You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWX Operator同步含Vault密钥的Git库存失败,修改Deployment后Pod崩溃

AWX Operator同步含Vault密钥的Git清单失败及Pod CrashLoop问题解决

问题场景

通过awx-operator部署的AWX,从Git仓库导入包含Ansible Vault加密内容的清单时,同步任务失败,报错:

ERROR! Attempting to decrypt but no vault secrets found

尝试手动在节点创建密码文件并设置ANSIBLE_VAULT_PASSWORD_FILE额外变量,但通过kubectl edit deployment修改initContainers后,Pod进入CrashLoopBackOff,查看Pod描述发现启动错误:

exec: "/bin/echo \"XXXXXXXX\" > /tmp/vault_password": stat /bin/echo "XXXXXXXX" > /tmp/vault_password: no such file or directory: unknown

错误原因分析

Kubernetes容器的Command字段用于指定可执行程序路径,而非完整shell命令串。你将echo "XXXX" > /tmp/vault_password作为Command的第一个元素,Kubernetes会尝试寻找名为/bin/echo "XXXX" > /tmp/vault_password的可执行文件,显然该文件不存在,导致容器启动失败。

正确解决方案

1. 用Kubernetes Secret存储Vault密码(推荐)

明文写入容器命令存在安全风险,优先用Secret存储密码:

kubectl create secret generic awx-vault-password -n awx --from-literal=password="你的Vault解密密码"

2. 通过AWX CR配置(避免手动改Deployment被operator覆盖)

编辑AWX自定义资源,让operator自动管理Pod挂载和环境变量:

kubectl edit awx awx-demo -n awx

添加以下配置片段:

spec:
  extra_env:
    - name: ANSIBLE_VAULT_PASSWORD_FILE
      value: /etc/vault/password
  extra_volumes:
    - name: vault-password
      secret:
        secretName: awx-vault-password
  extra_volume_mounts:
    - name: vault-password
      mountPath: /etc/vault
      readOnly: true

保存后,awx-operator会自动更新Deployment,无需手动修改Pod定义。

3. 修复Init容器命令(临时测试用,不推荐明文)

如果一定要用Init容器创建密码文件,需用/bin/sh -c包裹所有命令:

initContainers:
  init:
    Command:
      - /bin/sh
      - -c
      - |
        echo "你的Vault解密密码" > /tmp/vault_password
        chmod 600 /tmp/vault_password
        hostname=$MY_POD_NAME
        receptor --cert-makereq bits=2048 commonname=$hostname dnsname=$hostname nodeid=$hostname outreq=/etc/receptor/tls/receptor.req outkey=/etc/receptor/tls/receptor.key
        receptor --cert-signreq req=/etc/receptor/tls/receptor.req cacert=/etc/receptor/tls/ca/receptor-ca.crt cakey=/etc/receptor/tls/ca/receptor-ca.key outcert=/etc/receptor/tls/receptor.crt verify=yes

注意:将所有执行逻辑放在-c后的多行字符串中,同时将密码文件权限设为600(最小权限原则,避免777的安全风险)。

4. 验证配置

Pod重启后,检查密码文件是否正常存在:

# 对应Secret挂载方式
kubectl exec -n awx awx-demo-xxxx-xxxx -- cat /etc/vault/password
# 对应Init容器创建方式
kubectl exec -n awx awx-demo-xxxx-xxxx -- cat /tmp/vault_password

重新触发清单同步,验证Vault加密内容是否能正常解密。

内容的提问来源于stack exchange,提问作者Red Cricket

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 02:56:11