The gcp-compute mixed provider lists running Compute Engine instances with the Google Compute Engine Go client and returns them as dynamic server entries.
It also exposes a gcp-iap connector for IAP TCP forwarding based SSH access.
[providers]
paths = ["~/.config/lssh/providers/provider-mixed-gcp-compute"]
max_parallel = 4
[provider.gcp]
plugin = "provider-mixed-gcp-compute"
enabled = true
capabilities = ["inventory", "connector"]
project = "example-project"
credentials_file = "~/.config/gcloud/application_default_credentials.json"
addr_strategy = "public_first"
server_name_template = "gcp:${name}"
note_template = "gcp ${zone} ${private_ip}"
[provider.gcp.match.web_ssh]
meta_in = ["label.role=web", "label.connection=ssh"]
connector_name = "ssh"
user = "ubuntu"
key = "~/.ssh/gcp-web.pem"
[provider.gcp.match.web_sdk]
meta_in = ["label.role=web", "label.connection=iap-sdk"]
connector_name = "gcp-iap"
iap_runtime = "sdk"
zone = "asia-northeast1-a"
user = "ubuntu"
key = "~/.ssh/gcp-web.pem"
[provider.gcp.match.web_command]
meta_in = ["label.role=web", "label.connection=iap-command"]
connector_name = "gcp-iap"
iap_runtime = "command"
zone = "asia-northeast1-b"
user = "ubuntu"
key = "~/.ssh/gcp-web.pem"providers.pathsis intended to list provider executable files.providers.max_parallellimits simultaneousinventory.listcalls across configured providers.- unset or
0means no explicit limit
- unset or
- Uses Google Application Default Credentials by default.
credentials_filecan be used to point at a specific service-account or ADC JSON file.endpointandscopescan be overridden when needed.plugin.describereports connector namegcp-iap.iap_runtimecontrols the connector runtime.sdk(default): provider-managed IAP WebSocket + SSH transport for shell, exec, SFTP, mount, and local forwardingcommand:gcloud compute ssh --tunnel-through-iapbased transport
sdkruntime does not requiregcloudinPATH.- when
sdkandcommandhosts are mixed, setiap_runtimeon each server ormatchentry instead of provider-wide. addr_strategycontrols how generatedaddris chosen.private_first(default)public_firstprivate_onlypublic_only
- Only running instances are returned.
matchcan override SSH settings per generated host.- Available match metadata includes
name,id,project,zone,private_ip,public_ip, andlabel.<LabelName>. connector.describe/connector.preparerequireproject,zone, and instance metadata from this provider.shellandport_forward_localare available in both runtimes.exec,exec_pty,sftp_transport,upload,download,mount, and internaltcp_dial_transportare available insdkruntime.
[provider.gcp.match.web_ssh]
meta_in = ["label.connection=ssh"]
connector_name = "ssh"
user = "ubuntu"
key = "~/.ssh/gcp-web.pem"
[provider.gcp.match.web_sdk]
meta_in = ["label.connection=iap-sdk"]
connector_name = "gcp-iap"
iap_runtime = "sdk"
zone = "asia-northeast1-a"
user = "ubuntu"
key = "~/.ssh/gcp-web.pem"
[provider.gcp.match.web_command]
meta_in = ["label.connection=iap-command"]
connector_name = "gcp-iap"
iap_runtime = "command"
zone = "asia-northeast1-b"
user = "ubuntu"
key = "~/.ssh/gcp-web.pem"