【问题标题】:how use aws profile when using ansible ec2.py module使用 ansible ec2.py 模块时如何使用 aws 配置文件
【发布时间】:2017-01-27 14:38:25
【问题描述】:

我写了一个快速的 ansible playbook 来启动一个简单的 ec2 实例,但我认为我对如何进行身份验证有疑问。

我不想做的是将我的 aws 访问/密钥设置为 env 变量,因为它们每小时都会过期,我需要通过脚本重新生成 ~/.aws/credentials 文件。

现在,我的 ansible playbook 如下所示:

--- # Launch ec2
- name: Create ec2 instance
  hosts: local
  connection: local
  gather_facts: false
  vars:
    profile: profile_xxxx
    key_pair: usrxxx
    region: us-east-1
    subnet: subnet-38xxxxx
    security_groups: ['sg-e54xxxx', 'sg-bfcxxxx', 'sg-a9dxxx']
    image: ami-031xxx
    instance_type: t2.small
    num_instances: 1
    tag_name: ansibletest
    hdd_volumes:
    - device_name: /dev/sdf
      volume_size: 50
      delete_on_termination: true
    - device_name: /dev/sdh
      volume_size: 50
      delete_on_termination: true
  tasks:
    - name: launch ec2
      ec2:
        count: 1
        key_name: "{{ key_pair }}"
        profile: "{{ profile }}"
        group_id: "{{ security_groups }}"
        instance_type: "{{ instance_type }}"
        image: "{{ image }}"
        region: "{{ region }}"
        vpc_subnet_id: "{{ subnet }}"
        assign_public_ip: false
        volumes: "{{ hdd_volumes }}"
        instance_tags:
          Name: "{{ tag_name }}"
          ASV: "{{ tag_asv }}"
          CMDBEnvironment: "{{ tag_cmdbEnv }}"
          EID: "{{ tag_eid }}"
          OwnerContact: "{{ tag_eid }}"
      register: ec2
    - name: print ec2 vars
      debug: var=ec

我的主机文件是这样的:

[local]
localhost ansible_python_interpreter=/usr/local/bin/python2.7

我这样运行我的剧本:

ansible-playbook -i hosts launchec2.yml -vvv

然后把它拿回来:

PLAYBOOK: launchec2.yml ********************************************************
1 plays in launchec2.yml

PLAY [Create ec2 instance] *****************************************************

TASK [launch ec2] **************************************************************
task path: /Users/usrxxx/Desktop/cloud-jumper/Ansible/launchec2.yml:27
Using module file /Library/Frameworks/Python.framework/Versions/2.7/lib/python2.7/site-packages/ansible/modules/core/cloud/amazon/ec2.py
<localhost> ESTABLISH LOCAL CONNECTION FOR USER: usrxxx
<localhost> EXEC /bin/sh -c '( umask 77 && mkdir -p "` echo ~/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730 `" && echo ansible-tmp-1485527483.82-106272618422730="` echo ~/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730 `" ) && sleep 0'
<localhost> PUT /var/folders/cx/_fdv7nkn6dz21798p_bn9dp9ln9sqc/T/tmpnk2rh5 TO /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/ec2.py
<localhost> PUT /var/folders/cx/_fdv7nkn6dz21798p_bn9dp9ln9sqc/T/tmpEpwenH TO /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/args
<localhost> EXEC /bin/sh -c 'chmod u+x /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/ /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/ec2.py /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/args && sleep 0'
<localhost> EXEC /bin/sh -c '/usr/bin/env python /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/ec2.py /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/args; rm -rf "/Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/" > /dev/null 2>&1 && sleep 0'
fatal: [localhost]: FAILED! => {
    "changed": false, 
    "failed": true, 
    "invocation": {
        "module_name": "ec2"
    }, 
    "module_stderr": "usage: ec2.py [-h] [--list] [--host HOST] [--refresh-cache]\n              [--profile BOTO_PROFILE]\nec2.py: error: unrecognized arguments: /Users/usrxxx/.ansible/tmp/ansible-tmp-1485527483.82-106272618422730/args\n", 
    "module_stdout": "", 
    "msg": "MODULE FAILURE"
}
    to retry, use: --limit @/Users/usrxxx/Desktop/cloud-jumper/Ansible/launchec2.retry

PLAY RECAP *********************************************************************
localhost                  : ok=0    changed=0    unreachable=0    failed=1 

我注意到在ec2.py 文件中是这样写的:

NOTE: This script assumes Ansible is being executed where the environment
variables needed for Boto have already been set:
    export AWS_ACCESS_KEY_ID='AK123'
    export AWS_SECRET_ACCESS_KEY='abc123'

