Create a service to connect with SSH
You can create a service for a virtual machine (VM) and connect to the IP address and port exposed by the service. Services provide excellent performance and are recommended for applications that are accessed from outside the cluster or within the cluster. Ingress traffic is protected by firewalls.
After you create a service with virtctl, you must add special: key to the spec.template.metadata.labels stanza of the VirtualMachine manifest. If the cluster network cannot handle the traffic load, consider using a secondary network for VM access.
About services
A Kubernetes service exposes network access for clients to an application running on a set of pods. Services offer abstraction, load balancing, and, in the case of the NodePort and LoadBalancer types, exposure to the outside world.
ClusterIPExposes the service on an internal IP address and as a DNS name to other applications within the cluster. A single service can map to multiple virtual machines. When a client tries to connect to the service, the client’s request is load balanced among available backends.
ClusterIPis the default service type.NodePortExposes the service on the same port of each selected node in the cluster.
NodePortmakes a port accessible from outside the cluster, provided that the node itself is externally accessible to the client.LoadBalancerCreates an external load balancer in the current cloud (if supported) and assigns a fixed, external IP address to the service.
For on-premise clusters, you can configure a load balancing service by deploying the MetalLB Operator.
Enabling load balancer service creation by using the web console
You can enable the creation of load balancer services for a virtual machine (VM) by using the OpenShift Container Platform web console.
Prerequisites
- You have configured a load balancer for the cluster.
- You have logged in as a user with the
cluster-adminrole. - You created a network attachment definition for the network.
Procedure
- Go to Virtualization → Settings.
- Click Cluster.
- Expand General settings and SSH configuration.
- Set SSH over LoadBalancer service to on.
Create a service with the web console
You can create a node port or load balancer service for a virtual machine (VM) by using the OpenShift Container Platform web console.
Prerequisites
- You configured the cluster network to support either a load balancer or a node port.
- To create a load balancer service, you enabled the creation of load balancer services.
Procedure
- Navigate to VirtualMachines and select a virtual machine to view the VirtualMachine details page.
- On the Details tab, select SSH over LoadBalancer from the SSH service type list.
- Optional: Click the copy icon to copy the
SSHcommand to your clipboard.
Verification
- Check the Services pane on the Details tab to view the new service.
Create a service with virtctl
You can create a service for a virtual machine (VM) by using the virtctl command-line tool.
Prerequisites
- You installed the
virtctlcommand-line tool. - You configured the cluster network to support the service.
- The environment where you installed
virtctlhas the cluster permissions required to access the VM. For example, you ranoc loginor you set theKUBECONFIGenvironment variable.
Procedure
- Create a service by running the following command:terminal
$ virtctl expose vm <vm_name> --name <service_name> --type <service_type> --port <port>where:
<vm_name>Specifies the name of the VM you are exposing.
<service_name>Specifies a user-defined name for the service you are creating.
<service_type>Specifies one of
ClusterIP,NodePort, orLoadBalancer.<port>Specifies the network port on the VM that the service will expose. Example:
terminal$ virtctl expose vm example-vm --name example-service --type NodePort --port 22
Verification
- Verify the service by running the following command:terminal
$ oc get service
Creating a service by using the CLI
You can create a service and associate it with a virtual machine (VM) by using the command line.
Prerequisites
- You configured the cluster network to support the service.
- You have installed the OpenShift CLI (
oc).
Procedure
- Edit the
VirtualMachinemanifest to add the label for service creation. Addspecial: keyto thespec.template.metadata.labelsstanza:yamlapiVersion: kubevirt.io/v1 kind: VirtualMachine metadata: name: example-vm namespace: example-namespace spec: runStrategy: Halted template: metadata: labels: special: key # ...NoteLabels on a virtual machine pass through to the pod. The
special: keylabel must match the label in thespec.selectorattribute of theServicemanifest. - Save the
VirtualMachinemanifest file to apply your changes. - Create a
Servicemanifest to expose the VM:yamlapiVersion: v1 kind: Service metadata: name: example-service namespace: example-namespace spec: # ... selector: special: key type: NodePort ports: protocol: TCP port: 80 targetPort: 9376 nodePort: 30000spec.selectordefines the label that you added to thespec.template.metadata.labelsstanza of theVirtualMachinemanifest.spec.typedefines the type of service by the way it is exposed. Choose one ofClusterIP,NodePort, orLoadBalancer.spec.portsdefines a collection of network ports and protocols to expose from the virtual machine.
- Save the
Servicemanifest file. - Create the service by running the following command:terminal
$ oc create -f example-service.yaml - Restart the VM to apply the changes.
Verification
- Query the
Serviceobject to verify that it is available:terminal$ oc get service -n example-namespace
Connecting to a VM exposed by a service by using SSH
You can connect to a virtual machine (VM) that a service exposes by using SSH.
Prerequisites
- You created a service to expose the VM.
- You have an SSH client installed.
- You are logged in to the cluster.
Procedure
- Run the following command to access the VM:terminal
$ ssh <user_name>@<ip_address> -p <port>where:
<ip_address>Specifies the cluster IP for a cluster IP service, the node IP for a node port service, or the external IP address for a load balancer service.