{"id":42640,"date":"2023-11-13T12:45:16","date_gmt":"2023-03-07T12:23:22","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/"},"modified":"2024-05-04T08:49:45","modified_gmt":"2024-05-04T00:49:45","slug":"%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/","title":{"rendered":"\u6211\u8bd5\u7528\u4e86Ansible"},"content":{"rendered":"<h1>\u9996\u5148<\/h1>\n<p>\u4e3a\u4e86\u5b66\u4e60\u81ea\u52a8\u5316\u57fa\u7840\u8bbe\u65bd\u7ba1\u7406\u548cDevOps\uff0c\u6211\u51b3\u5b9a\u5b66\u4e60Ansible\u3002<br \/>\n\u867d\u7136\u5f00\u6e90\u8f6f\u4ef6\u7684\u5b89\u88c5\u6b65\u9aa4\u56e0\u7248\u672c\u4e0d\u540c\u800c\u6709\u6240\u5dee\u5f02\uff0c\u4f46\u6211\u89c9\u5f97\u73b0\u5728\u662f\u65f6\u5019\u5b66\u4e60\u4e00\u79cd&#8221;\u8f7b\u677e\u90e8\u7f72&#8221;\u73af\u5883\u7684\u65b9\u6cd5\u4e86\u3002<\/p>\n<h1>\u7248\u672c\u4fe1\u606f<\/h1>\n<div>\n<div class=\"post-table\">\u30d1\u30c3\u30b1\u30fc\u30b8\u30d0\u30fc\u30b8\u30e7\u30f3CentOS7.6.1810 (Core)Ansible2.9.10<\/div>\n<\/div>\n<h1>\u4e2d\u592e\u63a7\u5236\u8bbe\u5907\u914d\u7f6e\u3001\u534f\u8c03\u548c\u7ba1\u7406\u7684\u5f00\u6e90\u81ea\u52a8\u5316\u5de5\u5177\u3002<\/h1>\n<h2>\u7b80\u8ff0<\/h2>\n<p>\u5728\u7531RedHat\u63d0\u4f9b\u7684\u914d\u7f6e\u7ba1\u7406\u5de5\u5177\u4e2d\uff0c\u901a\u8fc7\u88ab\u79f0\u4e3a\u63a7\u5236\u8282\u70b9\u7684\u7ba1\u7406\u673a\u5668\uff0c\u5411\u76ee\u6807\u8282\u70b9\u63a8\u52a8\u5728playbook\u4e2d\u8bb0\u5f55\u7684\u914d\u7f6e\u66f4\u6539\uff0c\u4ece\u800c\u5b9e\u73b0\u5927\u89c4\u6a21\u670d\u52a1\u5668\u914d\u7f6e\u7ba1\u7406\u7684\u53ef\u80fd\u6027\u3002<\/p>\n<p>\u4e3e\u4e2a\u4f8b\u5b50\uff0c\u53ef\u4ee5\u8f7b\u677e\u5730\u5bf9\u88ab\u5f52\u7c7b\u4e3aWeb\u670d\u52a1\u5668\u7fa4\u7ec4\u7684\u673a\u5668\u5b89\u88c5httpd\u8f6f\u4ef6\u5305\uff0c\u6216\u5bf9\u88ab\u5f52\u7c7b\u4e3a\u6570\u636e\u5e93\u670d\u52a1\u5668\u7fa4\u7ec4\u7684\u673a\u5668\u5b89\u88c5mysql\u8f6f\u4ef6\u5305\uff0c\u4ee5\u4fbf\u5bf9\u591a\u53f0\u670d\u52a1\u5668\u8fdb\u884c\u5404\u79cd\u4e0d\u540c\u7684\u4fee\u6539\u3002<\/p>\n<h1>&#8220;playbook&#8221;\u662f\u4ec0\u4e48\u610f\u601d\uff1f<\/h1>\n<p>Playbook\u662f\u6307Ansible\u8bfb\u53d6\u7684\u4e00\u7ec4\u914d\u7f6e\u6587\u4ef6\uff0c\u7528\u4e8e\u6267\u884c\u4e00\u7cfb\u5217\u64cd\u4f5c\u3002<\/p>\n<h3>Playbook\u6587\u4ef6\u7684\u7ec4\u6210\u548c\u534f\u4f5c\u6982\u8ff0<\/h3>\n<p>playbook\u6587\u4ef6\u5c06\u4e0e\u4ee5\u4e0b\u670d\u52a1\uff08\u5305\uff09\u7684\u89d2\u8272\u914d\u7f6e\u6587\u4ef6\u8fdb\u884c\u534f\u4f5c\u3002<br \/>\n\u203b\u4ee5\u4e0b\u662f\u4e3ahttpd\u8bbe\u7f6e\u800c\u521b\u5efa\u7684playbook\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d4d9e37434c4406cbe238\/12-0.png\" alt=\"image.png\" \/><\/div>\n<h1>\u670d\u52a1\u5668\u914d\u7f6e<\/h1>\n<div>\n<div class=\"post-table\">No.Ansible\u306e\u5f79\u5272\u30db\u30b9\u30c8\u540dIP\u30a2\u30c9\u30ec\u30b9\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3059\u308b\u6a5f\u80fd1\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30ce\u30fc\u30c9ansiblehost10.0.1.111-2\u30bf\u30fc\u30b2\u30c3\u30c8\u30ce\u30fc\u30c9ansibletest110.0.1.112webserver<\/div>\n<\/div>\n<h2>\u6211\u60f3\u5728Playbook\u4e0a\u6267\u884c\u4efb\u52a1\u3002<\/h2>\n<p>\u6574\u7406\u76ee\u6807\u8282\u70b9\u6216\u8005\u60f3\u8981\u5728\u6d4b\u8bd5\u73af\u5883\u4e2d\u6267\u884c\u7684\u4efb\u52a1\u3002<br \/>\n\u203b\u5efa\u8bae\u4f7f\u7528\u865a\u62df\u5316\u57fa\u7840\u8bbe\u65bd\u7684\u5feb\u7167\u529f\u80fd\u7b49\uff0c\u5728\u6267\u884c\u6b65\u9aa4\u4e4b\u524d\u5c06\u72b6\u6001\u8fd8\u539f\uff0c\u4ee5\u4fbf\u66f4\u5bb9\u6613\u8fdb\u884c\u786e\u8ba4\u3002<\/p>\n<p>\u5728\u8fd9\u4e2a\u73af\u5883\u4e2d\uff0c\u9700\u8981\u5c06\u4ee5\u4e0b\u4efb\u52a1\u4ece\u63a7\u5236\u8282\u70b9\u5206\u53d1\u5230\u76ee\u6807\u8282\u70b9\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">selinux\u306e\u7121\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">apache(httpd)\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3068\u30b5\u30fc\u30d3\u30b9\u306e\u6709\u52b9\u5316(\u958b\u59cb)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Firewalld\u306bhttp\u901a\u4fe1\u8a31\u53ef\u30dd\u30ea\u30b7\u30fc\u306e\u8ffd\u52a0<\/ul>\n<h1>\u64cd\u4f5c\u6b65\u9aa4<\/h1>\n<h2>1. \u51c6\u5907\u597d<\/h2>\n<h3>\u5728\u63a7\u5236\u8282\u70b9\u4e0a\u5b89\u88c5Ansible\u3002<\/h3>\n<p>\u6839\u636e\u636e\u8bf4\u53ef\u4ee5\u4eceepel-relase\u4ed3\u5e93\u83b7\u53d6\u8f6f\u4ef6\u5305\u5e76\u8fdb\u884c\u5b89\u88c5\u914d\u7f6e\uff0c\u6211\u5c06\u6309\u7167\u8fd9\u4e00\u70b9\u6765\u5b89\u88c5Ansible\u3002<\/p>\n<h4>\u5b89\u88c51.1.1.epel-release\u8f6f\u4ef6\u4ed3\u5e93\u3002<\/h4>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> yum <span class=\"nb\">install<\/span> <span class=\"nt\">-y<\/span> epel-release\r\n<\/code><\/pre>\n<h4>1.1.2 \u5b89\u88c5 Ansible<\/h4>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> yum <span class=\"nb\">install<\/span> <span class=\"nt\">-y<\/span> ansible\r\n<\/code><\/pre>\n<h4>1.1.3.\u68c0\u67e5Ansible\u662f\u5426\u5df2\u5b89\u88c5<\/h4>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> ansible <span class=\"nt\">--version<\/span>\r\n<span class=\"go\">ansible 2.9.10\r\n  config file = \/etc\/ansible\/ansible.cfg\r\n  configured module search path = [u'\/root\/.ansible\/plugins\/modules', u'\/usr\/share\/ansible\/plugins\/modules']\r\n  ansible python module location = \/usr\/lib\/python2.7\/site-packages\/ansible\r\n  executable location = \/bin\/ansible\r\n  python version = 2.7.5 (default, Oct 30 2018, 23:45:53) [GCC 4.8.5 20158623 (Red Hat 4.0.5-36)]\r\n<\/span><\/code><\/pre>\n<h3>\u5728\u63a7\u5236\u8282\u70b9\u4e0a\u751f\u6210\u52a0\u5bc6\u5bc6\u94a5\u5e76\u5206\u53d1\u7ed9\u76ee\u6807\u8282\u70b9\u3002<\/h3>\n<p>\u4e3a\u4e86\u5728\u63a7\u5236\u8282\u70b9\u548c\u76ee\u6807\u8282\u70b9\u4e4b\u95f4\u65e0\u9700\u5bc6\u7801\u767b\u5f55\uff0c\u9700\u8981\u5c06\u516c\u94a5\u590d\u5236\u5230\u76ee\u6807\u8282\u70b9\u4e0a\u3002<\/p>\n<h4>\u521b\u9020\u4e00\u4e2a\u5bc6\u7801\u952e<\/h4>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> ssh-keygen\r\n<span class=\"go\">Generating public\/private rsa pair.\r\nEnter file in which to save the key (\/root\/.ssh\/id_rsa): [\u4f55\u3082\u5165\u529b\u305b\u305a\u306bEnter\u30ad\u30fc\u3092\u62bc\u4e0b]\r\nCreated directory '\/root\/.ssh'.