gce: register SSH keys under the "ubuntu" user for Ubuntu images - #18581
Conversation
kOps registers SSH public keys in GCE instance metadata under the "admin" username, but on Ubuntu images the GCE guest agent fails to create that user because the images ship with an "admin" group, so the key is never installed and SSH to instances does not work. Derive the username from the instance group image instead: Ubuntu images register the key under the built-in "ubuntu" user, while other images keep "admin" so SSH access to existing non-Ubuntu clusters is unchanged.
|
I see the prow jobs are able to SSH: We set but thats only used by kops for SSHing in to dump logs, we dont create that user: https://github.com/search?q=repo%3Akubernetes%2Fkops%20SSHUser&type=code Any idea why this is working with |
|
I verified this on real VMs: only Ubuntu has the conflicting group, while Debian, RHEL, Rocky and COS create the |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: rifelpet The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/override pull-kops-e2e-k8s-aws-calico |
|
@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-k8s-aws-calico DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
kOps registers SSH public keys in GCE instance metadata under the "admin" username, but on Ubuntu images the GCE guest agent fails to create that user because the images ship with an "admin" group, so the key is never installed and SSH to instances does not work.
Derive the username from the instance group image instead: Ubuntu images register the key under the built-in "ubuntu" user, while other images keep "admin" so SSH access to existing non-Ubuntu clusters is unchanged.
Refs #16642