如何在OpenStack Ansible模块中正确使用Auth Token?
问题:使用OpenStack Auth Token调用Ansible模块失败
我在运行包含openstack.cloud集合任务的Ansible Playbook时,尝试用前一任务返回的Auth Token调用security_group_info模块,任务代码如下:
- name: "Use Token for Retrieving SGs" openstack.cloud.security_group_info: auth: "{{api_token_response}}" auth_type: openstack.cloud.auth name: default register: security_group_results
执行任务时返回错误,怀疑是auth_type设置错误,错误信息如下:
An exception occurred during task execution. To see the full traceback, use -vvv. The error was: keystoneauth1.exceptions.auth_plugins.NoMatchingPlugin: The plugin openstack.cloud.auth could not be found fatal: [localhost]: FAILED! => {"changed": false, "module_stderr": "Traceback (most recent call last): File \"/usr/local/lib/python3.10/dist-packages/keystoneauth1/loading/base.py\", line 78, in get_plugin_loader mgr = stevedore.DriverManager(namespace=PLUGIN_NAMESPACE, File \"/usr/local/lib/python3.10/dist-packages/stevedore/driver.py\", line 54, in __init__ super(DriverManager, self).__init__( File \"/usr/local/lib/python3.10/dist-packages/stevedore/named.py\", line 89, in __init__ self._init_plugins(extensions) File \"/usr/local/lib/python3.10/dist-packages/stevedore/driver.py\", line 113, in _init_plugins raise NoMatches('No %r driver found, looking for %r' % stevedore.exception.NoMatches: No 'keystoneauth1.plugin' driver found, looking for 'openstack.cloud.auth' During handling of the above exception, another exception occurred: .... .... .... keystoneauth1.exceptions.auth_plugins.NoMatchingPlugin: The plugin openstack.cloud.auth could not be found
前一任务返回的api_token_response变量结构如下:
{ "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python3" }, "auth_token": "asdf1234workssuccessfully", "changed": false, "failed": false }
解决方案
你的问题确实是auth_type设置错误,同时auth参数的传递方式也有问题,修正方案如下:
- auth_type需改为
token:openstack.cloud.auth不是合法的Keystone认证插件类型,使用已有令牌认证时,正确的插件类型是token。 - 正确构造auth参数:不能直接传入整个
api_token_response变量,因为它包含Ansible任务的元数据(如changed、ansible_facts),需要提取其中的auth_token,并补充Keystone的auth_url(令牌认证必须指定Keystone地址)。
修正后的任务代码:
- name: "Use Token for Retrieving SGs" openstack.cloud.security_group_info: auth: auth_url: "http://你的Keystone地址:5000/v3" # 替换为实际的OpenStack Keystone endpoint token: "{{ api_token_response.auth_token }}" auth_type: token name: default register: security_group_results
关键说明:
auth_type: token是Keystone官方支持的令牌认证插件,会被keystoneauth正确识别auth字典中必须包含auth_url和token两个核心字段,缺一不可- 确保
auth_url与你的OpenStack环境中Keystone的实际地址一致,通常格式为http://controller:5000/v3
内容的提问来源于stack exchange,提问作者HC LW
相关产品推荐
相关产品推荐

