如何在Debian 10上安装Ansible
在如今的 IT 领域,自动化一个是热门话题,每个组织都开始采用自动化工具,像 Puppet、Ansible、Chef、CFEngine、Foreman 和 Katello。在这些工具中,Ansible 是几乎所有 IT 组织中管理 UNIX 和 Linux 系统的首选。在本文中,我们将演示如何在 Debian 10 Sever 上安装和使用 Ansible。
我的实验室环境:
- Debian 10 – Ansible 服务器/ 控制节点 – 192.168.1.14
- CentOS 7 – Ansible 主机 (Web 服务器)– 192.168.1.15
- CentOS 7 – Ansible 主机(DB 服务器)– 192.169.1.17
我们还将演示如何使用 Ansible 服务器管理 Linux 服务器
在 Debian 10 Server 上安装 Ansible
我假设你的 Debian 10 中有一个拥有 root 或 sudo 权限的用户。在我这里,我有一个名为 pkumar
的本地用户,它拥有 sudo 权限。
Ansible 2.7 包存在于 Debian 10 的默认仓库中,在命令行中运行以下命令安装 Ansible,
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> apt update</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> apt install ansible </span><span class="pun">-</span><span class="pln">y</span>
运行以下命令验证 Ansible 版本,
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">--</span><span class="pln">version</span>
ansible-version
要安装最新版本的 Ansible 2.8,首先我们必须设置 Ansible 仓库。
一个接一个地执行以下命令,
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">echo</span><span class="pln"> </span><span class="str">"deb http://ppa.launchpad.net/ansible/ansible/ubuntu bionic main"</span><span class="pln"> </span><span class="pun">|</span><span class="pln"> </span><span class="kwd">sudo</span><span class="pln"> </span><span class="kwd">tee</span><span class="pln"> </span><span class="pun">-</span><span class="pln">a </span><span class="pun">/</span><span class="pln">etc</span><span class="pun">/</span><span class="pln">apt</span><span class="pun">/</span><span class="pln">sources</span><span class="pun">.</span><span class="kwd">list</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> apt</span><span class="pun">-</span><span class="pln">key adv </span><span class="pun">--</span><span class="pln">keyserver keyserver</span><span class="pun">.</span><span class="pln">ubuntu</span><span class="pun">.</span><span class="pln">com </span><span class="pun">--</span><span class="pln">recv</span><span class="pun">-</span><span class="pln">keys </span><span class="lit">93C4A3FD7BB9C367</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> apt update</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> apt install ansible </span><span class="pun">-</span><span class="pln">y</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">--</span><span class="pln">version</span>
latest-ansible-version
使用 Ansible 管理 Linux 服务器
请参考以下步骤,使用 Ansible 控制器节点管理 Linux 类的服务器,
步骤 1:在 Ansible 服务器及其主机之间交换 SSH 密钥
在 Ansible 服务器生成 ssh 密钥并在 Ansible 主机之间共享密钥。
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> </span><span class="pun">-</span><span class="pln">i</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~#</span><span class="pln"> </span><span class="kwd">ssh</span><span class="pun">-</span><span class="pln">keygen</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~#</span><span class="pln"> </span><span class="kwd">ssh</span><span class="pun">-</span><span class="pln">copy</span><span class="pun">-</span><span class="kwd">id</span><span class="pln"> root@linuxtechi</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~#</span><span class="pln"> </span><span class="kwd">ssh</span><span class="pun">-</span><span class="pln">copy</span><span class="pun">-</span><span class="kwd">id</span><span class="pln"> root@linuxtechi</span>
步骤 2:创建 Ansible 主机清单
安装 Ansible 后会自动创建 /etc/ansible/hosts
,在此文件中我们可以编辑 Ansible 主机或其客户端。我们还可以在家目录中创建自己的 Ansible 主机清单,
运行以下命令在我们的家目录中创建 Ansible 主机清单。
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">vi</span><span class="pln"> $HOME</span><span class="pun">/</span><span class="pln">hosts</span>
<span class="pun">[</span><span class="typ">Web</span><span class="pun">]</span>
<span class="lit">192.168</span><span class="pun">.</span><span class="lit">1.15</span>
<span class="pun">[</span><span class="pln">DB</span><span class="pun">]</span>
<span class="lit">192.168</span><span class="pun">.</span><span class="lit">1.17</span>
保存并退出文件。
注意:在上面的主机文件中,我们也可以使用主机名或 FQDN,但为此我们必须确保 Ansible 主机可以通过主机名或者 FQDN 访问。
步骤 3:测试和使用默认的 Ansible 模块
Ansible 附带了许多可在 ansible
命令中使用的默认模块,示例如下所示。
语法:
<span class="com">#</span><span class="pln"> ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun"><</span><span class="pln">host_file</span><span class="pun">></span><span class="pln"> </span><span class="pun">-</span><span class="pln">m </span><span class="pun"><</span><span class="kwd">module</span><span class="pun">></span><span class="pln"> </span><span class="pun"><</span><span class="pln">host</span><span class="pun">></span>
这里:
-i ~/hosts
:包含 Ansible 主机列表-m
:在之后指定 Ansible 模块,如 ping 和 shell<host>
:我们要运行 Ansible 模块的 Ansible 主机
使用 Ansible ping 模块验证 ping 连接,
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun">~/</span><span class="pln">hosts </span><span class="pun">-</span><span class="pln">m </span><span class="kwd">ping</span><span class="pln"> all</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun">~/</span><span class="pln">hosts </span><span class="pun">-</span><span class="pln">m </span><span class="kwd">ping</span><span class="pln"> </span><span class="typ">Web</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun">~/</span><span class="pln">hosts </span><span class="pun">-</span><span class="pln">m </span><span class="kwd">ping</span><span class="pln"> DB</span>
命令输出如下所示:
Ansible-ping-module-examples
使用 shell 模块在 Ansible 主机上运行 shell 命令
语法:
