Skip to content

Fix dstack apply --ssh-identity - #4191

Merged
un-def merged 1 commit into
masterfrom
issue_4190_fix_dstack_apply_ssh_identity
Aug 21, 2026
Merged

Fix dstack apply --ssh-identity#4191
un-def merged 1 commit into
masterfrom
issue_4190_fix_dstack_apply_ssh_identity

Conversation

@un-def

@un-def un-def commented Aug 21, 2026

Copy link
Copy Markdown
Collaborator
  • Report a proper error instead of a traceback if the key file does not exist or cannot be parsed
  • Generate the public key from the private key if there is no .pub file, as the API docstrings already claimed
  • Pass the key to Run.attach(), so that the run SSH config no longer falls back to ~/.dstack/ssh/id_rsa
  • Reject public key paths, as SSH tunneling requires a private key

Refactoring and related changes:

  • Add the resolve_ssh_key() helper that resolves a private or public key path to key contents and paths, and reuse it in the fleet configurator, which had the same logic inlined
  • Look up <key>.pub instead of <key stem>.pub, which resolved to a wrong path for key names with dots
  • Add ssh_key_pub to RunCollection.get_run_plan() and apply_configuration() for public keys not stored on disk, mutually exclusive with ssh_identity_file
  • dstack fleet: raise CLIError instead of printing an error and exiting with a zero exit code

Fixes: #4190
Co-authored-by: Claude Opus 5 (1M context) noreply@anthropic.com

* Report a proper error instead of a traceback if the key file does not
  exist or cannot be parsed
* Generate the public key from the private key if there is no `.pub`
  file, as the API docstrings already claimed
* Pass the key to `Run.attach()`, so that the run SSH config no longer
  falls back to `~/.dstack/ssh/id_rsa`
* Reject public key paths, as SSH tunneling requires a private key

Refactoring and related changes:

* Add the `resolve_ssh_key()` helper that resolves a private or public
  key path to key contents and paths, and reuse it in the fleet
  configurator, which had the same logic inlined
* Look up `<key>.pub` instead of `<key stem>.pub`, which resolved to a
  wrong path for key names with dots
* Add `ssh_key_pub` to `RunCollection.get_run_plan()` and
  `apply_configuration()` for public keys not stored on disk, mutually
  exclusive with `ssh_identity_file`
* `dstack fleet`: raise `CLIError` instead of printing an error and
  exiting with a zero exit code

Fixes: #4190
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@un-def
un-def merged commit 511c318 into master Aug 21, 2026
27 checks passed
@un-def
un-def deleted the issue_4190_fix_dstack_apply_ssh_identity branch August 21, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: [CLI] dstack apply --ssh-identity is broken

1 participant