无法通过pyeapi执行SCP从Arista交换机传输文件至外部机器
Let's break down what's going on here and fix that SCP transfer issue you're hitting.
First, here's the setup you tried: you're using pyeapi to run a copy command on an Arista switch, trying to send a file from flash to an external machine via SCP. Your code looks like this:
import pyeapi node = pyeapi.connect(transport='https', host='x.x.x.x', username='yyy', password='zzz', enable_pwd='xxx', return_node=True) node.run_command(['copy flash:/file.log.gz scp://user:password@hostname/location/'], encoding='json')
But you ran into this error:
pyeapi.eapilib.CommandError: Error [1000]: CLI command 2 of 2 'copy flash:/file.log.gz scp:user:password@hostname/location/' failed: could not run command [Error copying flash:/file.log.gz to scp:user:password@hostname/location/ (Warning: Permanently added 'hostname' (ECDSA) to the list of known hosts. Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password). lost connection)]
What's causing the problem?
First, notice the typo in the error message: the SCP path is scp:user:... instead of scp://user:... — that missing slash might be a parsing quirk from pyeapi when passing the command as a list. But the real showstopper is the Permission denied line: your switch can't authenticate to the SCP server using the credentials or methods you're trying.
Fixes to try:
Fix the command format in pyeapi
Instead of passing the command as a list, try sending it as a single string. Sometimes list parsing can mangle the URL structure:node.run_command('copy flash:/file.log.gz scp://user:password@hostname/location/', encoding='json')Validate your credentials and server settings
- Double-check that the username and password for the SCP server are correct. If your password has special characters (like
@,!, or#), you'll need to URL-encode them (e.g., replace@with%40). - Many SCP servers disable password authentication by default (for security). If that's the case, you'll either need to enable password login on the server (not recommended for production) or switch to SSH key-based authentication.
- Double-check that the username and password for the SCP server are correct. If your password has special characters (like
Use SSH key authentication (more secure and reliable)
This is the preferred method for production environments:- On your Arista switch, generate an SSH key pair with:
ssh key generate rsa - Copy the switch's public key (you can get it with
show ssh public-key) to the SCP server's~/.ssh/authorized_keysfile for the target user. - Update your pyeapi command to remove the password (the switch will use its key to authenticate):
node.run_command('copy flash:/file.log.gz scp://user@hostname/location/', encoding='json')
- On your Arista switch, generate an SSH key pair with:
Test the command directly on the switch CLI
Log into the switch's console or SSH session and run thecopycommand manually. If it fails there, the issue isn't with pyeapi — it's a network or permission issue between the switch and the SCP server. This will help you narrow down whether the problem is in your code or the underlying infrastructure.
内容的提问来源于stack exchange,提问作者mac and mocha

