Documents

huawei-cloud-ecs-passwordless-login

Try it

Configure passwordless SSH login to Huawei Cloud ECS instances using COC (Cloud Operations Center). Automates IAM agency authorization, SSH key pair generati...

What it does

Configure passwordless SSH login to Huawei Cloud ECS instances using COC (Cloud Operations Center). Automates IAM agency authorization, SSH key pair generation, COC script deployment to the target ECS, SSH connection testing, and automatic security cleanup after 60 seconds (removing keys from both local and remote). 触发词: 免密登录, COC SSH, ECS key login, SSH key deployment, passwordless SSH

The skill document

Huawei Cloud ECS Passwordless Login

Overview

Configure passwordless SSH login to Huawei Cloud ECS using COC (Cloud Operations Center) with a 7-step automated workflow:

  1. IAM Authorization — Create the ServiceAgencyForCOC agency for COC service and bind 4 required roles; skip entirely if agency already exists (HTTP 409)
  2. Key Generation — Generate a local RSA 4096-bit SSH key pair
  3. Script Creation — Create or reuse a parameterized COC script that deploys the public key
  4. Script Execution — Execute the script on the target ECS via COC
  5. SSH Test — Verify passwordless SSH connection to the target ECS
  6. Persistent Connection — Establish SSH ControlMaster so the agent can continue SSH access after keys are cleaned up
  7. Security Cleanup — After 60 seconds, automatically remove keys from remote authorized_keys, delete the local key pair, and clean up the COC script

Tool chain: hcloud CLI (KooCLI) + local SSH tools. Deployment is handled through COC script execution only.

Prerequisites

  • hcloud CLI (KooCLI) installed and authenticated with AK/SK — see CLI Installation Guide
  • IAM user with sufficient permissions to create agencies and operate COC — see IAM Policies
  • SSH client and ssh-keygen available locally
  • Target ECS instance ID or elastic IP (the ECS must be in ACTIVE state)

Security

  • Never expose private key content in conversation or output
  • Never log or persist private keys beyond the 60s window
  • Cleanup is mandatory — if SSH test succeeds, keys MUST be removed within cleanup_delay seconds
  • Removing the public key from authorized_keys only blocks new SSH connections; existing sessions are NOT interrupted
  • If SSH test fails, preserve keys for debugging and do NOT trigger cleanup

Workflow

Execute the numbered steps below in order. See Core Commands section for the exact command syntax to use at each step.

1. IAM Authorization

One-time per-account setup. Authorize COC to operate on your ECS instances.

  1. Get domain ID — Call KeystoneListAuthDomains and extract the id.
  2. Create agency — Call CreateAgency with name ServiceAgencyForCOC and trust domain op_svc_coc.
    • HTTP 200 — New agency created. Record agency.id. Proceed to step 3.
    • HTTP 409 — Agency already exists. Skip the entire IAM phase (steps 3–4) and jump to Step 2 (Key Generation).
  3. Find role IDs — Call KeystoneListPermissions for each of the 4 roles: IAM ReadOnlyAccess, RMS ReadOnlyAccess, DCS UserAccess, COCServiceAgencyPolicy. If any role is not found, stop — the account may lack access.
  4. Bind roles — Call AssociateAgencyWithAllProjectsPermission for each of the 4 role IDs.
    • HTTP 200 — Bound successfully.
    • HTTP 409 — Already bound, skip and continue.

2. Generate Local SSH Key Pair

Generate an RSA 4096-bit key pair. The comment coc-temp-key is the cleanup marker.

Record the key fingerprint. Never display the private key content.

3. Create or Reuse COC Script

  1. Check existing — Call ListScripts with --name_like="coc_ssh_key_setup". If found, record script_uuid and skip step 2.
  2. Create new — Write a JSON file with the script content, then call CreateScript --cli-jsonInput=. Use --cli-jsonInput (not inline --content) to avoid shell quoting issues with special characters in the script body. Record the returned script_uuid.

4. Execute Script on Target ECS

  1. Resolve instance — If only an ECS IP was provided, call NovaListServersDetails to find the instance ID.

  2. Execute — Write a JSON file with the public key embedded, then call ExecuteScript --cli-jsonInput=. Same pattern as Step 3 to avoid shell quoting issues with the public key content. Record execute_uuid.

