| name | qemu-alpine-ssh |
| description | This skill provides guidance for setting up Alpine Linux virtual machines in QEMU with SSH access via port forwarding. It should be used when tasks involve running Alpine Linux in QEMU, configuring SSH access to VMs, setting up port forwarding for VM network access, or troubleshooting QEMU networking issues. |
QEMU Alpine SSH Setup
Overview
This skill guides the setup of Alpine Linux virtual machines in QEMU with SSH access configured through port forwarding. The typical goal is to have a running Alpine VM accessible via SSH on a forwarded host port.
Critical Pre-Flight Checks
Before starting QEMU, always perform these checks to avoid common failures:
1. Check for Port Conflicts
The most common cause of QEMU startup failures is a port already in use. Always check before starting:
ss -tlnp | grep :<port>
lsof -i :<port>
If the port is in use, either:
- Kill the process using it:
fuser -k <port>/tcp
- Choose a different port
2. Check for Orphaned QEMU Processes
Previous QEMU instances may still be running from failed attempts:
ps aux | grep qemu-system
pgrep -la qemu
Clean up any orphaned processes before starting a new instance:
pkill -f "qemu-system-x86_64" || true
sleep 1
pgrep qemu && echo "WARNING: QEMU still running" || echo "Clean"
3. Verify Required Files
Ensure ISO/disk images exist and are accessible before attempting to boot.
Recommended Approach
Phase 1: Start QEMU with Port Forwarding
Start QEMU with user-mode networking and port forwarding:
qemu-system-x86_64 \
-m 512M \
-cdrom alpine.iso \
-boot d \
-netdev user,id=net0,hostfwd=tcp::<host_port>-:22 \
-device virtio-net-pci,netdev=net0 \
-nographic
Key parameters:
-m 512M: Allocate sufficient memory (256MB minimum, 512MB recommended)
-netdev user,id=net0,hostfwd=tcp::<port>-:22: User-mode networking with port forwarding
-nographic: Console-only mode for scripted interaction
Phase 2: Configure the VM
After VM boots, perform configuration in this order:
-
Set root password:
passwd
-
Configure networking inside VM:
ifconfig eth0 up
udhcpc -i eth0
-
Set up package repositories:
setup-apkrepos -1
-
Install SSH server:
apk update
apk add openssh
-
Configure SSH for root login:
sed -i 's/#PermitRootLogin.*/PermitRootLogin yes/' /etc/ssh/sshd_config
grep "^PermitRootLogin" /etc/ssh/sshd_config
-
Start SSH service:
rc-update add sshd
rc-service sshd start
Phase 3: Verify Setup
After configuration, verify each component:
- SSH service running:
rc-status | grep sshd
- Port forwarding working: From host,
ss -tlnp | grep :<host_port>
- SSH connection:
ssh -o ConnectTimeout=5 -p <host_port> root@localhost
Common Pitfalls
Port Binding Failures
Symptom: QEMU fails to start or port forwarding doesn't work.
Common mistake: Trying different hostfwd syntax variations when the syntax is correct but the port is in use.
Correct approach: Always check port availability first. All of these syntaxes are valid:
hostfwd=tcp::<port>-:22
hostfwd=tcp:127.0.0.1:<port>-:22
hostfwd=tcp:0.0.0.0:<port>-:22
If one fails, the issue is usually NOT the syntax.
SSH Connection Refused
Symptom: Cannot connect via SSH even though VM appears to be running.
Check in order:
- Is sshd running in VM?
- Is
PermitRootLogin yes set in sshd_config?
- Was sshd restarted after config change?
- Is the network interface up with an IP?
Network Not Working in VM
Symptom: Cannot install packages, DNS fails.
Resolution:
- Bring up interface:
ifconfig eth0 up
- Get DHCP lease:
udhcpc -i eth0
- If DNS fails:
echo "nameserver 8.8.8.8" > /etc/resolv.conf
Verification Strategies
Incremental Verification
Verify each step before proceeding to the next. Do not assume success.
After running commands that modify configuration:
- Use
grep or cat to verify changes took effect
- Check service status after starting services
- Test connectivity at each stage
Final Verification Checklist
Before declaring the task complete, verify ALL of:
Debugging Failed States
When things fail, diagnose systematically rather than trying random variations:
- Identify the failure point: Which specific step failed?
- Check prerequisites: Are all prerequisites for that step satisfied?
- Examine error messages: What exactly does the error say?
- Check resource conflicts: Ports, processes, file locks
- Verify intermediate state: Did previous steps actually succeed?
For detailed troubleshooting steps, consult references/troubleshooting.md.
Resources
references/
troubleshooting.md: Detailed diagnosis and resolution steps for common issues including port conflicts, SSH failures, and network configuration problems.