ansible 批量按用户名创建kerberos主体,并分发到远程主机

可以批量生产票据并分发目标主机

TypeScript 复制代码
- name: Configure Kerberos for Hadoop Users
  hosts: hadoop_servers
  become: no
  gather_facts: no
  vars:
    kerberos_server: hadoop01.xuexi.com
    keytab_dir: /home/hadoop/hxy
    keytab_local_dir: ./keytabs
    principals:
      - hxy
      - stars

  tasks:

    - name: Ensure key directory exists
      ansible.builtin.file:
        path: "{
  
  { keytab_dir }}"
        state: directory
        mode: '0755'

    - name: Create Kerberos principals and generate keytab files
      block:
        - name: Create a Kerberos principal
          ansible.builtin.command: >
            kadmin.local -q "addprinc -randkey {
  
  { item }}/{
  
  { inventory_hostname }}@XUEXI.COM"
          register: addprinc_results
          delegate_to: "{
  
  { kerberos_server }}"
          ignore_errors: yes
          loop: "{
  
  { principals }}"

        - name: Set facts for successfully created principals
          set_fact:
            created_principals: "{
  
  { created_principals | default([]) + [item.item] }}"
          when: item.rc == 0
          loop: "{
  
  { addprinc_results.results }}"

        - name: Report failed principal creation attempts
          ansible.builtin.debug:
            msg: "Failed to create principal for {
  
  { item.item }}/{
  
  { inventory_hostname }}@XUEXI.ICOM: {
  
  { item.stderr }}"
          when: "'Principal already exists' not in item.stderr and item.rc != 0"
          loop: "{
  
  { addprinc_results.results }}"

        - name: Generate keytab file for each principal
          ansible.builtin.command: >
            kadmin.local -q "xst -k {
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab -norandkey {
  
  { item }}/{
  
  { inventory_hostname }}@XUEXI.COM"
          register: xst_results
          delegate_to: "{
  
  { kerberos_server }}"
          loop: "{
  
  { created_principals }}"

        - name: Fetch the keytab files to the control machine
          ansible.builtin.fetch:
            src: "{
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
            dest: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
            flat: yes
          delegate_to: "{
  
  { kerberos_server }}"
          when: item is defined and (lookup('file', keytab_dir + '/' + item + '-' + inventory_hostname + '.keytab') is not none)
          loop: "{
  
  { created_principals }}"

    - name: Distribute keytab files to each target host
      ansible.builtin.copy:
        src: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        dest: "/data1/tmp/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
      when: item is defined and (lookup('file', keytab_local_dir + '/' + item + '-' + inventory_hostname + '.keytab') is not none)
      loop: "{
  
  { created_principals }}"
      delegate_to: "{
  
  { inventory_hostname }}"

    - name: Clean up keytab files on Kerberos server
      ansible.builtin.file:
        path: "{
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        state: absent
      when: item is defined
      delegate_to: "{
  
  { kerberos_server }}"
      loop: "{
  
  { created_principals }}"

    - name: Clean up local keytab files on control machine
      ansible.builtin.file:
        path: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        state: absent
      when: item is defined
      loop: "{
  
  { created_principals }}"
      run_once: yes
相关推荐
段帅龙呀36 分钟前
Redis构建缓存服务器
服务器·redis·缓存
乌鸦不像写字台1 小时前
【docker部署】在服务器上使用docker
服务器·docker·容器
莫彩2 小时前
Mapreduce 工业界批式计算经验汇总(下)
大数据·mapreduce
Antonio9153 小时前
【音视频】HLS简介与服务器搭建
运维·服务器·音视频
kfepiza4 小时前
Debian的`/etc/network/interfaces`的`allow-hotplug`和`auto`对比讲解 笔记250704
linux·服务器·网络·笔记·debian
无妄-20244 小时前
软件架构升级中的“隐形地雷”:版本选型与依赖链风险
java·服务器·网络·经验分享
R.X. NLOS4 小时前
VS Code远程开发新方案:使用SFTP扩展解决Remote-SSH连接不稳定问题
运维·服务器·ssh·debug·vs code
爱吃面的猫6 小时前
大数据Hadoop之——Flink1.17.0安装与使用(非常详细)
大数据·hadoop·分布式
Fireworkitte6 小时前
安装 Elasticsearch IK 分词器
大数据·elasticsearch
ywyy67987 小时前
短剧系统开发定制全流程解析:从需求分析到上线的专业指南
大数据·需求分析·短剧·推客系统·推客小程序·短剧系统开发·海外短剧系统开发