Ansible-Galaxy安装集合时JWT令牌过期问题求助
问题描述
批量安装Ansible集合时,因总耗时过长导致JWT令牌过期,触发以下错误:
ERROR! Error when getting collection version metadata for redhat.satellite_operations:3.0.0 from automation_hub (https://console.redhat.com/api/automation-hub/) (HTTP Code: 401, Message: Invalid JWT token - 'exp' claim expired at Fri, 15 Nov 2024 21:50:24 GMT Code: Unknown)
执行的安装命令为:
ANSIBLE_GALAXY_DISABLE_GPG_VERIFY=1 ansible-galaxy collection install --pre --verbose -r requirements.yml --collections-path "/usr/share/ansible/collections"
批量安装(多集合)耗时约17分钟失败,仅安装4个左右集合时耗时12分钟可成功,添加--timeout 1000参数无效果。
解决方案
1. 拆分安装任务
将requirements.yml拆分为多个小配置文件,分批次执行安装命令。每次运行ansible-galaxy collection install都会重新获取新的JWT令牌,确保单批安装耗时在令牌有效期内。
示例操作:
- 拆分
requirements.yml为req-core.yml、req-satellite.yml等文件 - 依次执行安装命令:
ANSIBLE_GALAXY_DISABLE_GPG_VERIFY=1 ansible-galaxy collection install --pre --verbose -r req-core.yml --collections-path "/usr/share/ansible/collections" ANSIBLE_GALAXY_DISABLE_GPG_VERIFY=1 ansible-galaxy collection install --pre --verbose -r req-satellite.yml --collections-path "/usr/share/ansible/collections"
2. 启用并行安装(Ansible 2.14+)
Ansible Galaxy 2.14及以上版本支持--parallel参数,可并行下载和安装集合,大幅缩短总耗时。根据服务器资源调整并行数(如8或10):
ANSIBLE_GALAXY_DISABLE_GPG_VERIFY=1 ansible-galaxy collection install --pre --verbose --parallel 8 -r requirements.yml --collections-path "/usr/share/ansible/collections"
3. 使用长效令牌或调整有效期
- 若使用自有Automation Hub:由管理员在Hub配置中延长JWT令牌的过期时间。
- 若使用Red Hat官方Automation Hub:生成服务账号令牌(而非临时用户令牌),服务账号令牌通常具有更长的有效期,可避免短时间内过期。
4. 本地预下载集合
提前将所有需要的集合下载到本地,后续从本地文件安装,无需连接Automation Hub,彻底规避令牌过期问题:
- 下载集合到本地目录:
ansible-galaxy collection download -r requirements.yml --dest ./collections-download
- 从本地安装:
ANSIBLE_GALAXY_DISABLE_GPG_VERIFY=1 ansible-galaxy collection install --pre --verbose -r requirements.yml --collections-path "/usr/share/ansible/collections" --force-with-deps ./collections-download/*
5. 启用本地缓存
配置Ansible Galaxy缓存,避免重复下载已安装过的集合,减少后续安装耗时:
- 在
ansible.cfg中添加缓存配置:
[galaxy] galaxy_cache_path = /path/to/cache/directory
- 或通过环境变量设置:
export ANSIBLE_GALAXY_CACHE_DIR=/path/to/cache/directory
内容的提问来源于stack exchange,提问作者jeremywat

