使用Ansible Vault加密密码后hosts文件解析失败求助
问题:Ansible Vault加密密码替换后Hosts文件解析失败
报错信息
[WARNING]: * Failed to parse /var/lib/awx/projects/Windows/hosts with yaml plugin: We were unable to read either as JSON nor YAML, these are the errors we got from each: JSON: Expecting value: line 1 column 2 (char 1) Syntax Error while loading YAML. did not find expected <document start> The error appears to be in '/var/lib/awx/projects/AD/WindowsAD/hosts': line 2, column 1, but may be elsewhere in the file depending on the exact syntax problem. The offending line appears to be: [Windows] 10.15.200.130 ^ here
[WARNING]: * Failed to parse /var/lib/awx/projects/Windows/hosts with ini plugin: /var/lib/awx/projects/Windows/hosts:7: Expected key=value, got: $ANSIBLE_VAULT;1.1;AES256
出错的Hosts文件内容
[Windows] 10.15.200.130 [Windows:vars] ansible_user=domain\username ansible_password=!vault | $ANSIBLE_VAULT;1.1;AES256 62303438666666336666343361326637376135363461326430336438306237363330303765393438 6565373439616366663836656238643132346264356162350a643533373632393639376335356464 65363934613137653730636633363761346538393562653137666331303834633563303538643961 3965356162623463370a653266663231336430643538363737633862613662663062616139613137 6330 ansible_connection=winrm ansible_port=5985 ansible_winrm_transport=credssp ansible_winrm_server_cert_validation=ignore ansible_winrm_kerberos_delegation=true [test] 10.15.170.22 [test:vars] ansible_user=user ansible_password=!vault | $ANSIBLE_VAULT;1.1;AES256 65353661646365653531376564373966623933386336623538386435643738636566633132633763 6232633465336337373839303130393066633439316335660a636136636539346666633032613838 32313162393338353265313365356435626664373766626461326563393830313665393933386337 6162643836393766360a316238313861646235343833313232633164316434643765313261346630 3966 ansible_connection=winrm ansible_port=5986 ansible_winrm_transport=basic ansible_winrm_server_cert_validation=ignore
已尝试的无效操作
将Vault加密内容合并为单行,问题仍未解决:
ansible_password=!vault | $ANSIBLE_VAULT;1.1;AES256 623034386666663366663433613266373761353634613264303364383062373633303037653934386565373439616366663836656238643132346264356162350a643533373632393639376335356464653639346131376537306366333637613465383935626531376663313038346335633035386439613965356162623463370a6532666632313364306435383637376338626136626630626161396131376330 ansible_password=!vault | $ANSIBLE_VAULT;1.1;AES256 653536616463656535313765643739666239333863366235383864356437386365666331326337636232633465336337373839303130393066633439316335660a636136636539346666633032613838323131623933383532653133653564356266643737666264613265633938303136653939333863376162643836393766360a3162383138616462353438333132326331643164346437653132613466303966
解决方案
问题根源
INI格式的inventory文件不支持YAML风格的多行!vault |语法,Ansible的INI插件无法解析跨多行的Vault加密值。
方法1:生成单行Vault加密字符串
使用ansible-vault encrypt_string命令生成适合INI文件的单行加密值:
ansible-vault encrypt_string '你的明文密码' --name 'ansible_password'
命令输出的内容需完全合并为单行(删除所有换行),最终格式如下:
ansible_password=!vault | $ANSIBLE_VAULT;1.1;AES256 623034386666663366663433613266373761353634613264303364383062373633303037653934386565373439616366663836656238643132346264356162350a643533373632393639376335356464653639346131376537306366333637613465383935626531376663313038346335633035386439613965356162623463370a6532666632313364306435383637376338626136626630626161396131376330
将该单行值直接替换到INI格式的hosts文件中即可。
方法2:改用YAML格式的inventory文件
将原INI格式的hosts文件转换为YAML格式,原生支持多行Vault语法,示例如下:
all: children: Windows: hosts: 10.15.200.130: vars: ansible_user: domain\username ansible_password: !vault | $ANSIBLE_VAULT;1.1;AES256 62303438666666336666343361326637376135363461326430336438306237363330303765393438 6565373439616366663836656238643132346264356162350a643533373632393639376335356464 65363934613137653730636633363761346538393562653137666331303834633563303538643961 3965356162623463370a653266663231336430643538363737633862613662663062616139613137 6330 ansible_connection: winrm ansible_port: 5985 ansible_winrm_transport: credssp ansible_winrm_server_cert_validation: ignore ansible_winrm_kerberos_delegation: true test: hosts: 10.15.170.22: vars: ansible_user: user ansible_password: !vault | $ANSIBLE_VAULT;1.1;AES256 65353661646365653531376564373966623933386336623538386435643738636566633132633763 6232633465336337373839303130393066633439316335660a636136636539346666633032613838 32313162393338353265313365356435626664373766626461326563393830313665393933386337 6162643836393766360a316238313861646235343833313232633164316434643765313261346630 3966 ansible_connection: winrm ansible_port: 5986 ansible_winrm_transport: basic ansible_winrm_server_cert_validation: ignore
内容的提问来源于stack exchange,提问作者Whaily
相关产品推荐
相关产品推荐

