在GitHub Actions的ubuntu-latest上运行带AWS动态Inventory的Ansible报错求助
问题:Ansible无法加载AWS动态Inventory
已尝试的GitHub Actions工作流配置
name: Terraform-ansible-apply on: workflow_dispatch: jobs: Terraform: name: Terraform Plan & Apply runs-on: ubuntu-latest env: AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }} steps: - name: Checkout Repo uses: actions/checkout@v2 - name: Terraform Setup uses: hashicorp/setup-terraform@v1 with: terraform_wrapper: false - name: Terraform Init run: terraform init working-directory: ./Terraform - name: Terraform Validate run: terraform validate working-directory: ./Terraform - name: Terraform Apply id: tf-apply run: terraform apply -auto-approve working-directory: ./Terraform ################ - name: install continue-on-error: true run: | pipx install boto3 --include-deps pipx install botocore --include-deps - name: Run Ansible playbook run: | ansible --version ansible-galaxy collection list ansible-inventory -i aws_ec2.yaml --graph working-directory: ./Ansible
出现的错误信息
Warning: : * Failed to parse /home/runner/work/AWS-project/AWS- project/Ansible/aws_ec2.yaml with ansible_collections.amazon.aws.plugins.inventory.aws_ec2 plugin: Failed to import the required Python library (botocore and boto3) on fv-az613-985's Python /opt/pipx/venvs/ansible-core/bin/python. Please read the module documentation and install it in the appropriate location. If the required library is installed, but Ansible is using the wrong Python interpreter, please consult the documentation on ansible_python_interpreter Warning: : Unable to parse /home/runner/work/AWS-project/AWS- project/Ansible/aws_ec2.yaml as an inventory source Warning: : No inventory was parsed, only implicit localhost is available @all: |--@ungrouped:
现有配置信息
ansible.cfg内容
host_key_checking = False remote_user=ubuntu become=True enable_plugins = aws_ec2 host_key_checking=False
AWS动态Inventory文件aws_ec2.yaml内容
plugin: aws_ec2 regions: - eu-central-1
Ansible版本信息
ansible --version ansible [core 2.15.1] config file = /home/runner/work/AWS-project/AWS-project/Ansible/ansible.cfg configured module search path = ['/home/runner/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules'] ansible python module location = /opt/pipx/venvs/ansible-core/lib/python3.10/site-packages/ansible ansible collection location = /home/runner/.ansible/collections:/usr/share/ansible/collections executable location = /opt/pipx_bin/ansible python version = 3.10.6 (main, May 29 2023, 11:10:38) [GCC 11.3.0] (/opt/pipx/venvs/ansible-core/bin/python) jinja version = 3.1.2 libyaml = True
注:amazon.aws集合已安装,AWS凭证通过GitHub Secrets配置正确,Terraform运行正常
问题分析与解决方案
核心问题
通过pipx install单独安装的boto3和botocore,没有进入Ansible使用的独立虚拟环境(/opt/pipx/venvs/ansible-core/bin/python),导致Ansible加载AWS插件时找不到依赖库。
具体修复步骤
调整依赖安装方式
替换原工作流中的install步骤,使用pipx inject将boto3和botocore注入到ansible-core的虚拟环境中,确保Ansible能调用到:- name: Install Ansible AWS dependencies run: | pipx inject ansible-core boto3 botocore同时去掉
continue-on-error: true,依赖安装必须成功才能继续后续步骤。验证凭证传递
工作流中已通过全局env配置AWS凭证,无需额外修改,可在Ansible步骤中添加以下命令确认变量存在(不要输出完整密钥):echo "AWS_ACCESS_KEY_ID exists: $([ -n "$AWS_ACCESS_KEY_ID" ] && echo yes || echo no)"确认插件配置
ansible.cfg中enable_plugins = aws_ec2配置正确,动态Inventory文件格式无误,无需调整。
修改后的完整Ansible相关步骤
- name: Install Ansible AWS dependencies run: | pipx inject ansible-core boto3 botocore - name: Run Ansible playbook run: | ansible --version ansible-galaxy collection list ansible-inventory -i aws_ec2.yaml --graph working-directory: ./Ansible
内容的提问来源于stack exchange,提问作者petronomus
相关产品推荐
相关产品推荐

