You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Ansible Playbook创建Kubernetes资源时遇权限认证问题

Ansible执行kubectl命令出现认证错误的解决方法

问题背景

我编写了用于创建Kubernetes Deployment和Service的Ansible Playbook,但执行时出现kubectl认证错误。直接以ubuntu用户在终端执行kubectl命令正常,但通过Playbook运行就报错,核心错误提示为Authentication required。

我的Playbook内容

---
- hosts: master
  user: ubuntu

  tasks:
    - name: check version
      command: kubectl version

    - name: create deployment
      command: kubectl apply -f abc-deployment.yml
      args:
        chdir: /project/abc-technologies/kubernetes-files

    - name: create service
      command: kubectl apply -f abc-service.yml
      args:
        chdir: /project/abc-technologies/kubernetes-files

    - name: update deployment if pods updated in container repository
      command: kubectl rollout restart deployment.apps/abc-deploy

关键错误信息

Error from server (Forbidden): <html><head><meta http-equiv='refresh' content='1;url=/login?from=%2Fversion%3Ftimeout%3D32s'/></script></head><body>Authentication required</body></html>

原因分析

  • 交互式终端登录ubuntu用户时,shell会自动加载~/.bashrc、~/.profile等配置文件,kubectl默认读取~/.kube/config作为认证配置,此时环境变量和权限都正常。
  • Ansible执行命令时采用非交互式非登录shell,不会自动加载用户的shell配置,导致kubectl无法找到正确的kubeconfig文件,或者缺失必要的环境变量,最终触发认证失败。

解决方案

方案1:显式指定kubeconfig路径

在每个kubectl命令中直接指定ubuntu用户的kubeconfig文件路径,确保kubectl能定位到正确的认证配置:

修改后的Playbook示例:

---
- hosts: master
  user: ubuntu

  tasks:
    - name: check version
      command: kubectl version --kubeconfig /home/ubuntu/.kube/config

    - name: create deployment
      command: kubectl apply -f abc-deployment.yml --kubeconfig /home/ubuntu/.kube/config
      args:
        chdir: /project/abc-technologies/kubernetes-files

    - name: create service
      command: kubectl apply -f abc-service.yml --kubeconfig /home/ubuntu/.kube/config
      args:
        chdir: /project/abc-technologies/kubernetes-files

    - name: update deployment if pods updated in container repository
      command: kubectl rollout restart deployment.apps/abc-deploy --kubeconfig /home/ubuntu/.kube/config

或者通过环境变量统一设置,避免重复指定:

---
- hosts: master
  user: ubuntu
  environment:
    KUBECONFIG: /home/ubuntu/.kube/config

  tasks:
    - name: check version
      command: kubectl version

    - name: create deployment
      command: kubectl apply -f abc-deployment.yml
      args:
        chdir: /project/abc-technologies/kubernetes-files

    - name: create service
      command: kubectl apply -f abc-service.yml
      args:
        chdir: /project/abc-technologies/kubernetes-files

    - name: update deployment if pods updated in container repository
      command: kubectl rollout restart deployment.apps/abc-deploy

方案2:让Ansible使用登录shell执行命令

改用shell模块,并指定bash以登录模式执行,强制加载用户的shell配置文件,确保kubectl能读取到正确的环境变量:

---
- hosts: master
  user: ubuntu

  tasks:
    - name: check version
      shell: kubectl version
      args:
        executable: /bin/bash -l

    - name: create deployment
      shell: kubectl apply -f abc-deployment.yml
      args:
        chdir: /project/abc-technologies/kubernetes-files
        executable: /bin/bash -l

    - name: create service
      shell: kubectl apply -f abc-service.yml
      args:
        chdir: /project/abc-technologies/kubernetes-files
        executable: /bin/bash -l

    - name: update deployment if pods updated in container repository
      shell: kubectl rollout restart deployment.apps/abc-deploy
      args:
        executable: /bin/bash -l

方案3:验证kubeconfig文件权限

确保ubuntu用户对kubeconfig文件拥有正确的读写权限,避免Ansible执行时出现权限不足的问题:

---
- hosts: master
  user: ubuntu

  tasks:
    - name: ensure kubeconfig has correct permissions
      file:
        path: /home/ubuntu/.kube/config
        owner: ubuntu
        group: ubuntu
        mode: '0600'

    - name: check version
      command: kubectl version

    # 后续任务保持不变...

内容的提问来源于stack exchange,提问作者VivekGupta434

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 23:50:15