You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Ansible创建PostgreSQL数据库用户时遭遇Peer认证失败

解决Ansible创建PostgreSQL用户时的"Peer authentication failed"错误

错误原因

PostgreSQL默认对本地连接采用Peer认证,要求操作系统用户名与PostgreSQL用户名完全匹配。你的playbook用become: true切换到root用户执行任务,而community.postgresql.postgresql_user模块默认会以postgres用户身份尝试连接数据库,root与postgres并非同一系统用户,因此触发Peer认证失败。


解决方案

方法一:切换到postgres系统用户执行数据库任务

这是最直接且符合PostgreSQL安全规范的方式,在创建用户的任务中指定become_user: postgres,让任务以postgres系统用户身份执行,Peer认证即可匹配:

---
- name: postgresql demo
  hosts: all
  become: true
  become_method: sudo
  vars:
    db_user: myuser
    db_password: MySecretPassword123

  tasks:
    - name: Utility present
      ansible.builtin.package:
        name: python3-psycopg2
        state: present

    - name: Create db user
      become_user: postgres  # 新增该行,切换到postgres用户执行
      community.postgresql.postgresql_user:
        state: present
        name: "{{ db_user }}"
        password: "{{ db_password }}"

方法二:配置密码认证替代Peer认证

如果需要保持root用户执行任务,可修改PostgreSQL的认证规则,允许密码登录:

  1. 先为postgres用户设置密码:
- name: Set postgres user password
  become_user: postgres
  community.postgresql.postgresql_user:
    name: postgres
    password: "YourSecurePostgresPassword"
  1. 修改pg_hba.conf,将postgres用户的本地认证方式从peer改为scram-sha-256(或md5,推荐前者):
- name: Update pg_hba.conf for password authentication
  ansible.builtin.lineinfile:
    path: /etc/postgresql/<你的PostgreSQL版本>/main/pg_hba.conf
    regexp: '^local   all             postgres                                peer'
    line: 'local   all             postgres                                scram-sha-256'
  notify: Restart PostgreSQL
  1. 添加重启PostgreSQL的handler:
handlers:
  - name: Restart PostgreSQL
    ansible.builtin.service:
      name: postgresql
      state: restarted
  1. 修改创建用户的任务,指定登录参数:
- name: Create db user
  community.postgresql.postgresql_user:
    state: present
    name: "{{ db_user }}"
    password: "{{ db_password }}"
    login_user: postgres
    login_password: "YourSecurePostgresPassword"

方法三:临时放宽认证规则(不推荐生产环境)

若仅需临时执行任务,可短暂将认证方式改为trust,完成后恢复,但此方式存在安全风险:

- name: Temporarily allow trust authentication for postgres
  become_user: postgres
  ansible.builtin.lineinfile:
    path: /etc/postgresql/<你的PostgreSQL版本>/main/pg_hba.conf
    regexp: '^local   all             postgres                                peer'
    line: 'local   all             postgres                                trust'
  notify: Restart PostgreSQL

- name: Create db user
  community.postgresql.postgresql_user:
    state: present
    name: "{{ db_user }}"
    password: "{{ db_password }}"

- name: Restore peer authentication for postgres
  become_user: postgres
  ansible.builtin.lineinfile:
    path: /etc/postgresql/<你的PostgreSQL版本>/main/pg_hba.conf
    regexp: '^local   all             postgres                                trust'
    line: 'local   all             postgres                                peer'
  notify: Restart PostgreSQL

内容的提问来源于stack exchange,提问作者Aris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 07:10:06