我想实现这个场景:在AWS上,我有一个VPC,它部署了一个公共和私有子网.在公有子网中,我有一个"堡垒"实例,而在私有子网中,有一个节点运行一些服务(AKA"服务实例").通过使用*nux ssh命令,我可以执行以下操作,从本地笔记本电脑连接到"服务实例":
ssh -t -o ProxyCommand="ssh -i <key> ubuntu@<bastion-ip> nc %h %p" -i <key> ubuntu@<service-instance-ip>
Run Code Online (Sandbox Code Playgroud)
我有一个Go程序,想要做以下事情:
- ssh通过"堡垒"从"本地笔记本电脑"连接到"服务实例"
- 使用连接会话来运行一些命令(例如"ls -l")
- 将文件从"本地笔记本电脑"上传到"服务实例"
我已经尝试但无法实现与此相同的过程
ssh -t -o ProxyCommand="ssh -i <key> ubuntu@<bastion-ip> nc %h %p" -i <key> ubuntu@<service-instance-ip>
Run Code Online (Sandbox Code Playgroud)
有人可以帮我看一个例子吗?谢谢!
顺便说一句,我发现了这个:https: //github.com/golang/go/issues/6223,这意味着它绝对能够做到这一点,对吧?
Jim*_*imB 10
您可以在没有nc命令的情况下使用"x/crypto/ssh"更直接地执行此操作,因为有一种方法可以从远程主机拨打连接并将其显示为net.Conn.
有了之后ssh.Client,您可以使用该Dial方法net.Conn在您和最终主机之间获取虚拟.然后,您可以将其转换为新ssh.Conn的ssh.NewClientConn,并创建一个新ssh.Client的ssh.NewClient
// connect to the bastion host
bClient, err := ssh.Dial("tcp", bastionAddr, config)
if err != nil {
log.Fatal(err)
}
// Dial a connection to the service host, from the bastion
conn, err := bClient.Dial("tcp", serviceAddr)
if err != nil {
log.Fatal(err)
}
ncc, chans, reqs, err := ssh.NewClientConn(conn, serviceAddr, config)
if err != nil {
log.Fatal(err)
}
sClient := ssh.NewClient(ncc, chans, reqs)
// sClient is an ssh client connected to the service host, through the bastion host.
Run Code Online (Sandbox Code Playgroud)