gcloud compute tpus tpu-vm ssh [USER@]TPU [--dry-run] [--force-key-file-overwrite] [--internal-ip] [--plain] [--ssh-flag=SSH_FLAG] [--ssh-key-file=SSH_KEY_FILE] [--strict-host-key-checking=STRICT_HOST_KEY_CHECKING] [--worker=WORKER; default="0"] [--zone=ZONE] [--command=COMMAND --output-directory=OUTPUT_DIRECTORY] [--ssh-key-expiration=SSH_KEY_EXPIRATION | --ssh-key-expire-after=SSH_KEY_EXPIRE_AFTER] [GCLOUD_WIDE_FLAG …] [-- SSH_ARGS …]
gcloud compute tpus tpu-vm ssh my-tpuTo SSH into worker 1 on a Cloud TPU VM Pod, run:
gcloud compute tpus tpu-vm ssh my-tpu --worker=1To run an SSH command in a Cloud TPU VM (for example, to print the time since last boot), run:
gcloud compute tpus tpu-vm ssh my-tpu --command="last boot"To run the same command in all workers in a Cloud TPU VM simultaneously, run:
gcloud compute tpus tpu-vm ssh my-tpu --command="last boot" --worker=allUSER@]TPU
specifies the username with which to
SSH. If omitted, the user login name is used.
USER
TPU specifies the name of the Cloud TPU VM
to SSH into.
SSH_ARGS …]gcloud compute tpus tpu-vm ssh example-instance --zone=us-central1-a -- -vvv -L 80:%TPU%:80--dry-run--force-key-file-overwrite--internal-ip--plainssh(1)/scp(1)
flags. This flag is useful if you want to take care of authentication yourself
or use specific ssh/scp features.
--ssh-flag=SSH_FLAGssh(1). It is recommended that
flags be passed using an assignment operator and quotes. Example:
gcloud compute tpus tpu-vm ssh example-instance --zone=us-central1-a --ssh-flag="-vvv" --ssh-flag="-L 80:localhost:80"
This flag will replace occurences of
and %USER% with their dereferenced values.
For example, passing ``80:%TPU%:80`` into the flag is equivalent to passing
%TPU% to
80:162.222.181.197:80ssh(1) if the external IP address of 'example-instance' is
162.222.181.197.
--ssh-key-file=SSH_KEY_FILE~/.ssh/google_compute_engine.
--strict-host-key-checking=STRICT_HOST_KEY_CHECKINGSTRICT_HOST_KEY_CHECKING must be one of:
yes, no, ask.
--worker=WORKER; default="0"--command
flag, it additionally supports a comma-separated list (e.g. '1,4,6'), range
(e.g. '1-3'), or special keyword ``all" to run the command concurrently on each
of the specified workers.
Note that when targeting multiple workers, you should run 'ssh-add' with your
private key prior to executing the gcloud command. Default: 'ssh-add
~/.ssh/google_compute_engine'.
--zone=ZONEcompute/zone property isn't set, you might
be prompted to select a zone (interactive mode only).
To avoid prompting when this flag is omitted, you can set the
property:
compute/zone
gcloud config set compute/zone ZONEA list of zones can be fetched by running:
gcloud compute zones listTo unset the property, run:
gcloud config unset compute/zoneCLOUDSDK_COMPUTE_ZONE.
These arguments are used to run commands using SSH.
--command=COMMANDRuns the command on the target Cloud TPU VM and then exits.
Note: in the case of a TPU Pod, it will only run the command in the workers specified with the--worker flag (defaults to worker 0 if not set).
--output-directory=OUTPUT_DIRECTORYThe path can be relative or absolute. The directory must already exist.
If not specified, standard output will be used.
The logs will be written in files named {WORKER_ID}.log. For example: "2.log".--ssh-key-expiration=SSH_KEY_EXPIRATION--ssh-key-expire-after=SSH_KEY_EXPIRE_AFTER--access-token-file,
--account, --billing-project,
--configuration,
--flags-file,
--flatten, --format, --help, --impersonate-service-account,
--log-http,
--project, --quiet, --trace-token, --user-output-enabled,
--verbosity.
Run $ gcloud help for details.
gcloud alpha compute tpus tpu-vm ssh
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.