使用Ansible Playbook创建Kubernetes资源时遇权限认证问题
Ansible执行kubectl命令出现认证错误的解决方法
问题背景
我编写了用于创建Kubernetes Deployment和Service的Ansible Playbook,但执行时出现kubectl认证错误。直接以ubuntu用户在终端执行kubectl命令正常,但通过Playbook运行就报错,核心错误提示为Authentication required。
我的Playbook内容
--- - hosts: master user: ubuntu tasks: - name: check version command: kubectl version - name: create deployment command: kubectl apply -f abc-deployment.yml args: chdir: /project/abc-technologies/kubernetes-files - name: create service command: kubectl apply -f abc-service.yml args: chdir: /project/abc-technologies/kubernetes-files - name: update deployment if pods updated in container repository command: kubectl rollout restart deployment.apps/abc-deploy
关键错误信息
Error from server (Forbidden): <html><head><meta http-equiv='refresh' content='1;url=/login?from=%2Fversion%3Ftimeout%3D32s'/></script></head><body>Authentication required</body></html>
原因分析
- 交互式终端登录ubuntu用户时,shell会自动加载
~/.bashrc、~/.profile等配置文件,kubectl默认读取~/.kube/config作为认证配置,此时环境变量和权限都正常。 - Ansible执行命令时采用非交互式非登录shell,不会自动加载用户的shell配置,导致kubectl无法找到正确的kubeconfig文件,或者缺失必要的环境变量,最终触发认证失败。
解决方案
方案1:显式指定kubeconfig路径
在每个kubectl命令中直接指定ubuntu用户的kubeconfig文件路径,确保kubectl能定位到正确的认证配置:
修改后的Playbook示例:
--- - hosts: master user: ubuntu tasks: - name: check version command: kubectl version --kubeconfig /home/ubuntu/.kube/config - name: create deployment command: kubectl apply -f abc-deployment.yml --kubeconfig /home/ubuntu/.kube/config args: chdir: /project/abc-technologies/kubernetes-files - name: create service command: kubectl apply -f abc-service.yml --kubeconfig /home/ubuntu/.kube/config args: chdir: /project/abc-technologies/kubernetes-files - name: update deployment if pods updated in container repository command: kubectl rollout restart deployment.apps/abc-deploy --kubeconfig /home/ubuntu/.kube/config
或者通过环境变量统一设置,避免重复指定:
--- - hosts: master user: ubuntu environment: KUBECONFIG: /home/ubuntu/.kube/config tasks: - name: check version command: kubectl version - name: create deployment command: kubectl apply -f abc-deployment.yml args: chdir: /project/abc-technologies/kubernetes-files - name: create service command: kubectl apply -f abc-service.yml args: chdir: /project/abc-technologies/kubernetes-files - name: update deployment if pods updated in container repository command: kubectl rollout restart deployment.apps/abc-deploy
方案2:让Ansible使用登录shell执行命令
改用shell模块,并指定bash以登录模式执行,强制加载用户的shell配置文件,确保kubectl能读取到正确的环境变量:
--- - hosts: master user: ubuntu tasks: - name: check version shell: kubectl version args: executable: /bin/bash -l - name: create deployment shell: kubectl apply -f abc-deployment.yml args: chdir: /project/abc-technologies/kubernetes-files executable: /bin/bash -l - name: create service shell: kubectl apply -f abc-service.yml args: chdir: /project/abc-technologies/kubernetes-files executable: /bin/bash -l - name: update deployment if pods updated in container repository shell: kubectl rollout restart deployment.apps/abc-deploy args: executable: /bin/bash -l
方案3:验证kubeconfig文件权限
确保ubuntu用户对kubeconfig文件拥有正确的读写权限,避免Ansible执行时出现权限不足的问题:
--- - hosts: master user: ubuntu tasks: - name: ensure kubeconfig has correct permissions file: path: /home/ubuntu/.kube/config owner: ubuntu group: ubuntu mode: '0600' - name: check version command: kubectl version # 后续任务保持不变...
内容的提问来源于stack exchange,提问作者VivekGupta434
相关产品推荐
相关产品推荐

