Skip to content

Support access and log submission

When VirtConsole support needs to investigate something on your installation, you have two options. You can grant the support team temporary SSH access to your management server or a hypervisor with a one-line script, or, when policy forbids SSH access, you can send the tail of a log file over an encrypted, password-protected paste service instead.

A one-line script downloads the VirtConsole support SSH public key and appends it to ~/.ssh/authorized_keys. The same script removes the key when you are done. The script itself never stays on disk.

  • The key is downloaded over HTTPS only.
  • The downloaded key is verified against a SHA-256 checksum before it is installed, so a tampered key cannot land on your server.
  • Your existing authorized_keys file is backed up before it is touched.
  • Removing the key touches only the VirtConsole support key; your own keys are untouched.

Run these from the shell of the server you are granting access to (the management server or a hypervisor):

Command What it does
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- add Install the support key
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- remove Remove the support key
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- check Check whether the key is installed
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- backup Back up authorized_keys
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- help Built-in help
  1. Grant access for the support session:

    Terminal window
    curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- add
  2. When the session is over, revoke it:

    Terminal window
    curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- remove

    The remove action backs up authorized_keys first, then removes only the VirtConsole key.

Manual backups land in ~/.ssh/hypervisor_backups/ with a timestamped filename. Audit that directory periodically and delete old backups.

When you cannot grant SSH access, send the evidence instead. On the management server, vcli support:send-log uploads the tail of any log file you choose to the VirtConsole encrypted paste service. The paste is password-protected automatically, and its content is shredded after a fixed period. You decide exactly what gets sent.

  1. Run the command with the log path and how many lines to include from the end of the file:

    Terminal window
    vcli support:send-log /var/log/virtconsole/app.log --lines=1000

    The default is the last 50 lines when --lines is omitted.

  2. The command prints the paste URL and its password:

    Reading last 1000 lines from: /var/log/virtconsole/app.log
    Sending content to Support Team...
    Successfully sent to Support!
    URL: https://paste.example.com/auth/word-word-word, Password: xxxxxxxxxxxxxxx
  3. Share the URL and the password with the support team through your usual channel (your ticket, a chat message). You do not need to send both in the same message.

Separately from SSH support access, your customers can request access to restricted locations (hypervisor groups) from their panel. Those requests queue at Infrastructure > Access requests, where you Approve or Deny each one. See Cloud Service for how location access works.

  • The support script fails with a permission error. Your SSH directory permissions are wrong. Fix them with chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys and retry.
  • support:send-log reports the file does not exist or is not readable. Check the path and that the user running vcli can read the file.
  • Support says the paste link does not work. The paste may have been shredded after its retention window. Run the command again and share the new URL and password.