  3. Poll — Call GetScriptJobInfo every 5 seconds until terminal status. Note: the API redacts param_value in the response for security; verify deployment by testing SSH in Step 5.

    StatusAction
    RUNNINGWait 5s, poll again
    SUCCESSProceed to Step 5
    FAILED / TIMEOUTReport error, stop

    Max 2 minutes (24 polls).

5. Test SSH Connection

Test passwordless SSH using the generated key.

  • SSH_OK returned — Proceed to Step 6.
  • Connection fails — Report error. Stop here. Preserve keys for debugging. Do NOT trigger cleanup.

6. Establish Persistent SSH Connection

Set up SSH ControlMaster so the agent can continue accessing the ECS after keys are removed in Step 7.

  1. Append SSH config — Add a Host block to ~/.ssh/config with ControlMaster auto, ControlPath /tmp/coc_ssh_%r@%h:%p, and ControlPersist .
  2. Start master — Run ssh -N -f -i to background a persistent master connection.
  3. Verify — Run ssh "echo SSH_MUX_OK" without a key file. If SSH_MUX_OK is returned, multiplexing works.

SSH config and socket do not need cleanup — config entries are harmless, sockets auto-expire with ControlPersist.

7. Security Cleanup

Mandatory. Start a background timer that fires after cleanup_delay seconds (default: 60):

  1. Remove coc-temp-key line from remote /root/.ssh/authorized_keys
  2. Delete the COC script via DeleteScript
  3. Delete local key files from /

After cleanup, the agent can still connect via ssh — ControlMaster bypasses key authentication.

Fallback: If remote key removal via SSH fails, create and execute a one-shot COC script:

#!/bin/bash
set -e
sed -i '/coc-temp-key/d' /root/.ssh/authorized_keys
echo "KEY_REMOVED"

Create and execute this script with no parameters. Delete it immediately after execution completes.

Core Commands

Placeholder values (see Parameters for per-OS resolution):

PlaceholderLinux / macOSWindows
``hcloudhcloud
``/tmp$env:TEMP
# 1. Check/setup COC IAM authorization
 IAM KeystoneListAuthDomains/v3
 IAM CreateAgency/v3 \
  --agency.domain_id="" \
  --agency.name="ServiceAgencyForCOC" \
  --agency.trust_domain_name="op_svc_coc" \
  --agency.duration="FOREVER"
 IAM KeystoneListPermissions/v3 \
  --display_name=""
 IAM AssociateAgencyWithAllProjectsPermission/v3 \
  --agency_id="" --domain_id="" --role_id=""

# 2. Generate local SSH key pair
ssh-keygen -t rsa -b 4096 -f /coc_ssh_key -N "" -C "coc-temp-key"
ssh-keygen -lf /coc_ssh_key  # record fingerprint

# 3. Check for existing COC script
 COC ListScripts --limit=100 --name_like="coc_ssh_key_setup"
# If not found, create a JSON file and use --cli-jsonInput:
cat > /coc_create.json << 'JSONEOF'
{
  "body": {
    "name": "coc_ssh_key_setup",
    "type": "SHELL",
    "description": "Deploy SSH public key for passwordless login",
    "content": "#!/bin/bash\nset -e\nmkdir -p /root/.ssh && chmod 700 /root/.ssh\necho $PUBLIC_KEY >> /root/.ssh/authorized_keys\nchmod 600 /root/.ssh/authorized_keys\necho KEY_DEPLOYED_SUCCESSFULLY",
    "properties": {
      "risk_level": "LOW",
      "version": "1.0.0"
    },
    "script_params": [
      {
        "param_name": "PUBLIC_KEY",
        "param_description": "SSH public key to deploy",
        "param_value": "",
        "sensitive": false
      }
    ]
  }
}
JSONEOF
 COC CreateScript --cli-jsonInput=/coc_create.json

# 4. Execute script on target ECS, replace with actual value
cat > /coc_execute.json << 'JSONEOF'
{
  "path": {"script_uuid": ""},
  "body": {
    "execute_batches": [{
      "batch_index": 1,
      "rotation_strategy": "CONTINUE",
      "target_instances": [{
        "region_id": "",
        "resource_id": ""
      }]
    }],
    "execute_param": {
      "execute_user": "root",
      "success_rate": 100,
      "timeout": 120,
      "script_params": [{
        "param_name": "PUBLIC_KEY",
        "param_value": pubkey
      }]
    }
  }
}
JSONEOF
 COC ExecuteScript --cli-jsonInput=/coc_execute.json