\r\nEnter passphrase (empty for no passphrase): [\u4f55\u3082\u5165\u529b\u305b\u305a\u306bEnter\u30ad\u30fc\u3092\u62bc\u4e0b]\r\nEnser same passphrase again: [\u4f55\u3082\u5165\u529b\u305b\u305a\u306bEnter\u30ad\u30fc\u3092\u62bc\u4e0b]\r\nYour identification has been saved in \/root\/.ssh\/id_rsa.\r\nYour public key has been saved in \/root\/.ssh\/id_rsa.pub\/\r\nThe key fingerprint is:\r\nSHA256:FXXPAU665kgaxMSrf2cogEke5j0hdVGdXWW617s8huM rootpansiblehost\r\n+---[RSA 2040]---+\r\n|     .00.0.+o+o+|\r\n|   . .p. .. .. o|\r\n|  = ... .  .  ..|\r\n| = * o.S. p  ...|\r\n|     +. ...  .. |\r\n|       o o .Eoo.|\r\n+----[SHA256]----+\r\n<\/span><\/code><\/pre>\n<h4>\u5c061.2.2.\u7684\u52a0\u5bc6\u5bc6\u94a5\u5206\u53d1\u7ed9\u76ee\u6807\u8282\u70b9\u3002<\/h4>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> <span class=\"nb\">cd<\/span> \/root\/.ssh\r\n<span class=\"gp\">[root@ansiblehost]#<\/span> cp-p id_rsa.pub authorized_keys\r\n<span class=\"gp\">[root@ansiblehost]#<\/span> <span class=\"nb\">cd<\/span> \/root\r\n<span class=\"gp\">[root@ansiblehost]#<\/span> scp <span class=\"nt\">-pr<\/span> .ssh root@10.0.1.112:~\/\r\n<\/code><\/pre>\n<h4>\u5728\u4e2d\u56fd\u662f\u4ee5\u4e2d\u6587\u4e3a\u6bcd\u8bed\u7684\u60c5\u51b5\u4e0b\uff0c\u5c06\u4ee5\u4e0b\u5185\u5bb9\u8fdb\u884c\u6539\u5199\uff1a<br \/>\n1.\u767b\u5f55\u5230\u76ee\u6807\u8282\u70b9\u7684ssh\u3002<\/h4>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> ssh root@10.0.1.112\r\n<span class=\"go\">Last login: Fri Sep 11 16:52:42 2020 from 10.0.1.111\r\n<\/span><span class=\"gp\">[root@ansibletest1]#<\/span>\r\n<\/code><\/pre>\n<h2>2. Ansobile\u901a\u4fe1\u786e\u8ba4<\/h2>\n<h3>2.1. \u5c06\u540d\u79f0\u89e3\u6790\u8bbe\u7f6e\u914d\u7f6e\u5230hosts\u6587\u4ef6\u4e2d<\/h3>\n<pre class=\"post-pre\"><code>\r\n<span class=\"m\">127<\/span>.<span class=\"m\">0<\/span>.<span class=\"m\">0<\/span>.<span class=\"m\">1<\/span>   <span class=\"n\">localhost<\/span> <span class=\"n\">localhost<\/span>.<span class=\"n\">localdomain<\/span> <span class=\"n\">localhost4<\/span> <span class=\"n\">localhost4<\/span>.<span class=\"n\">localdomain4<\/span>\r\n::<span class=\"m\">1<\/span>         <span class=\"n\">localhost<\/span> <span class=\"n\">localhost<\/span>.<span class=\"n\">localdomain<\/span> <span class=\"n\">localhost6<\/span> <span class=\"n\">localhost6<\/span>.<span class=\"n\">localdomain6<\/span>\r\n\r\n<span class=\"m\">10<\/span>.<span class=\"m\">0<\/span>.<span class=\"m\">1<\/span>.<span class=\"m\">112<\/span> <span class=\"n\">ansibletest1<\/span> <span class=\"n\">ansibletest1<\/span>.<span class=\"n\">dev<\/span>.<span class=\"n\">local<\/span>\r\n<\/code><\/pre>\n<h3>2.2. \u521b\u5efa\u6e05\u5355\u6587\u4ef6<\/h3>\n<pre class=\"post-pre\"><code><span class=\"c\"># This is the default ansible 'hosts' file.\r\n#\r\n# It should live in \/etc\/ansible\/hosts\r\n#\r\n#   - Comments begin with the '#' character\r\n#   - Blank lines are ignored\r\n#   - Groups of hosts are delimited by [header] elements\r\n#   - You can enter hostnames or ip addresses\r\n#   - A hostname\/ip can be a member of multiple groups\r\n<\/span>\r\n<span class=\"c\"># Ex 1: Ungrouped hosts, specify before any group headers.