You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过编程方式获取GitLab密钥哈希?Ansible部署GitLab密钥获取咨询

Great question—automating these token/secret retrievals is critical for building a fully hands-off GitLab deployment with Ansible. Let’s break down safe, programmatic methods for both GitLab Runner and Mattermost, no manual UI clicks required.

获取GitLab Runner的Registration Token

You’ve got two reliable options here, depending on whether you prefer using the GitLab API or the Omnibus-built Rails console:

方法1:GitLab API(实例级令牌)

If you’re targeting the instance-wide runner registration token, the API endpoint is straightforward—you might have overlooked it! You’ll need an admin-level personal access token (PAT) with the admin_runner scope.

The API call looks like this:

curl --header "PRIVATE-TOKEN: YOUR_ADMIN_PAT" "https://your-gitlab-instance/api/v4/runners/registration_token"

In Ansible, you can use the uri module to fetch this:

- name: Fetch instance-level GitLab Runner registration token
  uri:
    url: "{{ gitlab_base_url }}/api/v4/runners/registration_token"
    headers:
      PRIVATE-TOKEN: "{{ gitlab_admin_pat }}"
    method: GET
    return_content: true
    validate_certs: true
  register: runner_reg_token
  no_log: true  # Keep the token out of logs!

For group or project-specific tokens, use the respective API endpoints:

  • Group: GET /api/v4/groups/:id/runners/registration_token
  • Project: GET /api/v4/projects/:id/runners/registration_token

方法2:GitLab Rails Console(Omnibus专属)

Since you’re using the Omnibus package, you can run a Rails console command directly on the server to pull the token without API calls. This requires root access:

- name: Retrieve Runner registration token via Rails console
  command: gitlab-rails runner "puts Gitlab::CurrentSettings.current_application_settings.runners_registration_token"
  register: runner_reg_token
  become: true
  no_log: true
获取Mattermost的Application ID和Secret

Mattermost integrates with GitLab via an OAuth application—Omnibus typically creates this automatically during installation. You can fetch its credentials via either the Rails console or GitLab API:

方法1:GitLab Rails Console

Run this command to locate the Mattermost OAuth application and output its ID and secret:

- name: Get Mattermost OAuth credentials from Rails console
  command: >
    gitlab-rails runner "
      app = Doorkeeper::Application.find_by(name: 'Mattermost');
      puts \"#{app.id},#{app.secret}\"
    "
  register: mattermost_creds
  become: true
  no_log: true
  changed_when: false

- name: Parse Mattermost credentials into variables
  set_fact:
    mattermost_app_id: "{{ mattermost_creds.stdout.split(',')[0] }}"
    mattermost_app_secret: "{{ mattermost_creds.stdout.split(',')[1] }}"

方法2:GitLab API

Use the applications endpoint to list all OAuth apps, then filter for the one named "Mattermost". Again, you’ll need an admin PAT with admin_api scope:

- name: Fetch all GitLab OAuth applications
  uri:
    url: "{{ gitlab_base_url }}/api/v4/applications"
    headers:
      PRIVATE-TOKEN: "{{ gitlab_admin_pat }}"
    method: GET
    return_content: true
    validate_certs: true
  register: gitlab_apps
  no_log: true

- name: Extract Mattermost application credentials
  set_fact:
    mattermost_app: "{{ gitlab_apps.json | selectattr('name', 'equalto', 'Mattermost') | first }}"
    mattermost_app_id: "{{ (gitlab_apps.json | selectattr('name', 'equalto', 'Mattermost') | first).id }}"
    mattermost_app_secret: "{{ (gitlab_apps.json | selectattr('name', 'equalto', 'Mattermost') | first).secret }}"
安全最佳实践
  • Minimize PAT scopes: Only grant the necessary permissions (e.g., admin_runner for tokens, admin_api for apps) instead of full admin access.
  • Encrypt sensitive data: Store your admin PAT and retrieved tokens in Ansible Vault instead of plaintext playbooks.
  • No logging: Use no_log: true in tasks that handle secrets to prevent them from appearing in Ansible logs.
  • HTTPS everywhere: Always use HTTPS for GitLab API calls to avoid transmitting credentials in plaintext.

内容的提问来源于stack exchange,提问作者Jérôme B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:25:50