# Poll execution status (note: GetScriptJobInfo redacts param_value for security; check SSH directly to verify)
 COC GetScriptJobInfo --execute_uuid=

# 5. Test SSH connection
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null \
  -o ConnectTimeout=10 -i /coc_ssh_key root@ "echo SSH_OK"

# 6. Establish persistent SSH connection (ControlMaster multiplexing)
cat >> ~/.ssh/config << 'EOF'

Host 
  User 
  ControlMaster auto
  ControlPath /tmp/coc_ssh_%r@%h:%p
  ControlPersist 
  StrictHostKeyChecking no
  UserKnownHostsFile /dev/null
EOF
ssh -N -f  -i /coc_ssh_key && echo "MASTER_CONNECTED"
ssh  "echo SSH_MUX_OK"  # verify multiplexing works

# 7. Security cleanup (background, survives parent shell exit via nohup + disown)
nohup bash -c '
sleep 
# Remove public key from remote
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null \
  -o ConnectTimeout=5 -i /coc_ssh_key root@ \
  "sed -i \"/coc-temp-key/d\" /root/.ssh/authorized_keys" 2>/dev/null || true
# Delete COC script
 COC DeleteScript --script_uuid="" 2>/dev/null || true
# Delete local keys
rm -f /coc_ssh_key /coc_ssh_key.pub
echo "COC SSH keys cleaned up. Existing SSH sessions remain unaffected."
' > /coc_cleanup.log 2>&1 &
disown
echo "Cleanup scheduled in s (PID: $!, log: /coc_cleanup.log)"

Parameters

ParameterRequiredDefaultConstraint
ecs_instance_idConditionalNoneECS instance UUID; required if ecs_ip is not provided
ecs_ipConditionalNoneECS elastic IPv4 address; required if ecs_instance_id is not provided
regionYescn-north-4Region where the ECS and COC reside. Must match the ECS's region
ssh_userNorootSSH username on the target ECS
cleanup_delayNo60Seconds to wait before automatic key cleanup (min 10, max 300)
persist_timeoutNo3600Seconds to keep ControlMaster alive after all sessions close (min 60, max 86400)

Output Format

At each step, report progress in a structured manner:

StepOutput
1. AuthorizationAgency status (created / already exists), roles bound count (4/4)
2. Key GenerationKey fingerprint, key file paths
3. ScriptScript name, action (created / reused), script_uuid
4. Executionexecute_uuid, polling status, final result
5. SSH TestConnection result, SSH command string
6. Persistent ConnectionControlMaster status, multiplex verification, SSH alias ``
7. CleanupTimer PID, countdown notification, cleanup confirmation

Verification

Verify the workflow step by step:

  1. AuthorizationCreateAgency returns 200 → all 4 roles bound (200 or 409 each); returns 409 → entire IAM phase skipped (agency already authorized from prior run)
  2. Key Generation — Key pair files exist in / with correct permissions
  3. Scriptcoc_ssh_key_setup exists with PUBLIC_KEY parameter and valid script_uuid
  4. ExecutionGetScriptJobInfo shows SUCCESS within 2 minutes
  5. SSH Testssh connects without password prompt; test command returns SSH_OK
  6. Persistent Connection — SSH config appended, ssh -N -f starts master, ssh "echo SSH_MUX_OK" succeeds
  7. Cleanup — Remote key removed, COC script deleted, local key files deleted; ssh still connects via ControlMaster

See Verification Method and Acceptance Criteria for detailed checklists.

Best Practices

  • IAM authorization is a one-time per-account setup — if CreateAgency returns 409, the entire IAM phase (agency + role binding) is already complete and should be skipped entirely
  • Use the --name_like filter in ListScripts to avoid creating duplicate scripts
  • Always test the SSH connection before starting the cleanup timer
  • If SSH fails, keep keys on disk for debugging — do NOT clean up automatically
  • The cleanup timer runs in a background subshell; killing the process before cleanup completes leaves keys in place
  • After key cleanup, the agent can still SSH via ssh — ControlMaster bypasses key authentication
  • Use -o UserKnownHostsFile=/dev/null to avoid polluting the local known_hosts file
  • The SSH key comment coc-temp-key is the marker used by sed for cleanup — do not change it
  • COC script execution is limited to 200 hosts per execution and 10 hosts per batch
  • SSH config entries persist after cleanup as harmless dead entries; they can be removed later if desired

