- NAME
-
- gcloud alpha compute instance-groups ssh - SSH into instances of a Compute Engine instance group
- SYNOPSIS
-
-
gcloud alpha compute instance-groups sshNAME--command=COMMAND[--batch-size=BATCH_SIZE; default="all"] [--container=CONTAINER] [--dry-run] [--endpoint-mode=ENDPOINT_MODE] [--force-key-file-overwrite] [--output-directory=OUTPUT_DIRECTORY] [--plain] [--ssh-flag=SSH_FLAG] [--ssh-key-file=SSH_KEY_FILE] [--strict-host-key-checking=STRICT_HOST_KEY_CHECKING] [--user=USER] [--internal-ip|--tunnel-through-iap] [--region=REGION|--zone=ZONE] [--ssh-key-expiration=SSH_KEY_EXPIRATION|--ssh-key-expire-after=SSH_KEY_EXPIRE_AFTER] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(ALPHA)gcloud alpha compute instance-groups sshruns an SSH command concurrently on all running Compute Engine VM instances in a specified Instance Group (managed or unmanaged; unless--batch-sizeis specified).Within a batch, all instances are executed concurrently even if the command fails on some instances. When executing across multiple batches (via
--batch-size), if the command fails on any instance in a batch, subsequent batches are not executed. After execution completes, a summary of succeeded, failed (with their exit codes), and skipped instances (formatted by batch when multiple batches are used) is printed to standard error. If the command succeeds on all target instances,gcloud alpha compute instance-groups sshexits with status0. If the command fails on one or more instances,gcloud alpha compute instance-groups sshexits with the first non-zero exit status encountered (255for SSH connection or client errors, or the remote command's non-zero exit code). - EXAMPLES
-
To run an SSH command concurrently on all instances in Instance Group
my-groupin zoneus-central1-a, run:gcloud alpha compute instance-groups ssh my-group --zone=us-central1-a --command="hostname"To run an SSH command with a custom batch size on a regional Managed Instance Group
my-regional-migin regionus-central1, run:gcloud alpha compute instance-groups ssh my-regional-mig --region=us-central1 --command="uptime" --batch-size=4 - POSITIONAL ARGUMENTS
-
NAME- Name of the instance group to operate on.
- REQUIRED FLAGS
-
--command=COMMAND-
Command to run concurrently on all instances in the specified Instance Group
(unless
--batch-sizeis specified). Runs the command on each target instance and then exits.
- OPTIONAL FLAGS
-
--batch-size=BATCH_SIZE; default="all"-
Batch size for simultaneous command execution on the client's side. This flag
takes a value greater than 0 to specify the batch size to control concurrent
connections, or the special keyword
to allow concurrent command execution on all instances in the Instance Group. If the command fails on any instance in a batch, subsequent batches are not executed.all --container=CONTAINER- The name or ID of a container inside of the virtual machine instance to connect to. This only applies to virtual machines that are using a Google Container-Optimized virtual machine image. For more information, see https://cloud.google.com/compute/docs/containers.
--dry-run- Print the equivalent scp/ssh command that would be run to stdout, instead of executing it.
--endpoint-mode=ENDPOINT_MODE-
Specifies endpoint mode for a given command. Regional endpoints provide enhanced
data residency and reliability by ensuring your request is handled entirely
within the specified Google Cloud region. This differs from global endpoints,
which may process parts of the request outside the target region. Overrides the
default
regional/endpoint_modeproperty value for this command invocation.ENDPOINT_MODEmust be one of:global- (Default) Use global rather than regional endpoints.
regional- Only use regional endpoints. An error will be raised if a regional endpoint is not available for a given command.
regional-preferred- Use regional endpoints when available, otherwise use global endpoints. Recommended for most users.
--force-key-file-overwrite-
If enabled, the gcloud command-line tool will regenerate and overwrite the files
associated with a broken SSH key without asking for confirmation in both
interactive and non-interactive environments.
If disabled, the files associated with a broken SSH key will not be regenerated and will fail in both interactive and non-interactive environments.
--output-directory=OUTPUT_DIRECTORY-
Path to the directory to output the logs of the commands.
The path can be relative or absolute. The directory must already exist.
If not specified, standard output will be used.
The logs will be written in files named {INSTANCE_NAME}.log.
--plain-
Suppress the automatic addition of
ssh(1)/scp(1)flags. This flag is useful if you want to take care of authentication yourself or use specific ssh/scp features. --ssh-flag=SSH_FLAG-
Additional flags to be passed to
ssh(1). It is recommended that flags be passed using an assignment operator and quotes.This flag will replace occurrences of
,%USER%,%INSTANCE%,%INTERNAL%,%NAME%, and%ZONE%with their dereferenced values for each target instance.%PROJECT%,%NAME%, and%ZONE%are replaced with the instance name, zone, and project ID respectively. If connecting to the instance's external IP, then%PROJECT%is replaced with that, otherwise it is replaced with the internal IP.%INSTANCE%is always replaced with the internal IP of the instance.%INTERNAL% --ssh-key-file=SSH_KEY_FILE-
The path to the SSH key file. By default, this is
.~/.ssh/google_compute_engine --strict-host-key-checking=STRICT_HOST_KEY_CHECKING-
Override the default behavior of StrictHostKeyChecking for the connection. By
default, StrictHostKeyChecking is set to 'no' the first time you connect to an
instance, and will be set to 'yes' for all subsequent connections.
STRICT_HOST_KEY_CHECKINGmust be one of:yes,no,ask. --user=USER- Username with which to SSH into the instances. If omitted, the default login user is used.
-
At most one of these can be specified:
--internal-ip-
Connect to instances using their internal IP addresses rather than their
external IP addresses. Use this to connect from one instance to another on the
same VPC network, over a VPN connection, or between two peered VPC networks.
For this connection to work, you must configure your networks and firewall to allow SSH connections to the internal IP address of the instance to which you want to connect.
To learn how to use this flag, see https://cloud.google.com/compute/docs/instances/connecting-advanced#sshbetweeninstances.
--tunnel-through-iap-
Tunnel the ssh connection through Cloud Identity-Aware Proxy for TCP forwarding.
To learn more, see the IAP for TCP forwarding documentation.
-
At most one of these can be specified:
--region=REGION-
Region of the instance group to operate on. If not specified, you might be
prompted to select a region (interactive mode only).
A list of regions can be fetched by running:
gcloud compute regions listOverrides the default
compute/regionproperty value for this command invocation. --zone=ZONE-
Zone of the instance group to operate on. If not specified, you might be
prompted to select a zone (interactive mode only).
A list of zones can be fetched by running:
gcloud compute zones listOverrides the default
compute/zoneproperty value for this command invocation.
-
At most one of these can be specified:
--ssh-key-expiration=SSH_KEY_EXPIRATION- The time when the ssh key will be valid until, such as "2017-08-29T18:52:51.142Z." This is only valid if the instance is not using OS Login. See $ gcloud topic datetimes for information on time formats.
--ssh-key-expire-after=SSH_KEY_EXPIRE_AFTER- The maximum length of time an SSH key is valid for once created and installed, e.g. 2m for 2 minutes. See $ gcloud topic datetimes for information on duration formats.
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - NOTES
- This command is currently in alpha and might change without notice. If this command fails with API permission errors despite specifying the correct project, you might be trying to access an API with an invitation-only early access allowlist.
gcloud alpha compute instance-groups ssh
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-10-06 UTC.