ansible 批量按用户名创建kerberos主体,并分发到远程主机

可以批量生产票据并分发目标主机

TypeScript 复制代码
- name: Configure Kerberos for Hadoop Users
  hosts: hadoop_servers
  become: no
  gather_facts: no
  vars:
    kerberos_server: hadoop01.xuexi.com
    keytab_dir: /home/hadoop/hxy
    keytab_local_dir: ./keytabs
    principals:
      - hxy
      - stars

  tasks:

    - name: Ensure key directory exists
      ansible.builtin.file:
        path: "{
  
  { keytab_dir }}"
        state: directory
        mode: '0755'

    - name: Create Kerberos principals and generate keytab files
      block:
        - name: Create a Kerberos principal
          ansible.builtin.command: >
            kadmin.local -q "addprinc -randkey {
  
  { item }}/{
  
  { inventory_hostname }}@XUEXI.COM"
          register: addprinc_results
          delegate_to: "{
  
  { kerberos_server }}"
          ignore_errors: yes
          loop: "{
  
  { principals }}"

        - name: Set facts for successfully created principals
          set_fact:
            created_principals: "{
  
  { created_principals | default([]) + [item.item] }}"
          when: item.rc == 0
          loop: "{
  
  { addprinc_results.results }}"

        - name: Report failed principal creation attempts
          ansible.builtin.debug:
            msg: "Failed to create principal for {
  
  { item.item }}/{
  
  { inventory_hostname }}@XUEXI.ICOM: {
  
  { item.stderr }}"
          when: "'Principal already exists' not in item.stderr and item.rc != 0"
          loop: "{
  
  { addprinc_results.results }}"

        - name: Generate keytab file for each principal
          ansible.builtin.command: >
            kadmin.local -q "xst -k {
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab -norandkey {
  
  { item }}/{
  
  { inventory_hostname }}@XUEXI.COM"
          register: xst_results
          delegate_to: "{
  
  { kerberos_server }}"
          loop: "{
  
  { created_principals }}"

        - name: Fetch the keytab files to the control machine
          ansible.builtin.fetch:
            src: "{
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
            dest: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
            flat: yes
          delegate_to: "{
  
  { kerberos_server }}"
          when: item is defined and (lookup('file', keytab_dir + '/' + item + '-' + inventory_hostname + '.keytab') is not none)
          loop: "{
  
  { created_principals }}"

    - name: Distribute keytab files to each target host
      ansible.builtin.copy:
        src: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        dest: "/data1/tmp/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
      when: item is defined and (lookup('file', keytab_local_dir + '/' + item + '-' + inventory_hostname + '.keytab') is not none)
      loop: "{
  
  { created_principals }}"
      delegate_to: "{
  
  { inventory_hostname }}"

    - name: Clean up keytab files on Kerberos server
      ansible.builtin.file:
        path: "{
  
  { keytab_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        state: absent
      when: item is defined
      delegate_to: "{
  
  { kerberos_server }}"
      loop: "{
  
  { created_principals }}"

    - name: Clean up local keytab files on control machine
      ansible.builtin.file:
        path: "{
  
  { keytab_local_dir }}/{
  
  { item }}-{
  
  { inventory_hostname }}.keytab"
        state: absent
      when: item is defined
      loop: "{
  
  { created_principals }}"
      run_once: yes
相关推荐
智能工业品检测-奇妙智能17 分钟前
开源知识库平台有哪些
服务器·人工智能·spring boot·开源·openclaw·奇妙智能
2501_9431240521 分钟前
认证护航品质,青岛福尔蒂新材料构建国际级材料安全体系
大数据·人工智能
深念Y35 分钟前
旧物新生:用魅蓝Note5 root后搭建家用Linux服务器(部署宝塔/AList/QB)
linux·运维·服务器·手机·diy·魔改·魅族
Q168496451536 分钟前
k8s-通过ansible-playbook脚本将其他节点加入集群失败?
容器·kubernetes·ansible
wanhengidc43 分钟前
云手机会导致本地数据被读取吗
运维·服务器·数据库·游戏·智能手机
野犬寒鸦1 小时前
从零起步学习计算机操作系统:内存管理篇
服务器·后端·学习·缓存·面试
一只努力的微服务1 小时前
【Calcite 系列】深入理解 Calcite 的 SetOpToFilterRule
大数据·数据库·calcite·优化规则
开开心心就好1 小时前
轻量级PDF阅读器,仅几M大小打开秒开
linux·运维·服务器·安全·pdf·1024程序员节·oneflow
七夜zippoe1 小时前
Elasticsearch全文搜索与数据分析实战指南
大数据·python·elasticsearch·数据分析·全文搜索
ljh5746491191 小时前
linux sed 命令
linux·运维·服务器