Support access and log submission
When VirtConsole support needs to investigate something on your installation, you have two options. You can grant the support team temporary SSH access to your management server or a hypervisor with a one-line script, or, when policy forbids SSH access, you can send the tail of a log file over an encrypted, password-protected paste service instead.
Grant SSH support access
Section titled “Grant SSH support access”A one-line script downloads the VirtConsole support SSH public key and appends it to ~/.ssh/authorized_keys. The same script removes the key when you are done. The script itself never stays on disk.
How it is kept safe
Section titled “How it is kept safe”- The key is downloaded over HTTPS only.
- The downloaded key is verified against a SHA-256 checksum before it is installed, so a tampered key cannot land on your server.
- Your existing
authorized_keysfile is backed up before it is touched. - Removing the key touches only the VirtConsole support key; your own keys are untouched.
Commands
Section titled “Commands”Run these from the shell of the server you are granting access to (the management server or a hypervisor):
| Command | What it does |
|---|---|
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- add |
Install the support key |
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- remove |
Remove the support key |
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- check |
Check whether the key is installed |
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- backup |
Back up authorized_keys |
curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- help |
Built-in help |
Grant, then revoke
Section titled “Grant, then revoke”-
Grant access for the support session:
Terminal window curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- add -
When the session is over, revoke it:
Terminal window curl -sSL https://packages.virtconsole.com/tools/hv_support.sh | bash -s -- removeThe remove action backs up
authorized_keysfirst, then removes only the VirtConsole key.
Manual backups land in ~/.ssh/hypervisor_backups/ with a timestamped filename. Audit that directory periodically and delete old backups.
Send a log to support
Section titled “Send a log to support”When you cannot grant SSH access, send the evidence instead. On the management server, vcli support:send-log uploads the tail of any log file you choose to the VirtConsole encrypted paste service. The paste is password-protected automatically, and its content is shredded after a fixed period. You decide exactly what gets sent.
-
Run the command with the log path and how many lines to include from the end of the file:
Terminal window vcli support:send-log /var/log/virtconsole/app.log --lines=1000The default is the last
50lines when--linesis omitted. -
The command prints the paste URL and its password:
Reading last 1000 lines from: /var/log/virtconsole/app.logSending content to Support Team...Successfully sent to Support!URL: https://paste.example.com/auth/word-word-word, Password: xxxxxxxxxxxxxxx -
Share the URL and the password with the support team through your usual channel (your ticket, a chat message). You do not need to send both in the same message.
Related panel queue
Section titled “Related panel queue”Separately from SSH support access, your customers can request access to restricted locations (hypervisor groups) from their panel. Those requests queue at Infrastructure > Access requests, where you Approve or Deny each one. See Cloud Service for how location access works.
Common problems
Section titled “Common problems”- The support script fails with a permission error. Your SSH directory permissions are wrong. Fix them with
chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keysand retry. support:send-logreports the file does not exist or is not readable. Check the path and that the user runningvclican read the file.- Support says the paste link does not work. The paste may have been shredded after its retention window. Run the command again and share the new URL and password.

