无法通过SSH连接到Google Compute Engine

时间:2017-02-10 19:51:14

标签: linux ssh google-compute-engine

我在新项目上设置了一个新的Google Compute Engine实例。我启动实例并使用命令gcloud init连接到我的项目。然后我使用命令sudo gcloud compute ssh instance-1。它通过SSH密钥对生成:

WARNING: The private SSH key file for Google Compute Engine does not exist.
WARNING: You do not have an SSH key for Google Compute Engine.
WARNING: [/usr/bin/ssh-keygen] will be executed to generate a key.
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase): 
Enter same passphrase again: 
Your identification has been saved in /Users/username/.ssh/google_compute_engine.
Your public key has been saved in /Users/username/.ssh/google_compute_engine.pub.
The key fingerprint is:
SHA256:there_is_a_key_here_but_probably_should_not_show_it root@My-MacBook-Air-4.local
The key's randomart image is:
+---[RSA 2048]----+
|                 |
|                 |
|                 |
|                 |
|                 |
|                 |
|                 |
|There is an image|
|here             |
+----[SHA256]-----+
Updating project ssh metadata...\Updated [link to the project].
Updating project ssh metadata...done.                                                         
Warning: Permanently added 'compute.1788786712041991164' (ECDSA) to the list of known hosts.
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
Permission denied (publickey).
ERROR: (gcloud.compute.ssh) Could not SSH to the instance.  It is possible that your SSH key has not propagated to the instance yet. Try running this command again.  If you still cannot connect, verify that the firewall and instance are set to accept ssh traffic.

怪异。我检查了我的Google云端控制台中的元数据,运行此命令后,它们出现在那里。因此它已成功生成并更新了元数据。 我等一下,再次尝试相同的命令:

My-MacBook-Air-4:~ myname$ sudo gcloud compute ssh instance-1
Permission denied (publickey).
ERROR: (gcloud.compute.ssh) [/usr/bin/ssh] exited with return code [255]. See https://cloud.google.com/compute/docs/troubleshooting#ssherrors for troubleshooting hints.

所以我尝试了一些故障排除提示:

gcloud compute firewall-rules list

NAME                    NETWORK  SRC_RANGES    RULES                         SRC_TAGS  TARGET_TAGS
default-allow-http      default  0.0.0.0/0     tcp:80                                  http-server
default-allow-https     default  0.0.0.0/0     tcp:443                                 https-server
default-allow-icmp      default  0.0.0.0/0     icmp
default-allow-internal  default  10.128.0.0/9  tcp:0-65535,udp:0-65535,icmp
default-allow-rdp       default  0.0.0.0/0     tcp:3389
default-allow-ssh       default  0.0.0.0/0     tcp:22

防火墙似乎很好。这种情况发生在我在任何项目上创建的每个Google Compute Engine实例上。我不明白发生了什么,密钥对已经创建,我在几个不同的项目中多次尝试了所有步骤,错误仍然存​​在。

编辑:密钥出现在项目的SSH选项卡中,元数据选项卡仍为空。

2 个答案:

答案 0 :(得分:5)

  

然后我使用命令s1 [0x...c6,0x...cb] s2 [0x...c0,0x...c5] s3 [0x...a5,0x...bf]

此处使用sudo gcloud compute ssh instance-1是错误的。您似乎已在sudo中创建了密钥,但由于它具有评论/Users/username/.ssh/google_compute_engine,因此可能使用错误的所有权创建了密钥(即由root拥有)。

您可以通过以下方式解决此问题:

root@My-MacBook-Air-4.local

然后连接,不用 sudo chown $USER:$GROUPS ~/.ssh/google_compute_engine{,.pub}

sudo

或者,如果失败只是重新开始,但不要使用 gcloud compute ssh instance-1 来做任何事情。

答案 1 :(得分:1)

enter image description here

解决方案:创建一个新的防火墙,为 TCP 和 UDP 打开端口 22,如下图所示。