You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible执行s3_sync时报NoCredentialsError:无法定位凭证求助

Fixing "Unable to locate credentials" Error with Ansible s3_sync

Hey there, let's work through that botocore.exceptions.NoCredentialsError you're hitting when running your Ansible playbook. This error happens because the AWS SDK (boto3, which Ansible uses under the hood to interact with S3) can't find valid AWS credentials to authenticate your request. Here are the most reliable and secure ways to fix this:

1. Use the AWS Credentials File

The simplest approach is to set up a credentials file for the user executing the playbook. Since your playbook uses become: yes, it runs as the root user, so you'll need to create the file in /root/.aws/credentials (or in ~/.aws/credentials for ec2-user if you don't need to elevate privileges).

Create the file with this format:

[default]
aws_access_key_id = YOUR_AWS_ACCESS_KEY
aws_secret_access_key = YOUR_AWS_SECRET_KEY

Then lock down the file permissions to keep it secure:

chmod 600 /root/.aws/credentials

2. Pass Credentials via Environment Variables

You can inject credentials directly into your playbook using environment variables. Add an environment block to your play definition:

- name: main yaml file
  remote_user: ec2-user
  become: yes
  hosts: localhost
  environment:
    AWS_ACCESS_KEY_ID: "YOUR_AWS_ACCESS_KEY"
    AWS_SECRET_ACCESS_KEY: "YOUR_AWS_SECRET_KEY"
  roles:
    - s3

⚠️ Important: Never commit plaintext credentials to version control. Use Ansible Vault to encrypt these values if you need to store them in your playbook repository.

3. Use an IAM Role (Best Practice for EC2 Instances)

If your playbook is running on an AWS EC2 instance, the most secure method is to attach an IAM role to the instance. This lets boto3 automatically fetch temporary credentials without you having to store any keys manually.

You'll need an IAM role with these permissions for the s3uploadlocust bucket:

  • s3:ListBucket (to check existing files in the bucket)
  • s3:PutObject (to upload new files)
  • s3:PutObjectAcl (to apply the public-read permission)

Once the role is attached to your EC2 instance, you can remove all manual credential setup—Ansible will pick up the role's credentials automatically.

4. Specify Credentials Directly in the s3_sync Module

While this works, it's the least secure option unless you encrypt the values. If you need to use this method, add the credential parameters to your task:

- name: basic upload
  s3_sync:
    bucket: s3uploadlocust
    file_root: /home/ec2-user
    include: "*.csv"
    exclude: "*.txt,.*"
    permission: public-read
    file_change_strategy: force
    region: us-east-1
    aws_access_key: "YOUR_AWS_ACCESS_KEY"
    aws_secret_key: "YOUR_AWS_SECRET_KEY"

Again, use Ansible Vault to encrypt these credentials if you're storing this playbook anywhere.

Quick Fix for Your Playbook Structure

I noticed a small syntax issue in your playbook: you have a roles: - s3 line inside the play, then another standalone roles block outside the play. That's not valid Ansible syntax. You should either:

  • Move your s3_sync task into roles/s3/tasks/main.yml (following proper Ansible role structure), or
  • Replace the roles line with a tasks block directly in the play, like this:
- name: main yaml file
  remote_user: ec2-user
  become: yes
  hosts: localhost
  tasks:
    - name: basic upload
      s3_sync:
        bucket: s3uploadlocust
        file_root: /home/ec2-user
        include: "*.csv"
        exclude: "*.txt,.*"
        permission: public-read
        file_change_strategy: force
        region: us-east-1

Pick the solution that fits your environment best—using an IAM role is always the most secure choice if you're running on EC2.

内容的提问来源于stack exchange,提问作者Nagarjuna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 17:02:35