ansible-galaxy命令未使用已配置HTTP代理的问题求助
Ansible-Galaxy 不使用HTTP代理导致连接超时问题排查与解决
问题现象
执行sudo ansible-galaxy collection install community.docker时出现连接超时错误:
sudo ansible-galaxy collection install community.docker [sudo] password for <user>: [WARNING]: - collection was NOT installed successfully: Failed to get data from the API server (https://galaxy.ansible.com/api/): Failed to connect to galaxy.ansible.com at port 443: [Errno 110] Connection timed out ERROR! - you can use --ignore-errors to skip failed roles and finish processing the list.
已配置http_proxy、https_proxy、HTTP_PROXY、HTTPS_PROXY环境变量,curl google.com可正常通过代理访问,但Wireshark显示ansible-galaxy直接连接galaxy.ansible.com(IP:104.206.0.234),未走代理。
当前Ansible版本信息:
ansible 2.5.1 config file = /etc/ansible/ansible.cfg configured module search path = [u'/home/<user>/.ansible/plugins/modules', u'/usr/share/ansible/plugins/modules'] ansible python module location = /usr/lib/python2.7/dist-packages/ansible executable location = /usr/bin/ansible python version = 2.7.17 (default, Jul 1 2022, 15:56:32) [GCC 7.5.0]
解决方法
1. 使用sudo -E保留用户环境变量
sudo默认会重置环境变量,导致代理配置丢失。执行命令时添加-E参数,保留当前用户的环境变量:
sudo -E ansible-galaxy collection install community.docker
2. 在Ansible配置文件中显式设置代理
编辑/etc/ansible/ansible.cfg,找到[galaxy]段(如果没有则新增),添加代理配置:
[galaxy] http_proxy=http://<代理地址>:<端口>/ https_proxy=https://<代理地址>:<端口>/ # 若代理需要认证,格式为 http://<用户名>:<密码>@<代理地址>:<端口>/
保存配置后,重新执行安装命令即可。
3. 直接在sudo命令中指定代理环境变量
如果-E参数无效,可直接在sudo命令中显式传递代理变量:
sudo http_proxy=http://<代理地址>:<端口> https_proxy=https://<代理地址>:<端口> ansible-galaxy collection install community.docker
原因说明
curl正常是因为直接使用当前用户的环境变量,而sudo默认会清除大部分环境变量,导致ansible-galaxy无法读取代理配置。- Ansible 2.5.x属于较旧版本,部分组件对系统代理环境变量的自动识别支持不完善,需要显式配置。
内容的提问来源于stack exchange,提问作者DB_Tz
相关产品推荐
相关产品推荐

