VKS - Tips for SSH
Introduction
Since the Supervisor is a locked-down appliance, making direct changes via SSH—such as adding or deleting configurations—is generally discouraged.
However, in the real world of troubleshooting, you’ll inevitably face situations where "diving under the hood" is the only way to see what's really going on. The challenge is that logging into the Supervisor is already a hassle, and hopping from there into a VKS (TKG) Cluster is even more of a headache.
To take the pain out of this process and keep your workflow smooth, I’ve put together some handy command snippets that drastically streamline these login steps.
SSH Helper for Supervisor
By pasting this snippet onto your Supervisor, you can easily SSH into other Supervisors.
function svssh() {
echo "Supervisor IPs: $(kubectl -n kube-system get cm wcp-network-config -ojsonpath='{.data.api_servers_management_ips}')"
echo "Current IP: $(ip a show dev eth0 | grep 'inet ' | awk '{print $2}')"
[[ -z "${1:-}" ]] && { echo "Usage: svssh <TARGET_IP>"; return 1; }
SSHPASS=$(grep 'DESIRED_ROOT_PASSWORD' /var/lib/node.cfg | sed 's/.*= //') sshpass -e ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null root@"${1}"
}
# Usage
root@423e1a221d7a0ec030c3dea9348b4e07 # svssh
#> Supervisor Management IP list: 192.168.100.202 192.168.100.201 192.168.100.203
#> Current IP: 192.168.100.201/24
#> Usage: svssh [target-ip]
svssh 192.168.100.203
SSH Helper for VKS Cluster
By pasting this snippet onto your Supervisor, you can interactively select a VKS Cluster node and SSH into it seamlessly.
function vssh() {
[[ -z "${2:-}" ]] && { kubectl get cluster -A; echo "Usage: vssh <NS> <NAME> <IP>"; return 1; }
[[ -z "${3:-}" ]] && { kubectl get vm -n "${1}" -o wide | grep -E "(${2}|NAME)"; echo "Usage: vssh ${1} ${2} <IP>"; return 1; }
ssh-agent bash -c "kubectl -n \"${1}\" get secret \"${2}-ssh\" -o jsonpath='{.data.ssh-privatekey}' | base64 -d | ssh-add - >/dev/null 2>&1; ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null vmware-system-user@\"${3}\""
}
# Check - Target Cluster
root@423e1a221d7a0ec030c3dea9348b4e07 # vssh
#> NAMESPACE NAME CLUSTERCLASS PHASE AGE VERSION
#> vsphere-ns-1 test-1 builtin-generic-v3.1.0 Provisioned 12d v1.31.4+vmware.1-fips
#> vsphere-ns-1 test-2 builtin-generic-v3.1.0 Provisioned 12d v1.31.4+vmware.1-fips
#> Usage: vssh <namespace> <cluster-name>
# Check - Target node IP
root@423e1a221d7a0ec030c3dea9348b4e07 # vssh vsphere-ns-1 test-1
#> NAME POWER-STATE CLASS IMAGE PRIMARY-IP4 AGE
#> test-1-nodepool-1-nj7lg-2kqm7-s9pcn PoweredOn best-effort-custom vmi-54b55e9dd4ab00154 192.168.120.53 12d
#> test-1-tnkzc-blbdn PoweredOn best-effort-custom vmi-54b55e9dd4ab00154 192.168.120.4 12d
#> test-1-tnkzc-lqp7h PoweredOn best-effort-custom vmi-54b55e9dd4ab00154 192.168.120.28 12d
#> test-1-tnkzc-lv4gq PoweredOn best-effort-custom vmi-54b55e9dd4ab00154 192.168.120.56 12d
#> Usage: vssh <namespace> <cluster-name> <target-ip>
# SSH login to the target node
root@423e1a221d7a0ec030c3dea9348b4e07 # vssh vsphere-ns-1 test-1 192.168.120.53
#> Last login: Thu Dec 25 10:07:13 2025 from 192.168.120.17
vmware-system-user@test-1-nodepool-1-nj7lg-2kqm7-s9pcn [ ~ ]$
kubectl Helper for VKS Cluster
If you need to run kubectl commands against a target VKS Cluster from the Supervisor, just paste this snippet onto your Supervisor.
function vk() {
[[ -z "${2:-}" ]] && { kubectl get cluster -A; echo "Usage: vk <NS> <NAME> [COMMAND]"; return 1; }
local KCONF=$(kubectl -n "${1}" get secret "${2}-kubeconfig" -o jsonpath='{.data.value}' | base64 -d)
[[ -z "${3:-}" ]] && { echo "Target: ${2}"; kubectl --kubeconfig <(echo "${KCONF}") get nodes; echo "Usage: vk ${1} ${2} <COMMAND...>"; return 1; }
kubectl --kubeconfig <(echo "${KCONF}") "${@:3}"
}
# Usage
root@423e379314918899c90840e743ddd2f5 # vk
#> NAMESPACE NAME CLUSTERCLASS PHASE AGE VERSION
#> test-ns test-5 builtin-generic-v3.1.0 Provisioned 5d10h v1.31.4+vmware.1-fips
#> vsphere-ns-1 test-1 builtin-generic-v3.3.0 Provisioned 27d v1.32.7+vmware.3-fips
#> vsphere-ns-1 test-2 builtin-generic-v3.1.0 Provisioned 26d v1.31.4+vmware.1-fips
#> vsphere-ns-1 test-4 builtin-generic-v3.1.0 Provisioned 5d10h v1.31.4+vmware.1-fips
#> Usage: vk <NS> <NAME> [COMMAND]
root@423e379314918899c90840e743ddd2f5 # vk vsphere-ns-1 test-1 get nodes
#> NAME STATUS ROLES AGE VERSION
#> test-1-nodepool-1-nj7lg-95r4d-cr55h Ready <none> 10d v1.32.7+vmware.3-fips
#> test-1-tnkzc-d5mzx Ready control-plane 10d v1.32.7+vmware.3-fips
#> test-1-tnkzc-h9rtv Ready control-plane 10d v1.32.7+vmware.3-fips
#> test-1-tnkzc-pq6xc Ready control-plane 10d v1.32.7+vmware.3-fips
