Core Idea
Vagrant provisions VMs from a file:
vagrant upbuilds and configures the machine automatically, and this note focuses on the insecure default private key you must rotate.
- Vagrant as a server provisioning tool driven by the Vagrant file.
- The insecure private key: what it is and why it matters.
- When and how to replace the insecure key, step by step.
Vagrant is a server provisioning tool.
vagrant up command automatically provisions the new VM based on Vagrant file.
- You can also run
vagrant provisionafter the VM has been created to explicitly run the provisioner again.
insecure private key
A default private SSH key that ships with Vagrant. It is used to allow Vagrant to access and manage virtual machines during provisioning without requiring custom SSH keys or manual intervention.
Key Details
- Purpose:
It simplifies initial setup by allowing Vagrant to connect to the VM using the predefinedvagrantuser with this known key. - Location:
The default insecure private key is typically located at:
~/.vagrant.d/insecure_private_key- Pairing:
The VMs created by Vagrant are pre-configured with the corresponding public key. This allows Vagrant to SSH into the VM using the private key for operations like provisioning, file synchronization, or management. - Security:
- It is insecure by design because the private key is publicly available and shared across all Vagrant users.
- It’s intended only for development and testing environments, not for production.
When and How to Replace It
For better security, especially if you’re sharing access or working in a team, you can replace the insecure key with your own custom SSH key pair.
Steps to Replace the Insecure Key:
-
Generate a New Key Pair:
ssh-keygen -t rsa -b 2048 -f ~/.ssh/my_vagrant_keyThis will create two files:
~/.ssh/my_vagrant_key(private key)~/.ssh/my_vagrant_key.pub(public key)
-
Update Vagrantfile:
Add aconfig.ssh.private_key_pathsetting to your Vagrantfile to point to the new private key:config.ssh.private_key_path = "~/.ssh/my_vagrant_key" -
Inject Public Key into the VM:
Use a provisioning script to copy your public key to the VM’s~/.ssh/authorized_keys:
config.vm.provision "shell", inline: <<-SHELL
mkdir -p ~/.ssh
echo 'your-public-key-contents' >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
SHELL👉 Heredoc
- Reload the VM:
vagrant reload --provision