Version v0.4.0 of the documentation is no longer actively maintained. The site that you are currently viewing is an archived snapshot. For up-to-date documentation, see the latest version.

GCP SSH connection

GCP SSH connection

Run commands on a Google Compute Engine VM over SSH from a task, via a managed Leoflow Connection. The host, port, and credentials are encrypted at rest and delivered to the task as AIRFLOW_CONN_<CONN_ID>.

Declare the provider

# leoflow.yaml
dag_id: gcpssh_run
connectors:
  - gcpssh

URI shape

gcpssh://<login>:<password>@<host>:<port>

The control plane percent-escapes the password; ComputeEngineSSHHook (which parses AIRFLOW_CONN_<ID>) un-escapes it back.

Fields the UI asks for

FieldRequiredNotes
Conn Idyese.g. gcpssh_default. Exported as AIRFLOW_CONN_GCPSSH_DEFAULT.
Conn Typeyesgcpssh.
HostyesThe VM’s IP or DNS name, e.g. 10.0.0.5.
PortoptionalDefaults to 22.
LoginyesThe OS login user on the VM.
PasswordyesStored encrypted at rest (ADR 0019). Percent-escaped in the URI.
ExtraoptionalJSON for hook-specific options (project, zone, IAP).

Example DAG

The hook is imported inside the task body so DAG parsing stays import-light.

# dag.py
from airflow.sdk import DAG, task


@task
def remote():
    from airflow.providers.google.cloud.hooks.compute_ssh import (
        ComputeEngineSSHHook,
    )

    hook = ComputeEngineSSHHook(gcp_conn_id="gcpssh_default")
    client = hook.get_conn()
    _, stdout, _ = client.exec_command("uname -a")
    return stdout.read().decode()


with DAG("gcpssh_run", schedule=None, catchup=False, tags=["example"]):
    remote()
# leoflow.yaml
schema_version: "1.0"
dag_id: gcpssh_run
python_version: "3.11"
connectors:
  - gcpssh

Security notes

  • Prefer keys / IAP over passwords: production Compute Engine SSH normally uses OS Login or an SSH key plus Identity-Aware Proxy; pass those in Extra. The password field is for environments that still rely on it.
  • Secrets in logs: never print() the URI — it carries the password. Log the host + login only.
  • gRPC channel (agent ↔ control plane): secrets are served only over an authenticated channel (ADR 0021); Pro must run with TLS.
  • ADR 0019 — secret encryption at rest.
  • ADR 0021 — agent secret delivery.
  • #67 — connectors umbrella.
  • #138 — the chain-of-custody contract test this page documents.