\r\n<\/span>\r\n<span class=\"c\">## green.example.com\r\n## blue.example.com\r\n## 192.168.100.1\r\n## 192.168.100.10\r\n<\/span>\r\n<span class=\"c\"># Ex 2: A collection of hosts belonging to the 'webservers' group\r\n<\/span>\r\n<span class=\"c\">## [webservers]\r\n## alpha.example.org\r\n## beta.example.org\r\n## 192.168.1.100\r\n## 192.168.1.110\r\n<\/span>\r\n<span class=\"c\"># If you have multiple hosts following a pattern you can specify\r\n# them like this:\r\n<\/span>\r\n<span class=\"c\">## www[001:006].example.com\r\n<\/span>\r\n<span class=\"c\"># Ex 3: A collection of database servers in the 'dbservers' group\r\n<\/span>\r\n<span class=\"c\">## [dbservers]\r\n##\r\n## db01.intranet.mydomain.net\r\n## db02.intranet.mydomain.net\r\n## 10.25.1.56\r\n## 10.25.1.57\r\n<\/span>\r\n<span class=\"c\"># Here's another example of host ranges, this time there are no\r\n# leading 0s:\r\n<\/span>\r\n<span class=\"c\">## db-[99:101]-node.example.com\r\n<\/span>\r\n[<span class=\"n\">test<\/span>]\r\n<span class=\"n\">ansibletest1<\/span>\r\n<\/code><\/pre>\n<h3>\u7528Ansible\u547d\u4ee4\u8fdb\u884c\u8fde\u63a5\u6d4b\u8bd5\u3002<\/h3>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> ansible all <span class=\"nt\">-m<\/span> ping\r\n<span class=\"gp\">ansibletest1 | SUCCESS =&gt;<\/span> <span class=\"o\">[<\/span>\r\n<span class=\"go\">  \"ansible_facts\": [\r\n    \"discovered_interpreter_python\": \"\/usr\/bin\/python\"\r\n  ]\r\n  \"changed\": false,\r\n  \"ping\": \"pong\"\r\n]\r\n<\/span><\/code><\/pre>\n<p>\u5982\u679c\u663e\u793a\u51fa\u4ee5\u4e0b\u7ed3\u679c\uff0c\u5219\u8868\u793a\u65e0\u6cd5\u89e3\u6790\u540d\u79f0\u6216\u8005hosts\u4e2d\u7684\u5185\u5bb9\u6709\u8bef\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"gp\">ansibetest1.dev.local | UNREACHABLE! =&gt;<\/span> <span class=\"o\">{<\/span>\r\n<span class=\"go\">    \"changed\": false,\r\n    \"msg\": \"Failed to connect to the host via ssh: ssh: Could not resolve hostname ansibetest1.dev.local: Name or service not known\",\r\n    \"unreachable\": true\r\n}\r\n<\/span><\/code><\/pre>\n<h2>\u521b\u5efa\u4e00\u4e2aplaybook<\/h2>\n<p>\u5728Ansible\u63a7\u5236\u8282\u70b9\u4e0a\u8fdb\u884cplaybook\u521b\u5efa\u3002<\/p>\n<h3>\u8fdb\u5165\u7ba1\u7406playbook\u7684\u6587\u4ef6\u5939<\/h3>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> <span class=\"nb\">cd<\/span> \/etc\/ansible\/roles\r\n<span class=\"go\">SSH password: **********\r\n<\/span><\/code><\/pre>\n<h3>\u521b\u5efa\u4e00\u4e2aSELinux\u4efb\u52a1 4.2.<\/h3>\n<h4>\u521b\u5efa\u7ba1\u7406selinux\u4efb\u52a1\u7684\u76ee\u5f55\uff08\u8bd1\u6587\u53ef\u80fd\u6709\u591a\u79cd\u65b9\u5f0f\uff0c\u8bf7\u9009\u62e9\u4e00\u4e2a\uff09\uff1a4.2.1. \u521b\u5efa\u7528\u4e8e\u7ba1\u7406selinux\u4efb\u52a1\u7684\u76ee\u5f55\u3002<\/h4>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d4d9e37434c4406cbe238\/52-0.png\" alt=\"image.png\" \/><\/div>\n<h4>\u7f16\u8f914.2.2.