求助:使用Ansible安装kubelet失败,手动执行yum命令可成功
It’s frustrating when manual commands work but Ansible playbooks don’t—let’s dig into the most likely culprits here and fix your playbook step by step.
1. Ensure YUM Cache is Refreshed After Adding the Kubernetes Repo
When you add a new repo, YUM’s existing cache won’t automatically include the new repo’s metadata. Your current playbook tries to update the cache during the kubelet install step, but this can be unreliable right after adding a repo. Explicitly refresh the cache immediately after adding the repo to guarantee Ansible sees the new kubelet package:
- name: refresh yum cache after adding k8s repo yum: update_cache: yes
2. Manually Import Kubernetes GPG Keys
While your yum_repository task specifies the GPG keys, Ansible doesn’t always import them as reliably as a manual yum install (which prompts you to approve key imports automatically). Add a task to import the keys explicitly before adding the repo:
- name: import kubernetes gpg keys rpm_key: key: "{{ item }}" state: present loop: - "https://packages.cloud.google.com/yum/doc/yum-key.gpg" - "https://packages.cloud.google.com/yum/doc/rpm-package-key.gpg"
3. Check for Network/Proxy Discrepancies
Make sure the nodes Ansible is targeting have the exact same network access as when you ran the manual yum install. If your environment uses a proxy, Ansible might not be passing those settings to the remote nodes. Add proxy environment variables to your playbook if needed:
- hosts: all become: yes environment: http_proxy: "http://your-proxy-server:port" https_proxy: "http://your-proxy-server:port" tasks: # ... rest of your tasks
4. Verify SELinux Settings (Sanity Check)
You ran setenforce 0 temporarily, but let’s make sure SELinux isn’t interfering with repo access in a way the manual install bypassed. Add a task to set SELinux to permissive permanently (this is optional but eliminates SELinux as a variable):
- name: set selinux to permissive permanently lineinfile: path: /etc/selinux/config regexp: '^SELINUX=' line: 'SELINUX=permissive'
Full Modified Playbook
Putting it all together, here’s your updated playbook with these fixes:
--- - hosts: all become: yes tasks: - name: install docker yum: name: docker state: present update_cache: true - name: import kubernetes gpg keys rpm_key: key: "{{ item }}" state: present loop: - "https://packages.cloud.google.com/yum/doc/yum-key.gpg" - "https://packages.cloud.google.com/yum/doc/rpm-package-key.gpg" - name: add kubernetes repo yum_repository: name: kuberepo description: kubernetes-repo baseurl: "https://packages.cloud.google.com/yum/repos/kubernetes-el7-x86_64" enabled: yes gpgcheck: yes repo_gpgcheck: yes - name: refresh yum cache after adding k8s repo yum: update_cache: yes - name: set selinux to permissive temporarily shell: setenforce 0 ignore_errors: yes # Ignore error if SELinux is already disabled - name: set selinux to permissive permanently lineinfile: path: /etc/selinux/config regexp: '^SELINUX=' line: 'SELINUX=permissive' - name: install kubelet yum: name: kubelet state: present
Bonus: Get Detailed Error Logs
If the issue persists, run your playbook with verbose output to get the exact error message (e.g., package not found, key validation failed, network timeout):
ansible-playbook -i hosts kube-dependencies.yml -vvv
This will show you exactly where Ansible is failing, making it easier to narrow down the root cause.
内容的提问来源于stack exchange,提问作者fsakiyama