<span class="pln">ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun"><</span><span class="pln">hosts_file</span><span class="pun">></span><span class="pln"> </span><span class="pun">-</span><span class="pln">m shell </span><span class="pun">-</span><span class="pln">a </span><span class="pun"><</span><span class="pln">shell_commands</span><span class="pun">></span><span class="pln"> </span><span class="pun"><</span><span class="pln">host</span><span class="pun">></span>
例子:
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun">~/</span><span class="pln">hosts </span><span class="pun">-</span><span class="pln">m shell </span><span class="pun">-</span><span class="pln">a </span><span class="str">"uptime"</span><span class="pln"> all</span>
<span class="lit">192.168</span><span class="pun">.</span><span class="lit">1.17</span><span class="pln"> </span><span class="pun">|</span><span class="pln"> CHANGED </span><span class="pun">|</span><span class="pln"> rc</span><span class="pun">=</span><span class="lit">0</span><span class="pln"> </span><span class="pun">>></span>
<span class="pln"> </span><span class="lit">01</span><span class="pun">:</span><span class="lit">48</span><span class="pun">:</span><span class="lit">34</span><span class="pln"> up </span><span class="lit">1</span><span class="pun">:</span><span class="lit">07</span><span class="pun">,</span><span class="pln"> </span><span class="lit">3</span><span class="pln"> </span><span class="kwd">users</span><span class="pun">,</span><span class="pln"> load average</span><span class="pun">:</span><span class="pln"> </span><span class="lit">0.00</span><span class="pun">,</span><span class="pln"> </span><span class="lit">0.01</span><span class="pun">,</span><span class="pln"> </span><span class="lit">0.05</span>
<span class="lit">192.168</span><span class="pun">.</span><span class="lit">1.15</span><span class="pln"> </span><span class="pun">|</span><span class="pln"> CHANGED </span><span class="pun">|</span><span class="pln"> rc</span><span class="pun">=</span><span class="lit">0</span><span class="pln"> </span><span class="pun">>></span>
<span class="pln"> </span><span class="lit">01</span><span class="pun">:</span><span class="lit">48</span><span class="pun">:</span><span class="lit">39</span><span class="pln"> up </span><span class="lit">1</span><span class="pun">:</span><span class="lit">07</span><span class="pun">,</span><span class="pln"> </span><span class="lit">3</span><span class="pln"> </span><span class="kwd">users</span><span class="pun">,</span><span class="pln"> load average</span><span class="pun">:</span><span class="pln"> </span><span class="lit">0.00</span><span class="pun">,</span><span class="pln"> </span><span class="lit">0.01</span><span class="pun">,</span><span class="pln"> </span><span class="lit">0.04</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$</span>
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible </span><span class="pun">-</span><span class="pln">i </span><span class="pun">~</span><span class="str">/hosts -m shell -a "uptime ; df -Th /</span><span class="pln"> </span><span class="pun">;</span><span class="pln"> </span><span class="kwd">uname</span><span class="pln"> </span><span class="pun">-</span><span class="pln">r</span><span class="str">" Web</span>
<span class="str">192.168.1.15 | CHANGED | rc=0 >></span>
<span class="str"> 01:52:03 up 1:11, 3 users, load average: 0.12, 0.07, 0.06</span>
<span class="str">Filesystem Type Size Used Avail Use% Mounted on</span>
<span class="str">/dev/mapper/centos-root xfs 13G 1017M 12G 8% /</span>
<span class="str">3.10.0-327.el7.x86_64</span>
<span class="str">root@linuxtechi:~$</span>
上面的命令输出表明我们已成功设置 Ansible 控制器节点。
让我们创建一个安装 nginx 的示例剧本,下面的剧本将在所有服务器上安装 nginx,这些服务器是 Web 主机组的一部分,但在这里,我的主机组下只有一台 centos 7 机器。
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">vi</span><span class="pln"> nginx</span><span class="pun">.</span><span class="pln">yaml</span>
<span class="pun">---</span>
<span class="pun">-</span><span class="pln"> hosts</span><span class="pun">:</span><span class="pln"> </span><span class="typ">Web</span>
<span class="pln"> tasks</span><span class="pun">:</span>
<span class="pln"> </span><span class="pun">-</span><span class="pln"> name</span><span class="pun">:</span><span class="pln"> </span><span class="typ">Install</span><span class="pln"> latest version of nginx on </span><span class="typ">CentOS</span><span class="pln"> </span><span class="lit">7</span><span class="pln"> </span><span class="typ">Server</span>
<span class="pln"> </span><span class="kwd">yum</span><span class="pun">:</span><span class="pln"> name</span><span class="pun">=</span><span class="pln">nginx state</span><span class="pun">=</span><span class="pln">latest</span>
<span class="pln"> </span><span class="pun">-</span><span class="pln"> name</span><span class="pun">:</span><span class="pln"> start nginx</span>
<span class="pln"> service</span><span class="pun">:</span>
<span class="pln"> name</span><span class="pun">:</span><span class="pln"> nginx</span>
<span class="pln"> state</span><span class="pun">:</span><span class="pln"> started</span>
现在使用以下命令执行剧本。
<span class="pln">root@linuxtechi</span><span class="pun">:~</span><span class="pln">$ </span><span class="kwd">sudo</span><span class="pln"> ansible</span><span class="pun">-</span><span class="pln">playbook </span><span class="pun">-</span><span class="pln">i </span><span class="pun">~/</span><span class="pln">hosts nginx</span><span class="pun">.</span><span class="pln">yaml</span>
上面命令的输出类似下面这样,