Reference Documents

DocumentDescription
CLI Installation GuideInstall and configure hcloud CLI and SSH tools
IAM PoliciesRequired IAM permissions, agency setup, and error handling
Verification MethodStep-by-step verification per workflow step
Acceptance CriteriaFull end-to-end acceptance checklist

Notes

  • All hcloud commands use the default region from the CLI profile (no --cli-region). Ensure your profile is configured with the correct region where your ECS and COC reside.
  • The COC script is created via --cli-jsonInput with a JSON file, not inline --content="..." — inline quoting causes parsing errors with shell special characters in the script body
  • The COC script is parameterized with PUBLIC_KEY — it persists across invocations and can deploy different keys
  • If the COC script already exists from a previous run, it is reused rather than recreated
  • The cleanup uses nohup bash -c '...' & + disown to survive parent shell exit; output is logged to /coc_cleanup.log for verification. The old (sleep N && ...) & pattern loses stdout when the parent shell exits in non-interactive mode
  • Private keys are stored in `` and should never be committed to VCS
  • The sed cleanup target coc-temp-key matches the key comment set during ssh-keygen
  • After cleanup, use ssh (no key file needed) — ControlMaster socket handles authentication
  • The SSH config entry is appended to ~/.ssh/config as a simple Host block
  • ControlMaster socket is stored at /tmp/coc_ssh_%r@%h:%p and auto-cleaned when the master process exits

Related skills

Provides guidance for Huawei Cloud KooCLI command-line tool operations. Covers KooCLI installation, IAM authentication configuration, access credential confi...

by huaweicloud-skills-team1 installs

Based on Huawei Cloud COC (Cloud Operations Center) APIs for script management and remote execution. Supports creating custom scripts (Shell, Python, Bat) and batch execution on target host instances via UniAgent. Applicable to cloud operations automation and batch script deployment scenarios. Trigger keywords: L-instance, COC script, script management, script execution, cloud operations, custom script, batch execution; COC, script management, script execution, cloud operations (中文触发词:L实例执行脚本).

by huaweicloud-skills-team

Queries Huawei Cloud ECS (Elastic Cloud Server) resources in read-only mode. Covers ECS instances, flavors, keypairs, quotas, server groups, block devices, NICs, VNC console, launch templates, recycle bin, scheduled events, and tags. No write operations. Use this skill when the user needs to query ECS instance details, list flavors, check server status, view block devices, or inspect ECS resource attributes. Triggers include: 查询ECS, ECS实例查询, 云服务器查询, 弹性云服务器, ECS规格, ECS配额, 云服务器列表, ECS详情, query ECS, list ECS servers, show server details, ECS flavors, ECS quotas, ECS keypairs, server groups, block devices, ECS inventory, cloud server list, ecs list, ecs query, ecs show.

Purchase Huawei Cloud X Instance server + one-click deploy SQLBot intelligent query application. Tech stack: Python 3.8+, Huawei Cloud SDK, COC (Cloud Operat...

by huaweicloud-skills-team1 installs

SSH-connect to Huawei Cloud Ascend servers for NPU monitoring, disk/LVM, and container ops with in-memory credentials.

by huaweicloud-skills-team2 installs

Query Huawei Cloud ECS CPU, memory, disk, and network metrics through Cloud Eye Service (CES) with hcloud CLI.

by huaweicloud-skills-team6 installs

More from huaweicloud-skills-team

Browse all skills

Manage Huawei Ascend NPUs with natural language commands that translate to npu-smi, locally or over SSH.

by huaweicloud-skills-team7 installs

Deploy and test LLM, VL, Embedding, and Rerank models on Huawei Cloud Ascend 910B DevServer with single- or dual-node topologies.

by huaweicloud-skills-team7 installs

Read-only queries against Huawei Cloud resources for inventory, verification, and parameter discovery.

by huaweicloud-skills-team6 installs

Query Huawei Cloud IAM resources (users, groups, policies, agencies, AK/SK, MFA, security settings) read-only via local Python SDK.

by huaweicloud-skills-team6 installs