如何用Ansible实现AWS EC2 CentOS7实例间动态RSA密钥分发?
Let's get this sorted out. Your goal is to let the first instance in the test group (10.100.0.1) SSH into the other two CentOS 7 EC2 instances without hardcoding IPs. First, let's fix the issue in your existing task, then build out the full playbook to handle everything dynamically.
First: Fix the Key Generation Task
Your current command has a typo in the creates parameter (vid_rsa should be id_rsa). Also, we'll explicitly delegate this task to the first host in the test group to ensure it runs exactly where you need it:
- name: Generate RSA key pair for root on the first test instance command: ssh-keygen -q -t rsa -f /root/.ssh/id_rsa -N "" args: creates: /root/.ssh/id_rsa # Fixed the typo here delegate_to: "{{ groups['test'][0] }}" run_once: true
Next: Dynamically Distribute the Public Key to Other Test Instances
We need to target all hosts in the test group except the first one, set up the correct permissions for the centos user's .ssh directory, and add the public key to authorized_keys. Here's a clean, efficient playbook with all necessary tasks:
- name: Configure SSH access from first test instance to others hosts: test gather_facts: yes tasks: # Step 1: Generate RSA key pair on the first test instance (as root) - name: Generate RSA key pair for root command: ssh-keygen -q -t rsa -f /root/.ssh/id_rsa -N "" args: creates: /root/.ssh/id_rsa delegate_to: "{{ groups['test'][0] }}" run_once: true # Step 2: Capture the public key content directly from the first instance - name: Fetch root's public key content command: cat /root/.ssh/id_rsa.pub delegate_to: "{{ groups['test'][0] }}" run_once: true register: root_public_key # Step 3: Ensure .ssh directory exists for centos user with secure permissions - name: Create .ssh directory for centos user file: path: /home/centos/.ssh state: directory owner: centos group: centos mode: '0700' # Required for SSH to trust the directory when: inventory_hostname != groups['test'][0] # Skip the first instance # Step 4: Add the public key to centos user's authorized_keys - name: Inject root's public key into centos user's authorized_keys authorized_key: user: centos state: present key: "{{ root_public_key.stdout }}" when: inventory_hostname != groups['test'][0] # Skip the first instance
Key Details & Explanations:
- Dynamic Targeting: We use
groups['test'][0]to reference the first instance in your inventory group, andinventory_hostname != groups['test'][0]to target only the other two nodes—no hardcoded IPs required. - Permission Hardening: The
.sshdirectory must be set to0700(only accessible to the user) and theauthorized_keysfile gets automatically set to0600by theauthorized_keymodule—this is mandatory for SSH to accept the keys. - No Extra Files: By registering the public key content directly into a variable, we avoid copying files to the Ansible controller, making the playbook cleaner and faster.
- Run Once: Tasks that only need to execute once (key generation and fetching) use
run_once: trueto avoid redundant work across all hosts.
内容的提问来源于stack exchange,提问作者user6826691