\u4efb\u52a1\u76f8\u5173\u6587\u4ef6\u3002<\/h4>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">disable_selinux<\/span>\r\n  <span class=\"na\">selinux<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">state<\/span><span class=\"pi\">:<\/span> <span class=\"s\">disable<\/span>\r\n    <span class=\"na\">policy<\/span><span class=\"pi\">:<\/span> <span class=\"s\">targeted<\/span>\r\n  <span class=\"na\">notify<\/span><span class=\"pi\">:<\/span> <span class=\"s\">reboot<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">import_tasks<\/span><span class=\"pi\">:<\/span> <span class=\"s\">selinux.yml<\/span>\r\n<\/code><\/pre>\n<h4>\u7f16\u8f914.2.3\u4e2d\u7684\u5904\u7406\u5668\u76f8\u5173\u6587\u4ef6\u3002<\/h4>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">reboot<\/span>\r\n  <span class=\"na\">reboot<\/span><span class=\"pi\">:<\/span>\r\n<\/code><\/pre>\n<h2>\u521b\u5efa\u4e00\u4e2a4.3.httpd\u4efb\u52a1\u3002<\/h2>\n<h4>\u521b\u5efa\u4e00\u4e2a\u7ba1\u74064.3.1.httpd\u4efb\u52a1\u7684\u76ee\u5f55\u3002<\/h4>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d4d9e37434c4406cbe238\/60-0.png\" alt=\"image.png\" \/><\/div>\n<h4>\u7f16\u8f91\u4e0e\u4efb\u52a1\u76f8\u5173\u7684\u6587\u4ef6<\/h4>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">install_httpd_by_yum<\/span>\r\n  <span class=\"na\">yum<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">httpd<\/span>\r\n    <span class=\"na\">state<\/span><span class=\"pi\">:<\/span> <span class=\"s\">present<\/span>\r\n  <span class=\"na\">notify<\/span><span class=\"pi\">:<\/span> <span class=\"s\">enable<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">import_tasks<\/span><span class=\"pi\">:<\/span> <span class=\"s\">install.yml<\/span>\r\n<\/code><\/pre>\n<h4>4.3.3. \u7f16\u8f91\u5904\u7406\u7a0b\u5e8f\u76f8\u5173\u6587\u4ef6<\/h4>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">enable<\/span>\r\n  <span class=\"na\">systemd<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">httpd.service<\/span>\r\n    <span class=\"na\">state<\/span><span class=\"pi\">:<\/span> <span class=\"s\">started<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"s\">yes<\/span>\r\n<\/code><\/pre>\n<h2>\u521b\u5efa 4.4. firewalld \u4efb\u52a1<\/h2>\n<h4>\u521b\u5efa\u4e00\u4e2a\u7ba1\u7406firewalld\u4efb\u52a1\u7684\u76ee\u5f55<\/h4>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d4d9e37434c4406cbe238\/68-0.png\" alt=\"image.png\" \/><\/div>\n<h4>\u7f16\u8f91\u4e0e\u4efb\u52a1\u76f8\u5173\u7684\u6587\u4ef6\u3002<\/h4>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">add_http_rule<\/span>\r\n  <span class=\"na\">firewalld<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">service<\/span><span class=\"pi\">:<\/span> <span class=\"s\">http<\/span>\r\n    <span class=\"na\">zone<\/span><span class=\"pi\">:<\/span> <span class=\"s\">public<\/span>\r\n    <span class=\"na\">permanent<\/span><span class=\"pi\">:<\/span> <span class=\"s\">yes<\/span>\r\n    <span class=\"na\">state<\/span><span class=\"pi\">:<\/span> <span class=\"s\">enabled<\/span>\r\n  <span class=\"na\">notify<\/span><span class=\"pi\">:<\/span> <span class=\"s\">reload<\/span>\r\n\r\n<span class=\"pi\">-<\/span> <span class=\"na\">meta<\/span><span class=\"pi\">:<\/span> <span class=\"s\">flush_handlers<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">import_tasks<\/span><span class=\"pi\">:<\/span> <span class=\"s\">allowhttpd.yml<\/span>\r\n<\/code><\/pre>\n<h4>\u7f16\u8f914.4.3.