This script also assumes there is an ec2.ini file alongside it.  To specify a
different path to ec2.ini, define the EC2_INI_PATH environment variable:

    export EC2_INI_PATH=/path/to/my_ec2.ini

If you're using eucalyptus you need to set the above variables and
you need to define:

    export EC2_URL=http://hostname_of_your_cc:port/services/Eucalyptus

If you're using boto profiles (requires boto>=2.24.0) you can choose a profile
using the --boto-profile command line argument (e.g. ec2.py --boto-profile prod) or using
the AWS_PROFILE variable:

    AWS_PROFILE=prod ansible-playbook -i ec2.py myplaybook.yml

所以我是这样运行的:

AWS_PROFILE=profile_xxxx ansible-playbook -i hosts launchec2.yml -vvv

但仍然得到相同的结果...

----编辑-----

我也是这样运行的:

export ANSIBLE_HOST_KEY_CHECKING=false
export AWS_ACCESS_KEY=<your aws access key here>
export AWS_SECRET_KEY=<your aws secret key here>

ansible-playbook -i hosts launchec2.yml

但仍然得到了这个……似乎仍然是凭据问题?

usrxxx$ ansible-playbook -i hosts launchec2.yml 

PLAY [Create ec2 instance] *****************************************************

TASK [launch ec2] **************************************************************
fatal: [localhost]: FAILED! => {"changed": false, "failed": true, "module_stderr": "usage: ec2.py [-h] [--list] [--host HOST] [--refresh-cache]\n              [--profile BOTO_PROFILE]\nec2.py: error: unrecognized arguments: /Users/usrxxx/.ansible/tmp/ansible-tmp-1485531356.01-33528208838066/args\n", "module_stdout": "", "msg": "MODULE FAILURE"}
    to retry, use: --limit @/Users/usrxxx/Desktop/cloud-jumper/Ansible/launchec2.retry

PLAY RECAP *********************************************************************
localhost                  : ok=0    changed=0    unreachable=0    failed=1   

---编辑2-----

完全删除了ansible,然后用自制软件安装但得到了同样的错误......所以我想去它寻找ec2.py(Using module file /usr/local/Cellar/ansible/2.2.1.0/libexec/lib/python2.7/site-packages/ansible/modules/core/cloud/amazon/ec2.py)的目录并用这个替换那个ec2.py.. .https://raw.githubusercontent.com/ansible/ansible/devel/contrib/inventory/ec2.py....but 现在得到这个错误:

Using /Users/usrxxx/ansible/ansible.cfg as config file

PLAYBOOK: launchec2.yml ********************************************************
1 plays in launchec2.yml

PLAY [Create ec2 instance] *****************************************************

TASK [aws : launch ec2] ********************************************************
task path: /Users/usrxxx/Desktop/cloud-jumper/Ansible/roles/aws/tasks/main.yml:1
Using module file /usr/local/Cellar/ansible/2.2.1.0/libexec/lib/python2.7/site-packages/ansible/modules/core/cloud/amazon/ec2.py
fatal: [localhost]: FAILED! => {
    "failed": true, 
    "msg": "module (ec2) is missing interpreter line"
}

【问题讨论】:

    标签: amazon-web-services amazon-ec2 ansible ansible-playbook


    【解决方案1】:

    您似乎已将ec2.py inventory script 放入您的/path/to/playbook/library/ 文件夹中。
    您不应该将动态清单脚本放在那里 - 这样 Ansible 会运行清单脚本而不是 ec2 module

    从项目的库文件夹(或 ansible.cfg 中定义的 Ansible 全局 library)中删除 ec2.py,然后重试。

    【讨论】:

    • 我的 playbook 路径中没有 ec2.py 或 ec2.ini 文件...不是在 /Library/Frameworks/Python.framework/Versions/2.7/lib/python2.7/site-packages/ansible/modules/core/cloud/amazon/ 中查找 ec2.py 模块吗?
    • 您可能已将其放置在库搜索路径中的其他位置。从干净的 VM 中尝试您的剧本。如果其他地方没有 ec2.py 可用,Ansible 将从默认路径中获取 ec2.py(此逻辑对于覆盖默认模块非常有用)。您的输出建议您运行清单脚本而不是 ec2 模块。
    • 我完全删除了 ansible 并通过自制软件再次安装,但仍然出现相同的错误...
    • 我将 ec2.py 替换为链接中的那个,但现在得到一个不同的错误...进行了编辑 2 以显示它...
    • 天啊...请逐字阅读我的原始答案——这就是你所需要的。用空的ansible.cfg 制作干净的项目目录,并逐行添加代码。抱歉,我退出了这个线程。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2019-09-29
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2016-01-23
    相关资源
    最近更新 更多