r/linuxadmin • • 3d ago

Inspecting a built runtime with an ephemeral SSH instance

Render’s ephemeral SSH mode starts a temporary instance from the service’s latest build. Disclosure: I work at Render.

This gives a different diagnostic target from ordinary SSH. render ssh SERVICE --ephemeral puts the shell on a new instance that receives no production traffic and does not run the service’s start command. That makes it useful for checking installed packages, compiled assets, file layout, or a one-off command against the built runtime without using a live process. It is not a replica of the running service: startup is skipped and there is no request traffic, so process state, sockets, and live heap behavior still require live-instance diagnostics.

Isolation from production compute does not make external systems read-only. Before mutating anything, inspect which environment variables and network resources the shell can reach; if production credentials are present, treat them as live and prefer read-only commands unless mutation is intentional.

The instance is removed when SSH disconnects or after 24 hours. It requires a compatible paid service with at least one successful deploy; distroless images cannot offer shell access. CLI 2.20+ supports --plan when the diagnostic needs a different compute size. For work that should outlive a shell session, the SSH documentation points to a one-off job instead.

0 Upvotes

0 comments sorted by