\u5904\u7406\u7a0b\u5e8f\u76f8\u5173\u6587\u4ef6<\/h4>\n<pre class=\"post-pre\"><code><span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">reload<\/span>\r\n  <span class=\"na\">service<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">firewalld<\/span>\r\n    <span class=\"na\">state<\/span><span class=\"pi\">:<\/span> <span class=\"s\">reloaded<\/span>\r\n<\/code><\/pre>\n<h2>\u7f16\u8f914.5.playbook\u6587\u4ef6\u3002<\/h2>\n<pre class=\"post-pre\"><code><span class=\"nn\">---<\/span>\r\n<span class=\"pi\">-<\/span> <span class=\"na\">hosts<\/span><span class=\"pi\">:<\/span> <span class=\"s\">all<\/span>\r\n  <span class=\"na\">gather_facts<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n  <span class=\"na\">remote_user<\/span><span class=\"pi\">:<\/span> <span class=\"s\">root<\/span>\r\n  <span class=\"na\">roles<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">httpd<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">firewalld<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">selinux<\/span>\r\n<\/code><\/pre>\n<h2>5. \u8fd0\u884cplaybook<\/h2>\n<pre class=\"post-pre\"><code><span class=\"gp\">[root@ansiblehost]#<\/span> <span class=\"nb\">cd<\/span> \/etc\/ansible\r\n<span class=\"gp\">[root@ansiblehost]#<\/span> ansible-playbook webserver.yml <span class=\"nt\">-i<\/span> hosts <span class=\"nt\">-k<\/span>\r\n<span class=\"go\">SSH password: *******\r\n\r\nPLAY [all] ********************************************************************************************************************\r\n\r\nTASK [install_httpd_by_yum] ***************************************************************************************************\r\nchange: [ansibletest1]\r\n\r\nTASK [firewalld: add_httpd_rules] *********************************************************************************************\r\nchange: [ansibletest1]\r\n\r\nRUNNING HANDLER [httpd: enable] ***************************************************************************************************\r\nchange: [ansibletest1]\r\n\r\nRUNNING HANDLER [firewalld: reload] ***************************************************************************************************\r\nchange: [ansibletest1]\r\n\r\nTASK [disable_selinux] ********************************************************************************************************\r\n[WARNING]: SELinux state temporarily changed from 'enforcing' to 'permissive'. State change will take effect next reboot.\r\nchanged: [ansibletest1]\r\n\r\nRUNNING HANDLER [selinux : reboot] ********************************************************************************************\r\nchanged: [ansibletest1]\r\n\r\nPLAY RECAP ********************************************************************************************************************\r\nansibletest1              : ok=6   changed=6    unreachable=0    failed=0    skipped=0     rescued=0    ignored=0\r\n<\/span><\/code><\/pre>\n<h3>\u5982\u679c\u51fa\u73b0\u9519\u8bef\u7684\u60c5\u51b5\u4e0b<\/h3>\n<p>\u5728\u6700\u521d\u7684\u6d4b\u8bd5\u4e2d\uff0c\u6211\u9519\u8bef\u5730\u66f4\u6539\u4e86selinux\u7684\u914d\u7f6e\u6b65\u9aa4\u3002\u6b64\u65f6\u663e\u793a\u7684\u9519\u8bef\u5982\u4e0b\u6240\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"gp\">fatal: [ansibletest1]:FAILED! =&gt;<\/span> <span class=\"o\">[<\/span><span class=\"s2\">\"changed\"<\/span>: <span class=\"nb\">false<\/span>, <span class=\"s2\">\"msg\"<\/span>: <span class=\"s2\">\"value of state must be one of: enforcing, permissive, disabled. go\r\n<\/span><span class=\"go\">t: disable\"]\r\n<\/span><\/code><\/pre>\n<h1>\u5982\u679c\u8981\u91cd\u65b0\u5efa\u7acb\u76ee\u6807\u670d\u52a1\u5668\u7684\u8bdd<\/h1>\n<p>\u5982\u679c\u91cd\u65b0\u5efa\u7acb\u76ee\u6807\u670d\u52a1\u5668\uff0c\u9700\u8981\u5728\u63a7\u5236\u670d\u52a1\u5668\u4e0a\u5220\u9664.ssh\/hosts\u4e2d\u8bb0\u5f55\u7684\u76ee\u6807\u670d\u52a1\u5668\u7684ssh\u4fe1\u606f\u3002<\/p>\n<h1>ansible-playbook \u547d\u4ee4\u683c\u5f0f<\/h1>\n<pre class=\"post-pre\"><code>ansible-playbook {playbook file} -i {inventory file} -l {host group} -k\r\n<\/code><\/pre>\n<div>\n<div class=\"post-table\">\u30aa\u30d7\u30b7\u30e7\u30f3\u8aac\u660e-ispecify inventory host path or comma separated host list.-kask for connection password-lfurther limit selected hosts to an additional pattern<\/div>\n<\/div>\n<h1>\u53ef\u4ee5\u53c2\u8003<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Ansible\u5165\u9580\u8005\u5411\u3051\u5b66\u7fd2\u30ac\u30a4\u30c9(CentOS\u7de8) http:\/\/c.itdo.jp\/technical-information\/ansible\/ansible-tutorial\/#back3<\/ul>\n<\/li>\n<\/ul>\n<p>5\u5206\u3067SSH\u306e\u516c\u958b\u9375\u8a8d\u8a3c\u3092\u6709\u52b9\u5316\u3059\u308b\u65b9\u6cd5\u3010\u30d5\u30a1\u30a4\u30eb\u8ee2\u9001\u30bd\u30d5\u30c8\u4e0d\u8981\u3011 https:\/\/hackers-high.com\/linux\/easy-ssh-publickey-authentication\/<\/p>\n<p>\u30a4\u30f3\u30d9\u30f3\u30c8\u30ea\u30fc\u306e\u69cb\u7bc9\u65b9\u6cd5 https:\/\/docs.ansible.com\/ansible\/2.9_ja\/user_guide\/intro_inventory.html<\/p>\n<p>Ansible\u30b3\u30de\u30f3\u30c9\u3067PING\u758e\u901a\u3059\u308b https:\/\/docs.ansible.com\/ansible\/2.9_ja\/\/user_guide\/intro_getting_started.html<\/p>\n<p>systemd\u30e2\u30b8\u30e5\u30fc\u30eb https:\/\/docs.ansible.com\/ansible\/latest\/modules\/systemd_module.html#systemd-module<\/p>\n<p>handlers\u3068notify\u306e\u95a2\u4fc2\u306b\u3064\u3044\u3066 https:\/\/blog.amedama.jp\/entry\/2015\/09\/01\/214912<\/p>\n<p>playbook\u5b9f\u884c\u6642\u306b\u30db\u30b9\u30c8\u30b0\u30eb\u30fc\u30d7\u3092\u6307\u5b9a https:\/\/tech.withsin.net\/2017\/07\/19\/ansible-playbook-l\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u4e3a\u4e86\u5b66\u4e60\u81ea\u52a8\u5316\u57fa\u7840\u8bbe\u65bd\u7ba1\u7406\u548cDevOps\uff0c\u6211\u51b3\u5b9a\u5b66\u4e60Ansible\u3002 \u867d\u7136\u5f00\u6e90\u8f6f\u4ef6\u7684\u5b89\u88c5\u6b65\u9aa4\u56e0\u7248\u672c\u4e0d\u540c\u800c [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-42640","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u6211\u8bd5\u7528\u4e86Ansible - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u8bd5\u7528\u4e86ansible\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u6211\u8bd5\u7528\u4e86Ansible\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u4e3a\u4e86\u5b66\u4e60\u81ea\u52a8\u5316\u57fa\u7840\u8bbe\u65bd\u7ba1\u7406\u548cDevOps\uff0c\u6211\u51b3\u5b9a\u5b66\u4e60Ansible\u3002 \u867d\u7136\u5f00\u6e90\u8f6f\u4ef6\u7684\u5b89\u88c5\u6b65\u9aa4\u56e0\u7248\u672c\u4e0d\u540c\u800c [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u8bd5\u7528\u4e86ansible\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-07T12:23:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-04T00:49:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d4d9e37434c4406cbe238\/12-0.png\" \/>\n<meta name=\"author\" content=\"\u79d1, \u96c5\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u79d1, \u96c5\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/\",\"name\":\"\u6211\u8bd5\u7528\u4e86Ansible - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-03-07T12:23:22+00:00\",\"dateModified\":\"2024-05-04T00:49:45+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u6211\u8bd5\u7528\u4e86Ansible\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a\",\"name\":\"\u79d1, \u96c5\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g\",\"caption\":\"\u79d1, \u96c5\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/keya\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u6211\u8bd5\u7528\u4e86Ansible - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u8bd5\u7528\u4e86ansible\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u6211\u8bd5\u7528\u4e86Ansible","og_description":"\u9996\u5148 \u4e3a\u4e86\u5b66\u4e60\u81ea\u52a8\u5316\u57fa\u7840\u8bbe\u65bd\u7ba1\u7406\u548cDevOps\uff0c\u6211\u51b3\u5b9a\u5b66\u4e60Ansible\u3002 \u867d\u7136\u5f00\u6e90\u8f6f\u4ef6\u7684\u5b89\u88c5\u6b65\u9aa4\u56e0\u7248\u672c\u4e0d\u540c\u800c [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u8bd5\u7528\u4e86ansible\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-03-07T12:23:22+00:00","article_modified_time":"2024-05-04T00:49:45+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d4d9e37434c4406cbe238\/12-0.png"}],"author":"\u79d1, \u96c5","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u79d1, \u96c5","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"4 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/","name":"\u6211\u8bd5\u7528\u4e86Ansible - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-03-07T12:23:22+00:00","dateModified":"2024-05-04T00:49:45+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u6211\u8bd5\u7528\u4e86Ansible"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a","name":"\u79d1, \u96c5","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g","caption":"\u79d1, \u96c5"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/keya\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e8%af%95%e7%94%a8%e4%ba%86ansible%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/42640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=42640"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/42640\/revisions"}],"predecessor-version":[{"id":97328,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/42640\/revisions\/97328"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=42640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=42640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=42640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}