OpenSSH treats the last @ as user/host separator, so the SSH username must be hop@target@ip without duplicating hop_host. Legacy templates with {hop_host} are stripped automatically; connect logs now show bastion_ssh_cli for comparison with manual ssh.
Co-authored-by: Cursor <cursoragent@cursor.com>
ZTE-TSM and similar bastions reject standard SSH password auth and require Vault password via keyboard-interactive; connect over an authenticated Paramiko session instead of re-handshaking with Netmiko.
Co-authored-by: Cursor <cursoragent@cursor.com>
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.
Co-authored-by: Cursor <cursoragent@cursor.com>