# SSH to node from "My Interactive Sessions" screen (clicking blue \[\>\_nodename.cluster\] button) not working

**URL:** <https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724>\
**Category:** Get Help\
**Tags:** ondemand2, question\
**Created:** [October 13, 2021, 8:36pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724 "2021-10-13T20:36:32Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [October 13, 2021, 8:36pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/1 "2021-10-13T20:36:32Z")

</div>

Hi there,

One of my users reported that clicking on the button with the nodename, shown below, doesn’t work:

![Screen Shot 2021-10-13 at 4.34.02 PM](https://us1.discourse-cdn.com/flex015/uploads/osc/original/1X/f4786c863f29a92a43f33dded7e7352ea387da01.png)

I didn’t realize that was there, so I hadn’t tested it, but they are right. I get the following error:

“Failed to establish a websocket connection. Be sure you are using a browser that supports websocket connections.”

I’m aware that Safari doesn’t support this, but it doesn’t work in Firefox or Chrome either. We run the Desktop app via a Singularity container, if that makes a difference.

How can I go about troubleshooting this? I’m not sure what this function is called (hence the clunky title), so I’m not sure if there are any docs.

The URL, in case that helps, is:

`https://<servername>/pun/sys/shell/ssh/<nodename>`

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 14, 2021, 2:02pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/2 "2021-10-14T14:02:00Z")

</div>

Does your site allow folks to ssh into compute nodes? There’s a way to disable this feature altogether, so the button won’t appear (though I’ll have to look it up if you’d like that).

But essentially, it works as you indicate - just uses the shell app to shell into a compute node. My guess is you have some connectivity issues or just don’t allow shelling into compute nodes.

If you want to allow this, you have to enable your compute nodes through the shell allow list. Here’s our allowlist for our compute nodes.

> <https://github.com/OSC/osc-ood-config/blob/8de57f4a61648f23317c9ffaceb0b644cb83f9d6/class.osc.edu/apps/shell/env#L3>

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [October 14, 2021, 7:15pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/3 "2021-10-14T19:15:38Z")

</div>

Thanks, Jeff! The issue was that environment variable not being defined. I hadn’t realized it existed. It’s actually not mentioned anywhere in the `apps/shell/README.md`, or in the docs for the shell app on Github that I can see. The only variable mentioned is `DEFAULT_SSHHOST`. Is there a doc somewhere that might explain the difference between `DEFAULT_SSHHOST` and `OOD_DEFAULT_SSHHOST`, for example?

At our site, anyone who’s got a job running on a compute node can SSH from the login node to that compute node (uses the PAM module that comes with SLURM to control that), which would be satisfied by a running desktop. This does seem to work as expected with the right allow list.

Kind of would be nice if this could accept the same list as `/etc/ood/config/ood_portal.yml`'s `host_regex` parameter, or even inherit that list, since it seems likely that you’d want it to default to allowing SSH to the same hosts, if you want to enable SSH at all.

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [October 14, 2021, 7:18pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/4 "2021-10-14T19:18:22Z")

</div>

Ah, another user at my site pointed me over here: [Customization — Open OnDemand 2.0.13 documentation](https://osc.github.io/ood-documentation/latest/customization.html)

(interesting that it calls that link 2.0.13 documentation; the URL I used has no version number)

Probably should also be mentioned in the shell app docs, I guess.

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [December 6, 2021, 4:58pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/5 "2021-12-06T16:58:56Z")

</div>

This has somehow stopped working for me again, despite having that environment variable defined and this having been working before. Is there anything else one can use to troubleshoot? I’m getting the same error as the original. Just in case I wrote a bad allow list, I put only the host I’m trying to connect to in there (and did `touch tmp/restart.txt` in the appropriate place). I don’t see any log files anywhere. I confirmed I can freely SSH between the OOD server and the compute node in question.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [December 6, 2021, 5:03pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/6 "2021-12-06T17:03:13Z")

</div>

I think the best practice for restarting is ‘Restart Web Server’ link in the help menu. Don’t know where you `touch tmp.restart.txt` but that implies you’re restarting your development version of the dashboard. Is this where you’re working? Touching the system restart file (I’d have to lookup where that is) will restart **everyone’s** dashboard.

I’m also not sure if we log any of our denials - which is something we should remedy.

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [December 6, 2021, 6:13pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/7 "2021-12-06T18:13:40Z")

</div>

It’s a test system, so it doesn’t really matter, but I’ve instead tried “Restart Web Server” and am having the same problem. I even took the node name from the URL that launches the shell app and searched the /etc/ood/config/apps/shell/env file to make sure I had no typo. I currently only have the node I have a session on defined in the file to eliminate any chance of a more complicated error.

Is there any debugging I could enable to see what’s going on?

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [December 6, 2021, 7:16pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/8 "2021-12-06T19:16:40Z")

</div>

Unfortunately, I’m not sure if there’s an easy way to see this info unless you hack the shell app.

I think first confirm it’s indeed an issue with the allowlist. You should get 401 with this error message if that’s indeed what’s happening now. (I pull this from the network tab of my browser).

![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/1X/245e1c301fb3c72b2107b5f4f2524f4fcc093eba.png)

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [December 6, 2021, 11:16pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/9 "2021-12-06T23:16:37Z")

</div>

It doesn’t really look like a 401 error is the problem or happening, though mine doesn’t look exactly like yours:

 ![Screen Shot 2021-12-06 at 6.15.54 PM](https://us1.discourse-cdn.com/flex015/uploads/osc/original/1X/432fb3fcf4abdffd8da57ce5622dd5b0a6f2ca6e.png)

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [December 7, 2021, 1:14am UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/10 "2021-12-07T01:14:32Z")

</div>

Sorry, we’re looking for the response headers not the request headers.

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [December 7, 2021, 9:32pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/11 "2021-12-07T21:32:53Z")

</div>

Mine still doesn’t look exactly like yours (maybe a version difference), and while I did find response headers on the second item in the list on the left, there are no response headers for the URL with wss:// – you can see there’s no response tab there where there is for this one.

 ![Screen Shot 2021-12-07 at 4.31.53 PM](https://us1.discourse-cdn.com/flex015/uploads/osc/original/1X/c1ae5ff91e16b1371c77fa91f5d01c8afe521d38.png)

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [December 7, 2021, 9:56pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/12 "2021-12-07T21:56:27Z")

</div>

Switched to Firefox and this one is calling out the allow list:

![Screen Shot 2021-12-07 at 4.51.11 PM](https://us1.discourse-cdn.com/flex015/uploads/osc/original/1X/5f7142c95aeaf6d04535926b75e71c14157e28be.png)

This seems fine to me?

```auto
[root@amarel-test2 ~]# cat /etc/ood/config/apps/shell/env 
OOD_SSHHOST_ALLOWLIST="slepner071.amarel.rutgers.edu"

```

---

<div class="post-metadata">

**Author:** ![novosirj](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/novosirj/32/339_2.png) [@novosirj](https://discourse.openondemand.org/u/novosirj)\
**Post date:** [December 7, 2021, 10:05pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/13 "2021-12-07T22:05:47Z")

</div>

Permissions on `/etc/ood/config/apps/shell` were `750`. Doh.

Sorry for wasting your time!

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [December 7, 2021, 10:07pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/14 "2021-12-07T22:07:18Z")

</div>

LOL. All’s well that ends well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [June 5, 2022, 10:08pm UTC](https://discourse.openondemand.org/t/ssh-to-node-from-my-interactive-sessions-screen-clicking-blue-nodename-cluster-button-not-working/1724/15 "2022-06-05T22:08:09Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
