You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Ansible为Elastic集群生成TLS证书时标准输入读取报错如何解决

问题原因

unable to read from standard input; is standard input open and a tty attached?报错的核心原因是Ansible的shell模块默认执行命令时不会分配伪终端(TTY),而elasticsearch-certutil即使添加了静默参数-s,仍会检测标准输入的TTY状态,无TTY时就会抛出该错误。

解决方案

方案1:为Ansible任务启用PTY分配(优先推荐)

直接在现有shell任务中添加pty: yes参数,让Ansible为该任务分配伪终端,匹配工具的运行要求,修改后的任务如下:

- name: Create certificates p12
  shell: |
    cd /usr/share/elasticsearch && \
    ./bin/elasticsearch-certutil ca -s --out elastic-stack-ca.p12 --pass {{ ca_password }} && \
    ./bin/elasticsearch-certutil cert -s --ca elastic-stack-ca.p12 --ca-pass {{ ca_password }} --out elastic-certificates.p12 --pass {{ cert_password }} && \
    cp elastic-certificates.p12 /etc/elasticsearch && \
    chmod 660 /etc/elasticsearch/elastic-certificates.p12
  # 新增以下行,分配伪终端
  pty: yes

该方案改动最小,不会影响原有命令逻辑。

方案2:喂入空输入绕过TTY检测

如果环境限制无法开启pty,可以在每个elasticsearch-certutil命令前加echo |前缀,强制给标准输入传入空内容,绕过TTY校验,修改后的完整任务如下:

- name: Create certificates p12
  shell: |
    cd /usr/share/elasticsearch && \
    echo | ./bin/elasticsearch-certutil ca -s --out elastic-stack-ca.p12 --pass {{ ca_password }} && \
    echo | ./bin/elasticsearch-certutil cert -s --ca elastic-stack-ca.p12 --ca-pass {{ ca_password }} --out elastic-certificates.p12 --pass {{ cert_password }} && \
    cp elastic-certificates.p12 /etc/elasticsearch && \
    chmod 660 /etc/elasticsearch/elastic-certificates.p12

内容的提问来源于stack exchange,提问作者Mikhail Znak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 02:30:02