使用Ansible的github_repo模块创建GitHub仓库时遇SSL证书错误
解决Ansible github_repo模块访问企业版GitHub的SSLError问题
核心原因
Git的http.sslverify配置不会作用于Ansible的github_repo模块,模块使用独立的HTTP客户端逻辑;另外如果未指定企业版GitHub的API地址,模块会默认访问公共GitHub的api.github.com,这也会导致企业版证书验证失败。
具体解决方法
模块内直接禁用SSL验证(快速测试场景)
给github_repo模块添加validate_certs: no参数,同时必须指定企业版的API地址:- name: 创建企业版GitHub仓库 github_repo: name: test-repo token: "{{ your_personal_access_token }}" enterprise_url: "https://your-ghe-domain/api/v3" validate_certs: no导入企业版CA证书(安全推荐方案)
若不想禁用验证,可将企业版GitHub的CA证书导入主机信任库,或直接在模块中指定证书路径:- name: 创建企业版GitHub仓库 github_repo: name: test-repo token: "{{ your_personal_access_token }}" enterprise_url: "https://your-ghe-domain/api/v3" ca_cert: "/etc/pki/ca-trust/source/anchors/ghe-ca.crt"全局禁用Ansible SSL验证(不推荐)
在ansible.cfg中添加全局配置:[defaults] validate_certs = False或执行任务前设置环境变量:
export ANSIBLE_VALIDATE_CERTS=False
内容的提问来源于stack exchange,提问作者hiero-nymus
相关产品推荐
相关产品推荐

