gcloud beta app instances ssh - SSH into the VM of an App Engine Flexible instance
gcloud beta app instances ssh INSTANCE [--container=CONTAINER] [--service=SERVICE, -s SERVICE] [--tunnel-through-iap] [--version=VERSION, -v VERSION] [GCLOUD_WIDE_FLAG ...] [-- COMMAND ...]
(BETA) gcloud beta app instances ssh lets you remotely log in to your running App Engine Flexible instances under two conditions:
The instance is running.
The instance has an external IP address. To check from the Cloud Console, go to the Instances page and confirm that there is an IP address listed in the VM IP column. To check from your app.yaml, open your app.yaml and look at the network settings. The instance_ip_mode field must be either not listed or set to external.
gcloud beta app instances ssh resolves the instance's IP address and pre-populates the VM with a public key managed by gcloud. If the gcloud managed key pair does not exist, it is generated the first time an SSH command is run, which may prompt you for a passphrase for the private key encryption.
All SSH commands require the OpenSSH client suite to be installed on Linux and Mac OS X. On Windows, the Google Cloud CLI comes with a bundled PuTTY suite instead, so it has no external dependencies.
To SSH into an App Engine Flexible instance, run:
$ gcloud beta app instances ssh --service=s1 --version=v1 i1
To SSH into the app container within an instance, run:
$ gcloud beta app instances ssh --service=s1 --version=v1 i1 \ --container=gaeapp
To SSH into the app container and run a remote command, run:
$ gcloud beta app instances ssh --service=s1 --version=v1 i1 \ --container=gaeapp -- echo hello
- INSTANCE
The instance ID.
- [-- COMMAND ...]
Remote command to execute on the VM.
The '--' argument must be specified between gcloud specific args on the left and COMMAND on the right.
- --container=CONTAINER
Name of the container within the VM to connect to.
- --service=SERVICE, -s SERVICE
The service ID.
- --tunnel-through-iap
Tunnel the ssh connection through Cloud Identity-Aware Proxy for TCP forwarding.
To learn more, see the IAP for TCP forwarding documentation https://cloud.google.com/iap/docs/tcp-forwarding-overview.
- --version=VERSION, -v VERSION
The version ID.
These flags are available to all commands: --access-token-file, --account, --billing-project, --configuration, --flags-file, --flatten, --format, --help, --impersonate-service-account, --log-http, --project, --quiet, --trace-token, --user-output-enabled, --verbosity.
Run $ gcloud help for details.
This command is currently in beta and might change without notice. This variant is also available:
$ gcloud app instances ssh