如何通过编程方式获取GitLab密钥哈希?Ansible部署GitLab密钥获取咨询
Great question—automating these token/secret retrievals is critical for building a fully hands-off GitLab deployment with Ansible. Let’s break down safe, programmatic methods for both GitLab Runner and Mattermost, no manual UI clicks required.
You’ve got two reliable options here, depending on whether you prefer using the GitLab API or the Omnibus-built Rails console:
方法1:GitLab API(实例级令牌)
If you’re targeting the instance-wide runner registration token, the API endpoint is straightforward—you might have overlooked it! You’ll need an admin-level personal access token (PAT) with the admin_runner scope.
The API call looks like this:
curl --header "PRIVATE-TOKEN: YOUR_ADMIN_PAT" "https://your-gitlab-instance/api/v4/runners/registration_token"
In Ansible, you can use the uri module to fetch this:
- name: Fetch instance-level GitLab Runner registration token uri: url: "{{ gitlab_base_url }}/api/v4/runners/registration_token" headers: PRIVATE-TOKEN: "{{ gitlab_admin_pat }}" method: GET return_content: true validate_certs: true register: runner_reg_token no_log: true # Keep the token out of logs!
For group or project-specific tokens, use the respective API endpoints:
- Group:
GET /api/v4/groups/:id/runners/registration_token - Project:
GET /api/v4/projects/:id/runners/registration_token
方法2:GitLab Rails Console(Omnibus专属)
Since you’re using the Omnibus package, you can run a Rails console command directly on the server to pull the token without API calls. This requires root access:
- name: Retrieve Runner registration token via Rails console command: gitlab-rails runner "puts Gitlab::CurrentSettings.current_application_settings.runners_registration_token" register: runner_reg_token become: true no_log: true
Mattermost integrates with GitLab via an OAuth application—Omnibus typically creates this automatically during installation. You can fetch its credentials via either the Rails console or GitLab API:
方法1:GitLab Rails Console
Run this command to locate the Mattermost OAuth application and output its ID and secret:
- name: Get Mattermost OAuth credentials from Rails console command: > gitlab-rails runner " app = Doorkeeper::Application.find_by(name: 'Mattermost'); puts \"#{app.id},#{app.secret}\" " register: mattermost_creds become: true no_log: true changed_when: false - name: Parse Mattermost credentials into variables set_fact: mattermost_app_id: "{{ mattermost_creds.stdout.split(',')[0] }}" mattermost_app_secret: "{{ mattermost_creds.stdout.split(',')[1] }}"
方法2:GitLab API
Use the applications endpoint to list all OAuth apps, then filter for the one named "Mattermost". Again, you’ll need an admin PAT with admin_api scope:
- name: Fetch all GitLab OAuth applications uri: url: "{{ gitlab_base_url }}/api/v4/applications" headers: PRIVATE-TOKEN: "{{ gitlab_admin_pat }}" method: GET return_content: true validate_certs: true register: gitlab_apps no_log: true - name: Extract Mattermost application credentials set_fact: mattermost_app: "{{ gitlab_apps.json | selectattr('name', 'equalto', 'Mattermost') | first }}" mattermost_app_id: "{{ (gitlab_apps.json | selectattr('name', 'equalto', 'Mattermost') | first).id }}" mattermost_app_secret: "{{ (gitlab_apps.json | selectattr('name', 'equalto', 'Mattermost') | first).secret }}"
- Minimize PAT scopes: Only grant the necessary permissions (e.g.,
admin_runnerfor tokens,admin_apifor apps) instead of full admin access. - Encrypt sensitive data: Store your admin PAT and retrieved tokens in Ansible Vault instead of plaintext playbooks.
- No logging: Use
no_log: truein tasks that handle secrets to prevent them from appearing in Ansible logs. - HTTPS everywhere: Always use HTTPS for GitLab API calls to avoid transmitting credentials in plaintext.
内容的提问来源于stack exchange,提问作者Jérôme B

