Access an AI Virtual Machine
You reach an AI Virtual Machine with virtctl, the KubeVirt command line tool, against the Compute Pool's cluster. virtctl proxies through the cluster's KubeVirt API, so there is no separate SSH endpoint to expose and no firewall rule to add. The PaletteAI console provides the kubeconfig for the cluster, but it does not host a terminal or a console session, so virtctl is required.
Prerequisites
- A running AI Virtual Machine. For the states a virtual machine reports, refer to Troubleshoot AI Virtual Machines.
- Access to the Compute Pool that runs it.
Get the Compute Pool Cluster Kubeconfig
- From the left main menu, open Compute Pools, and select the Compute Pool that runs your AI Virtual Machine.
- Select the Clusters tab.
- In the Kubeconfig column, download the kubeconfig file for the cluster.
Point kubectl at the file, and list the virtual machines on the cluster:
export KUBECONFIG=/path/to/<cluster-name>.kubeconfig
kubectl get virtualmachines --namespace default
NAME AGE
gpu-dev-vm-4bbfa220 5m
cpu-sandbox-93cece96 2d
AI Virtual Machines run in the default namespace on the Compute Pool cluster. The virtual machine has its own name on that cluster, which PaletteAI derives, so it can differ from the AI Virtual Machine's name in the console. Use the name the command prints in the commands that follow.
Install virtctl
Install virtctl at the same KubeVirt minor version as the Compute Pool's cluster. Download the release archive for your platform from the KubeVirt releases page, or install the plugin through Krew:
kubectl krew install virt
If you install through Krew, the plugin is invoked as kubectl virt rather than virtctl, so run kubectl virt where the commands below use virtctl. For more on the client tool, refer to the KubeVirt virtctl documentation.
Confirm the install, using kubectl virt in place of virtctl if you installed through Krew:
virtctl version --client
Connect over a Serial Console
The serial console needs nothing beyond the credentials, so it is the quickest way in. Connect with virtctl console, substituting the virtual machine name from the list above:
virtctl console <vm-name> --namespace default
The command attaches to the running instance and drops you at the guest's login prompt, where you sign in as pai with the password pai. Leave the console with Ctrl+] or Ctrl+5.
The built-in templates expire the pai password, so the first sign-in over any of these connections forces you to set a new password, and pai stops working from that point. Keep the new password, and keep a console or VNC session available as a way back in. Refer to Change AI Virtual Machine Credentials.
Connect over SSH
SSH hands the connection to the SSH client on your machine, so the first connection asks you to confirm the virtual machine's host key. Accept the key when it is offered, or let the client accept a key it has not seen before without stopping to ask:
virtctl ssh pai@vm/<vm-name> --namespace default
The built-in templates create the pai user with the password pai and enable password sign-in. To use an SSH key instead of the password, add --identity-file.
Connect over VNC
VNC attaches to the running instance, so the virtual machine must be in the Running state. Start a session with:
virtctl vnc <vm-name> --namespace default
virtctl vnc starts a proxy and hands it to a VNC viewer on your machine, such as remote-viewer or tiger-vnc. If no viewer is installed, add --proxy-only to print the local port and point your own viewer at it. Use --vnc-path to name a viewer that is not on your PATH.
Like the serial console, VNC works when SSH does not, for example while cloud-init is still finishing on first boot.
Troubleshoot the Connection
- The virtual machine is not in the Running state, so there is nothing to connect to. Refer to Manage an AI Virtual Machine.
- SSH stops at a host key prompt. The first connection asks you to confirm the virtual machine's host key. Accept it, or pass it through with
--local-ssh-opts='-o StrictHostKeyChecking=accept-new'. - SSH refuses the
paipassword. The password expires at first sign-in, so use the password you set, or connect over the serial console and set a new one. Refer to Change AI Virtual Machine Credentials. - The virtual machine name is not found. Read it from
kubectl get virtualmachines, since the name on the cluster can differ from the console name. kubectlcannot reach the cluster. Confirm the kubeconfig file is the one downloaded for this Compute Pool's cluster.
For failures that come from the AI Virtual Machine itself, refer to Troubleshoot AI Virtual Machines.
Next Steps
- Change AI Virtual Machine Credentials: replace the default user and password.
- Manage an AI Virtual Machine: start, stop, clone, or delete it.