connection error you’re seeing.
Check VPC network ACLs
Security groups are stateful, but VPC network ACLs are stateless—meaning you need to allow both inbound and outbound traffic on port 22. Even if your security group allows SSH, a restrictive network ACL can block the connection. Verify your VPC’s network ACL rules in the AWS console.Inspect master node system logs
From the EC2 console, select your master node, go to Actions > Monitor and troubleshoot > Get system log. Look for entries related tosshd(the SSH daemon):- Did
sshdstart successfully? - Is the admin user’s public key present in
/home/admin/.ssh/authorized_keys?
If the key is missing, reimport the SSH secret to Kops:
kops create secret --name ${KOPS_NAME} --state ${KOPS_STATE_STORE} sshpublickey admin -i ~/.ssh/id_rsa.pub kops update cluster --name ${KOPS_NAME} --state ${KOPS_STATE_STORE} --yesThis will force Kops to reapply the public key to the master nodes.
- Did
Use AWS SSM as a workaround
If SSH still won’t connect, use AWS Systems Manager Session Manager to access the master node without needing port 22. Once connected, check the SSH service status directly:sudo systemctl status sshdThis will tell you if
sshdis running and if there are any configuration issues blocking connections.
内容的提问来源于stack exchange,提问作者Ju East

