1. CentOS6.x x64 服务器端安装

# rpm -ivh http://download.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm    
# yum -y install ansible


配置文件查看:

[root@master ansible]# egrep -v "(#|^$)" /etc/ansible/ansible.cfg    
[defaults]    
hostfile       = /etc/ansible/hosts 
library        = /usr/share/ansible    
remote_tmp     = $HOME/.ansible/tmp    
pattern        = *    
forks          = 5   #默认并发5个。    
poll_interval  = 15    
sudo_user      = root    
transport      = smart    
remote_port    = 22    
module_lang    = C    
gathering = implicit    
sudo_exe = sudo    
timeout = 10    
ansible_managed = Ansible managed: {file} modified on %Y-%m-%d %H:%M:%S by {uid} on {host}    
action_plugins     = /usr/share/ansible_plugins/action_plugins    
callback_plugins   = /usr/share/ansible_plugins/callback_plugins    
connection_plugins = /usr/share/ansible_plugins/connection_plugins    
lookup_plugins     = /usr/share/ansible_plugins/lookup_plugins    
vars_plugins       = /usr/share/ansible_plugins/vars_plugins    
filter_plugins     = /usr/share/ansible_plugins/filter_plugins    
[paramiko_connection]    
[ssh_connection]    
[accelerate]    
accelerate_port = 5099    
accelerate_timeout = 30    
accelerate_connect_timeout = 5.0    
accelerate_daemon_timeout = 30


2. 配置主机Inventory

ansible通过读取默认的主机清单文件/etc/ansible/hosts,该文件在/etc/ansible/ansible.cfg文件中指定,可以自定义主机,支持IP,域名,支持分组,便于对某

些主机或者某一组功能相同的主机进行操作,还有一个缺省的all组,代表Inventory中所有主机。

# vi /etc/ansible/hosts

[test]  
192.168.10.191    
192.168.10.192

示例:可以指定端口与用户与密码:  
192.168.10.191   ansible_ssh_port=2222  ansible_ssh_user=root ansible_ssh_pass=passwd    
192.168.10.191:2222

 

3. 免密钥方式配置

置ansible端能基于密钥认证的方式联系各被管理节点。master服务器生成ssh-key,并分发到所有客户端。

# ssh-keygen -t rsa    
# ssh-copy-id -i ~/.ssh/id_rsa.pub [email protected]    
 
在此过程提示输入客户端密码


4. RHEL/CentOS/OEL5.X 客户端安装

RHEL/CentOS/OEL5.X x64 默认采用 python2.4,ansible对python2.4需要安装python-simplejson安装包。

说明: python2.4/2.5版本太低会出现"msg": "Error: ansible requires a json module, none found!", 报错.  
要么升级python,要么安装python-simplejson

[root@web01 Server]# rpm -vih python-simplejson-2.0.9-8.el5.x86_64.rpm    
warning: python-simplejson-2.0.9-8.el5.x86_64.rpm: Header V3 DSA signature: NOKEY, key ID 1e5e0159    
Preparing...                ########################################### [100%]    
   1:python-simplejson      ########################################### [100%]

 

5. ansible命令模块以及参数查询

(1) ansible命令语法

语法 ansible [options]  
ansible -m -a

选项:  
-i 设备列表路径,可制定一些动态路径    
-f 并行任务数    
-private-key 私钥路径    
-m 模块名 默认不指定模块就是采用command模块    
-M 模块夹在路径    
-a 参数    
-k 登陆密码    
-K sudo密码    
-t 输出结果保存路径    
-B 后台运行超时时间    
-P 调查后台程序时间    
-u 执行用户    
-U sudo用户    
-l 限制设备范围    
-s 是此用户sudo无需输入密码


(2) 查看ansible的模块以及参数

# ansible-doc

-l 列出所有的ansible模块  
-s 列出该模块的相关指令


[root@master ~]# ansible-doc -l    
            
boundary_meter       Manage boundary meters                                     
bzr                  Deploy software (or files) from bzr branches               
campfire             Send a message to Campfire                                 
capabilities         Manage Linux capabilities                                  
cloudformation       create a AWS CloudFormation stack                          
command              Executes a command on a remote node                        
composer             Dependency Manager for PHP                                 
copy                 Copies files to remote locations.                          
cpanm                Manages Perl library dependencies.                         
cron                 Manage cron.d and crontab entries.                         
datadog_event        Posts events to DataDog  service                           


[root@master ~]# ansible-doc -s command    
- name: E x e c u t e s   a   c o m m a n d   o n   a   r e m o t e   n o d e    
  action: command    
      chdir                  # cd into this directory before running the command    
      creates                # a filename, when it already exists, this step will *not* be run.    
      executable             # change the shell used to execute the command. Should be an absolute path to the executable.    
      free_form=             # the command module takes a free form command to run.  There is no parameter actually named 'free form'. See the

examples!  
      removes                # a filename, when it does not exist, this step will *not* be run.    
      warn                   # if command warnings are on in ansible.cfg, do not warn about this particular line if set to no/false.

 

6. 通过密码方式进行验证,加入-k参数

#提供了三种方式:一个在hosts文件中加入密码,一种是免密钥方式,一种是采用-k方式手动输入密码,常用于临时测试。

[root@master ansible]# ansible all -m ping -k

SSH password:    
192.168.10.192 | success >> {    
    "changed": false,    
    "ping": "pong"    
}

192.168.10.191 | success >> {  
    "changed": false,    
    "ping": "pong"    
}


7. 常用示例:

[root@master ansible]# ansible test -a 'df -h'   #这个省略了-m command模块名,-a接参数,可以指行linux命令

#执行操作系统命令可以采用command,shell,raw等,其中shell可以使用管道以及命令带参,script通常用执行脚本等,具体可以查看相关参数。

192.168.0.125 | success | rc=0 >>  
Filesystem                    Size  Used Avail Use% Mounted on    
/dev/mapper/vg_test2-lv_root   36G  3.6G   30G  11% /    
tmpfs                        1004M   72K 1004M   1% /dev/shm    
/dev/sda1                     485M   39M  421M   9% /boot

192.168.0.124 | success | rc=0 >>  
Filesystem                    Size  Used Avail Use% Mounted on    
/dev/mapper/vg_test1-lv_root   36G  3.6G   30G  11% /    
tmpfs                        1004M   72K 1004M   1% /dev/shm    
/dev/sda1                     485M   39M  421M   9% /boot

单条远程命令的执行,可以通过相关模块进行操作,也可以直接执行命令方式,命令方式将为后面play-book(可以简单理解为批处理)试打下基础。

ansible test -m yum -a "name=dstat state=latest"         #执行yum install dstat  
ansible test -m raw -a "rpm -qa|grep dstat"              #执行rpm -qa |grep dstat    
ansible test -m shell -a "service mysqld restart"        #通过命令方式执行service mysqld restart

单条命令方式:

ansible test -m service -a "name=mysqld state=stopped"   #通过服务模块执行service mysqld stop

play-book方式:

- name: stop mysqld service   #随便取名称  
  service: enabled=off name=rpcbind state=stopped    #模块与参数,单命令行方式也可很容易转成play-book方式。