You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Ansible实现AWS EC2 CentOS7实例间动态RSA密钥分发?

Solution for Dynamic SSH Key Distribution in Ansible

Let's get this sorted out. Your goal is to let the first instance in the test group (10.100.0.1) SSH into the other two CentOS 7 EC2 instances without hardcoding IPs. First, let's fix the issue in your existing task, then build out the full playbook to handle everything dynamically.

First: Fix the Key Generation Task

Your current command has a typo in the creates parameter (vid_rsa should be id_rsa). Also, we'll explicitly delegate this task to the first host in the test group to ensure it runs exactly where you need it:

- name: Generate RSA key pair for root on the first test instance
  command: ssh-keygen -q -t rsa -f /root/.ssh/id_rsa -N ""
  args:
    creates: /root/.ssh/id_rsa  # Fixed the typo here
  delegate_to: "{{ groups['test'][0] }}"
  run_once: true

Next: Dynamically Distribute the Public Key to Other Test Instances

We need to target all hosts in the test group except the first one, set up the correct permissions for the centos user's .ssh directory, and add the public key to authorized_keys. Here's a clean, efficient playbook with all necessary tasks:

- name: Configure SSH access from first test instance to others
  hosts: test
  gather_facts: yes
  tasks:
    # Step 1: Generate RSA key pair on the first test instance (as root)
    - name: Generate RSA key pair for root
      command: ssh-keygen -q -t rsa -f /root/.ssh/id_rsa -N ""
      args:
        creates: /root/.ssh/id_rsa
      delegate_to: "{{ groups['test'][0] }}"
      run_once: true

    # Step 2: Capture the public key content directly from the first instance
    - name: Fetch root's public key content
      command: cat /root/.ssh/id_rsa.pub
      delegate_to: "{{ groups['test'][0] }}"
      run_once: true
      register: root_public_key

    # Step 3: Ensure .ssh directory exists for centos user with secure permissions
    - name: Create .ssh directory for centos user
      file:
        path: /home/centos/.ssh
        state: directory
        owner: centos
        group: centos
        mode: '0700'  # Required for SSH to trust the directory
      when: inventory_hostname != groups['test'][0]  # Skip the first instance

    # Step 4: Add the public key to centos user's authorized_keys
    - name: Inject root's public key into centos user's authorized_keys
      authorized_key:
        user: centos
        state: present
        key: "{{ root_public_key.stdout }}"
      when: inventory_hostname != groups['test'][0]  # Skip the first instance

Key Details & Explanations:

  • Dynamic Targeting: We use groups['test'][0] to reference the first instance in your inventory group, and inventory_hostname != groups['test'][0] to target only the other two nodes—no hardcoded IPs required.
  • Permission Hardening: The .ssh directory must be set to 0700 (only accessible to the user) and the authorized_keys file gets automatically set to 0600 by the authorized_key module—this is mandatory for SSH to accept the keys.
  • No Extra Files: By registering the public key content directly into a variable, we avoid copying files to the Ansible controller, making the playbook cleaner and faster.
  • Run Once: Tasks that only need to execute once (key generation and fetching) use run_once: true to avoid redundant work across all hosts.

内容的提问来源于stack exchange,提问作者user6826691

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:59:49