ansible 批量按用户名创建kerberos主体,并分发到远程主机

可以批量生产票据并分发目标主机

TypeScript 复制代码
- name: Configure Kerberos for Hadoop Users
  hosts: hadoop_servers
  become: no
  gather_facts: no
  vars:
    kerberos_server: hadoop01.xuexi.com
    keytab_dir: /home/hadoop/hxy
    keytab_local_dir: ./keytabs
    principals:
      - hxy
      - stars

  tasks:

    - name: Ensure key directory exists
      ansible.builtin.file:
        path: "{
  
  { keytab_dir }}"
        state: directory
        mode: '0755'

    - name: Create Kerberos principals and generate keytab files
      block:
        - name: Create a Kerberos principal
          ansible.builtin.command: >
            kadmin.local -q "addprinc -randkey {
  
  { item }}/{
  
  { inventory_hostname }}@XUEXI.COM"
          register: addprinc_results
          delegate_to: "{
  
  { kerberos_server }}"
          ignore_errors: yes
          loop: "{
  
  { principals }}"

        - name: Set facts for successfully created principals
          set_fact:
            created_principals: "{
  
  { created_principals | default([]) + [item.item] }}"
          when: item.rc == 0
          loop: "{
  
  { addprinc_results.results }}"

        - name: Report failed principal creation attempts
          ansible.builtin.debug:
            msg: "Failed to create principal for {
  
  { item.item }}/{
  
  { inventory_hostname }}@XUEXI.ICOM: {
  
  { item.stderr }}"
          when: "'Principal already exists' not in item.stderr and item.rc != 0"
          loop: "{
  
  { addprinc_results.results }}"

        - name: Generate keytab file for each principal
          ansible.builtin.command: >
            kadmin.local -q "xst -k {
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab -norandkey {
  
  { item }}/{
  
  { inventory_hostname }}@XUEXI.COM"
          register: xst_results
          delegate_to: "{
  
  { kerberos_server }}"
          loop: "{
  
  { created_principals }}"

        - name: Fetch the keytab files to the control machine
          ansible.builtin.fetch:
            src: "{
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
            dest: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
            flat: yes
          delegate_to: "{
  
  { kerberos_server }}"
          when: item is defined and (lookup('file', keytab_dir + '/' + item + '-' + inventory_hostname + '.keytab') is not none)
          loop: "{
  
  { created_principals }}"

    - name: Distribute keytab files to each target host
      ansible.builtin.copy:
        src: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        dest: "/data1/tmp/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
      when: item is defined and (lookup('file', keytab_local_dir + '/' + item + '-' + inventory_hostname + '.keytab') is not none)
      loop: "{
  
  { created_principals }}"
      delegate_to: "{
  
  { inventory_hostname }}"

    - name: Clean up keytab files on Kerberos server
      ansible.builtin.file:
        path: "{
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        state: absent
      when: item is defined
      delegate_to: "{
  
  { kerberos_server }}"
      loop: "{
  
  { created_principals }}"

    - name: Clean up local keytab files on control machine
      ansible.builtin.file:
        path: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        state: absent
      when: item is defined
      loop: "{
  
  { created_principals }}"
      run_once: yes
相关推荐
元拓数智6 小时前
IntaLink:破解数仓建设痛点,重塑高效建设新范式
大数据·数据仓库·人工智能·数据关系·intalink
区块链小八歌6 小时前
从电商收入到链上资产:Liquid Royalty在 Berachain 重塑 RWA 想象力
大数据·人工智能·区块链
沃达德软件6 小时前
大数据反诈平台功能解析
大数据·人工智能
音视频牛哥6 小时前
AI时代底层技术链:GPU、云原生与大模型的协同进化全解析
大数据·云原生·kubernetes·音视频·transformer·gpu算力·云原生cloud native
hhwyqwqhhwy7 小时前
Linux file->private
linux·运维·服务器
WongKyunban7 小时前
在Linux下制作软件安装包
linux·运维·服务器
howard20057 小时前
实训云上搭建大数据集群
大数据·大数据集群·实训云
大模型服务器厂商7 小时前
人形机器人的技术概况与算力支撑背景
大数据·人工智能
hweiyu007 小时前
Linux 命令:parted
linux·运维·服务器
烽火聊员7 小时前
CertificateCreator生成服务器证书server.pfx
运维·服务器