22
17

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

Ansibleでパスワードをスマートに

Posted at

はじめに

ansibleでsshログイン時のパスワードを入力したり、sudo実行時のパスワード入力など
ansibleでパスワード入力をどう解決したらいいのか悩んでいる人向けの記事です。

解決方法

1. playbookコマンド実行時のパラメータで指定(対話形式で入力)

$ ansible-playbook sample.yml -i hosts --ask-pass --ask-sudo-pass

2. ansible.cfgで設定(上記パラメータ指定するのが面倒な方へ)
ansible.cfg
ask_pass = True
ask_sudo_pass = True
3. Ansible Vaultでパスワードを暗号化してパスワード入力を省略
passwd.ymlを作成
---
ansible_sudo_pass: hoge
ansible_ssh_pass: hogehoge
passwd.ymlを暗号化
$ ansible-vault encrypt passwd.yml
Vault password:
Confirm Vault password:
Encryption successful
ansible.cfgにvaultのパスワードを要求するよう設定
ask_vault_pass = True

playbookコマンド実行時に外部変数として読み込む

$ ansible-playbook sample.yml -i hosts --extra-vars="@password.yml"
Vault password:

参考サイト

Ansible で sudo を実行する
(公式)ansible.cfg

22
17
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
22
17

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?