You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OpenStack Ansible模块中正确使用Auth Token?

问题:使用OpenStack Auth Token调用Ansible模块失败

我在运行包含openstack.cloud集合任务的Ansible Playbook时,尝试用前一任务返回的Auth Token调用security_group_info模块,任务代码如下:

- name: "Use Token for Retrieving SGs"
  openstack.cloud.security_group_info:
    auth: "{{api_token_response}}"
    auth_type: openstack.cloud.auth
    name: default
  register: security_group_results

执行任务时返回错误,怀疑是auth_type设置错误,错误信息如下:

An exception occurred during task execution. To see the full traceback, use -vvv. The error was: keystoneauth1.exceptions.auth_plugins.NoMatchingPlugin: The plugin openstack.cloud.auth could not be found
fatal: [localhost]: FAILED! => {"changed": false, "module_stderr": "Traceback (most recent call last):
  File \"/usr/local/lib/python3.10/dist-packages/keystoneauth1/loading/base.py\", line 78, in get_plugin_loader
    mgr = stevedore.DriverManager(namespace=PLUGIN_NAMESPACE,
  File \"/usr/local/lib/python3.10/dist-packages/stevedore/driver.py\", line 54, in __init__
    super(DriverManager, self).__init__(
  File \"/usr/local/lib/python3.10/dist-packages/stevedore/named.py\", line 89, in __init__
    self._init_plugins(extensions)
  File \"/usr/local/lib/python3.10/dist-packages/stevedore/driver.py\", line 113, in _init_plugins
    raise NoMatches('No %r driver found, looking for %r' %
stevedore.exception.NoMatches: No 'keystoneauth1.plugin' driver found, looking for 'openstack.cloud.auth'

During handling of the above exception, another exception occurred:
....
....
....
keystoneauth1.exceptions.auth_plugins.NoMatchingPlugin: The plugin openstack.cloud.auth could not be found

前一任务返回的api_token_response变量结构如下:

{
    "ansible_facts": {
        "discovered_interpreter_python": "/usr/bin/python3"
    },
    "auth_token": "asdf1234workssuccessfully",
    "changed": false,
    "failed": false
}
解决方案

你的问题确实是auth_type设置错误,同时auth参数的传递方式也有问题,修正方案如下:

  1. auth_type需改为token:openstack.cloud.auth不是合法的Keystone认证插件类型,使用已有令牌认证时,正确的插件类型是token。
  2. 正确构造auth参数:不能直接传入整个api_token_response变量,因为它包含Ansible任务的元数据(如changed、ansible_facts),需要提取其中的auth_token,并补充Keystone的auth_url(令牌认证必须指定Keystone地址)。

修正后的任务代码:

- name: "Use Token for Retrieving SGs"
  openstack.cloud.security_group_info:
    auth:
      auth_url: "http://你的Keystone地址:5000/v3"  # 替换为实际的OpenStack Keystone endpoint
      token: "{{ api_token_response.auth_token }}"
    auth_type: token
    name: default
  register: security_group_results

关键说明:

  • auth_type: token是Keystone官方支持的令牌认证插件,会被keystoneauth正确识别
  • auth字典中必须包含auth_url和token两个核心字段,缺一不可
  • 确保auth_url与你的OpenStack环境中Keystone的实际地址一致,通常格式为http://controller:5000/v3

内容的提问来源于stack exchange,提问作者HC LW

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 19:03:23