Skip to main content

Command Palette

Search for a command to run...

VKS - Tips for SSH

Updated
•3 min read•View as Markdown

Introduction

Since the Supervisor is a locked-down appliance, making direct changes via SSH—such as adding or deleting configurations—is generally discouraged.

However, in the real world of troubleshooting, you’ll inevitably face situations where "diving under the hood" is the only way to see what's really going on. The challenge is that logging into the Supervisor is already a hassle, and hopping from there into a VKS (TKG) Cluster is even more of a headache.

To take the pain out of this process and keep your workflow smooth, I’ve put together some handy command snippets that drastically streamline these login steps.

SSH Helper for Supervisor

By pasting this snippet onto your Supervisor, you can easily SSH into other Supervisors.

function svssh() {
    echo "Supervisor IPs: $(kubectl -n kube-system get cm wcp-network-config -ojsonpath='{.data.api_servers_management_ips}')"
    echo "Current IP: $(ip a show dev eth0 | grep 'inet ' | awk '{print $2}')"
    [[ -z "${1:-}" ]] && { echo "Usage: svssh <TARGET_IP>"; return 1; }
    SSHPASS=$(grep 'DESIRED_ROOT_PASSWORD' /var/lib/node.cfg | sed 's/.*= //') sshpass -e ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null root@"${1}"
}

# Usage
root@423e1a221d7a0ec030c3dea9348b4e07 # svssh
#> Supervisor Management IP list: 192.168.100.202 192.168.100.201 192.168.100.203
#> Current IP: 192.168.100.201/24
#> Usage: svssh [target-ip]
svssh 192.168.100.203

SSH Helper for VKS Cluster

By pasting this snippet onto your Supervisor, you can interactively select a VKS Cluster node and SSH into it seamlessly.

function vssh() {
    [[ -z "${2:-}" ]] && { kubectl get cluster -A; echo "Usage: vssh <NS> <NAME> <IP>"; return 1; }
    [[ -z "${3:-}" ]] && { kubectl get vm -n "${1}" -o wide | grep -E "(${2}|NAME)"; echo "Usage: vssh ${1} ${2} <IP>"; return 1; }
    ssh-agent bash -c "kubectl -n \"${1}\" get secret \"${2}-ssh\" -o jsonpath='{.data.ssh-privatekey}' | base64 -d | ssh-add - >/dev/null 2>&1; ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null vmware-system-user@\"${3}\""
}

# Check - Target Cluster
root@423e1a221d7a0ec030c3dea9348b4e07 # vssh
#> NAMESPACE      NAME     CLUSTERCLASS             PHASE         AGE   VERSION
#> vsphere-ns-1   test-1   builtin-generic-v3.1.0   Provisioned   12d   v1.31.4+vmware.1-fips
#> vsphere-ns-1   test-2   builtin-generic-v3.1.0   Provisioned   12d   v1.31.4+vmware.1-fips
#> Usage: vssh <namespace> <cluster-name>

# Check - Target node IP
root@423e1a221d7a0ec030c3dea9348b4e07 # vssh vsphere-ns-1 test-1
#> NAME                                  POWER-STATE   CLASS                IMAGE                   PRIMARY-IP4      AGE
#> test-1-nodepool-1-nj7lg-2kqm7-s9pcn   PoweredOn     best-effort-custom   vmi-54b55e9dd4ab00154   192.168.120.53   12d
#> test-1-tnkzc-blbdn                    PoweredOn     best-effort-custom   vmi-54b55e9dd4ab00154   192.168.120.4    12d
#> test-1-tnkzc-lqp7h                    PoweredOn     best-effort-custom   vmi-54b55e9dd4ab00154   192.168.120.28   12d
#> test-1-tnkzc-lv4gq                    PoweredOn     best-effort-custom   vmi-54b55e9dd4ab00154   192.168.120.56   12d
#> Usage: vssh <namespace> <cluster-name> <target-ip>

# SSH login to the target node
root@423e1a221d7a0ec030c3dea9348b4e07 # vssh vsphere-ns-1 test-1 192.168.120.53
#> Last login: Thu Dec 25 10:07:13 2025 from 192.168.120.17
vmware-system-user@test-1-nodepool-1-nj7lg-2kqm7-s9pcn [ ~ ]$

kubectl Helper for VKS Cluster

If you need to run kubectl commands against a target VKS Cluster from the Supervisor, just paste this snippet onto your Supervisor.

function vk() {
    [[ -z "${2:-}" ]] && { kubectl get cluster -A; echo "Usage: vk <NS> <NAME> [COMMAND]"; return 1; }
    local KCONF=$(kubectl -n "${1}" get secret "${2}-kubeconfig" -o jsonpath='{.data.value}' | base64 -d)
    [[ -z "${3:-}" ]] && { echo "Target: ${2}"; kubectl --kubeconfig <(echo "${KCONF}") get nodes; echo "Usage: vk ${1} ${2} <COMMAND...>"; return 1; }
    kubectl --kubeconfig <(echo "${KCONF}") "${@:3}"
}

# Usage
root@423e379314918899c90840e743ddd2f5 # vk
#> NAMESPACE      NAME     CLUSTERCLASS             PHASE         AGE     VERSION
#> test-ns        test-5   builtin-generic-v3.1.0   Provisioned   5d10h   v1.31.4+vmware.1-fips
#> vsphere-ns-1   test-1   builtin-generic-v3.3.0   Provisioned   27d     v1.32.7+vmware.3-fips
#> vsphere-ns-1   test-2   builtin-generic-v3.1.0   Provisioned   26d     v1.31.4+vmware.1-fips
#> vsphere-ns-1   test-4   builtin-generic-v3.1.0   Provisioned   5d10h   v1.31.4+vmware.1-fips
#> Usage: vk <NS> <NAME> [COMMAND]

root@423e379314918899c90840e743ddd2f5 # vk vsphere-ns-1 test-1 get nodes
#> NAME                                  STATUS   ROLES           AGE   VERSION
#> test-1-nodepool-1-nj7lg-95r4d-cr55h   Ready    <none>          10d   v1.32.7+vmware.3-fips
#> test-1-tnkzc-d5mzx                    Ready    control-plane   10d   v1.32.7+vmware.3-fips
#> test-1-tnkzc-h9rtv                    Ready    control-plane   10d   v1.32.7+vmware.3-fips
#> test-1-tnkzc-pq6xc                    Ready    control-plane   10d   v1.32.7+vmware.3-fips