5 ms·
By implementing your own ssh, you appear to be ignoring lots of useful default ssh utilities, like ssh-agent and ~/.ssh/config eg. [derf@pan][09:06:20]-[~
by fps 10y ago
By implementing your own ssh, you appear to be ignoring lots of useful default ssh utilities, like ssh-agent and ~/.ssh/config eg.
[derf@pan][09:06:20]-[~] $ orgalorg -o pandora -C uptime
2016-07-25 09:06:28 [FATAL] can't create runner factory
└─ can't read SSH key: '/Users/derf/.ssh/id_rsa'
└─ can't read SSH key from file
└─ open /Users/derf/.ssh/id_rsa: no such file or directory
[derf@pan][09:06:28]-[~] $ orgalorg -p -o pandora -C uptime
Password:
2016-07-25 09:06:36 [WARN] still connecting to address after 2s: [derf@pandora:22]
2016-07-25 09:06:44 [FATAL] acquiring global cluster lock failed
└─ connection to 1 of 1 nodes failed
└─ can't connect to nodes
└─ can't connect to address: [derf@pandora:22]
└─ dial tcp 18.60.0.124:22: i/o timeout
[derf@pan][09:06:45]-[~] $ ssh pandora uptime
09:06:49 up 37 days, 23:45, 0 users, load average: 1.18, 0.70, 0.33
Is the assumption that I'm going to set up entries in /etc/hosts for all my systems, or add them to my network's DNS? What about ssh proxy hosts? The fact that you require a single ssh key to live in .ssh/id_rsa is going to make this useless for anyone that does any advanced usage of SSH.
- wjoe 10y agoThat's a shame. That does immediately rule out my use case of using it at work for working with multiple servers. I have all of our servers in ~/.ssh/config (populated from a script), which use a number of different ssh keys. I assumed the host names in the orgalorg examples would work with the ones defined in ~/.ssh/config
- seletskiy 10y agoParsing `ssh_config` is not implemented right now as well as multiple SSH keys for auth. However, it can be implemented easy. BTW, I have not implemented it, because I think it's very bad approach in maintaining clusters, e.g. storing host names inside local ~/.ssh/config file. Hosts should have DNS records.
- mugsie 10y agoyeap, but I have a nice .ssh/config that does wildcard masking , and a few other things to make sure I can log into servers without remembering which SSH Key I need to use, and what username. e.g. I use the following snippet for my dev build boxes - they are rebuilt all the time, but I need to login and check system state from time to time. Host 10.250.60.* UserKnownHostsFile /dev/null StrictHostKeyChecking no IdentityFile ~/.ssh/local-dev-key User build If you are implementing multiple SSH Keys, remember that a -lot- few people will have keys on GPG Cards, YubiKeys and other devices, not just on disk.
- seletskiy 10y ago> By implementing your own ssh, you appear to be ignoring lots of useful default ssh utilities, like ssh-agent What other utilities I'm ignoring besides of `ssh-agent`? `ssh-agent` support is a pending feature and implementing it is quite simple. I will be glad to see PR. > Is the assumption that I'm going to set up entries in /etc/hosts for all my systems, or add them to my network's DNS? Yes, you should to add your hosts to DNS. Otherwise, it's not production grade (we're talking about production clusters, aren't we?).
- fps 10y agoSSH config supports lots of esoteric options, like setting non-standards ports, usernames and specialized routing (using Proxycommand options). Three issues, for me, with adding hosts to DNS: 1) I work from several networks - work, home, tethered. I only control the DNS zone that is set up as my default DNS search domain on one of those networks. 2) I work on hosts in several external networks - they shouldn't all be in the same DNS search domain. 3) I work primarily with cloud hosted, ephemeral servers. Cattle, not pets. Right now I have a tool that adds hosts from my EC2 accounts to my ssh config file (https://github.com/fredsmith/aws-ssh-config. https://github.com/fredsmith/aws-ssh-config.) I also have solved this problem using 21 lines of bash in my bashrc. (https://github.com/fredsmith/dotfiles/blob/master/bash/dsh https://github.com/fredsmith/dotfiles/blob/master/bash/dsh) Mine doesn't have quite the level of polish of yours, but since it uses the system ssh binary, it handles special ssh configurations and seamlessly uses ssh-agent. I've used this on hundreds of hosts simultaneously, and it executes in parallel very quickly. [derf@pan][12:01:01]-[~] $ dsh smith.bz uptime pandora.smith.bz: 12:01:09 up 38 days, 2:40, 0 users, load average: 0.30, 0.23, 0.23 dione.smith.bz: 12:01:11 up 42 days, 14:22, 2 users, load average: 0.00, 0.01, 0.05 tethys.smith.bz: 12:01:11 up 23 days, 3:26, 1 user, load average: 0.00, 0.01, 0.05 hyperion.smith.bz: 12:01:12 up 23 days, 3:01, 1 user, load average: 0.89, 0.87, 0.76 io.smith.bz: 12:01:12 up 23 days, 3:26, 1 user, load average: 0.38, 0.73, 1.73 janus.smith.bz: 12:01:12 up 31 days, 3 min, 1 user, load average: 0.37, 0.37, 0.28 rhea.smith.bz: 12:01:12 up 42 days, 14:29, 2 users, load average: 0.03, 0.05, 0.07
- ranman 10y ago
- subway 10y agoBut how does one earn hipster cred without re-implementing battle-tested tools in go?
- brightball 10y agoSSH::Batch from CPAN is a handy and simple way to get s lot of what you're asking for.