可Ping通实例但Ansible Playbook执行失败求助
问题
已配置SSH公钥认证,可Ping通目标实例,Ansible临时命令ansible all -m ping -i /opt/hosts执行成功,但运行ansible-playbook -i /opt/hosts mars.yml时失败,报错权限拒绝,无法打开AnsiballZ_setup.py文件。
临时命令执行结果
suchetla@xhdlc210320:/scratch$ ansible all -m ping -i /opt/hosts [WARNING]: Invalid characters were found in group names but not replaced, use -vvvv to see details xhdlc201168 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python3" }, "changed": false, "ping": "pong" } xhdlc201164 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python3" }, "changed": false, "ping": "pong" } xhdlc201166 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python3" }, "changed": false, "ping": "pong" }
Playbook执行失败日志
suchetla@xhdlc210320:/scratch$ ansible-playbook -i /opt/hosts mars.yml [WARNING]: Invalid characters were found in group names but not replaced, use -vvvv to see details Sudo password: PLAY [xhd-hosts] *************************************************************************************************************************** TASK [Gathering Facts] ********************************************************************************************************************* fatal: [xhdlc210319]: FAILED! => {"ansible_facts": {}, "changed": false, "failed_modules": {"ansible.legacy.setup": {"ansible_facts": {"discovered_interpreter_python": "/usr/bin/python3"}, "failed": true, "module_stderr": "Shared connection to xhdlc210319 closed.\r\n", "module_stdout": "\r\n/usr/bin/python3: can't open file '/home/suchetla/.ansible/tmp/ansible-tmp-1711451084.9141061-329683-269580434256761/AnsiballZ_setup.py': [Errno 13] Permission denied\r\n", "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 2}}, "msg": "The following modules failed to execute: ansible.legacy.setup\n"}
Playbook内容
--- - hosts: xhd-hosts become: true become_method: sudo become_exe: "/tools/xgs/bin/sudo" #become_exe: "sudo" vars_prompt: - name: "ansible_sudo_pass" prompt: "Sudo password" private: yes tasks: - name: Install Prometheus Node Exporter apt: name: device-tree-compiler state: present
Inventory文件内容
hostname1 hostname2 hostname3
解决方案
问题原因
Playbook中启用了become: true,通过sudo切换到root用户执行模块时,Ansible默认将临时模块文件放到普通用户suchetla的家目录下(/home/suchetla/.ansible/tmp/),而root用户没有权限访问该普通用户目录下的文件,导致权限拒绝错误。
解决方法
方法1:修改Ansible临时文件目录到全局可访问路径
在目标主机的inventory文件中添加全局变量:
[all:vars] remote_tmp=/tmp/.ansible/tmp
或者修改控制节点的ansible.cfg文件:
[defaults] remote_tmp = /tmp/.ansible/tmp
方法2:在Playbook中直接指定临时目录
在Playbook的vars段添加临时目录配置:
--- - hosts: xhd-hosts become: true become_method: sudo become_exe: "/tools/xgs/bin/sudo" vars: remote_tmp: /tmp/.ansible/tmp vars_prompt: - name: "ansible_sudo_pass" prompt: "Sudo password" private: yes tasks: - name: Install Prometheus Node Exporter apt: name: device-tree-compiler state: present
方法3:验证自定义sudo工具权限(可选)
在目标主机执行以下命令,确认/tools/xgs/bin/sudo允许当前用户切换到root:
suchetla@xhdlc210319:~$ /tools/xgs/bin/sudo -l
内容的提问来源于stack exchange,提问作者Sudhamsh Buddy
相关产品推荐
相关产品推荐

