Configuration
Mise en place de ssh
Section titled “Mise en place de ssh”Générer les clés ssh sur le poste de travail avec la commande ssh-keygen
Section titled “Générer les clés ssh sur le poste de travail avec la commande ssh-keygen”ssh-keygen
Generating public/private rsa key pair.Enter file in which to save the key (/home/centos/.ssh/id_rsa):Enter passphrase (empty for no passphrase):Enter same passphrase again:Your identification has been saved in /home/centos/.ssh/id_rsa. Your public key has been saved in /home/centos/.ssh/id_rsa.pub. The key fingerprint is: SHA256:nSzbcedztAFuuh83IyyAgHmjE+2U+9AbXX73izyuObg centos@poste1 The key's randomart image is:+---[RSA 2048]----+||| +. || +B .. || * = ooo.. . || o + +So=..+.o.|| . o o+.o=o..+|Pousser les clés ssh sur les 3 hosts avec la commande ssh-copy-id
Section titled “Pousser les clés ssh sur les 3 hosts avec la commande ssh-copy-id”for host in host11 host12 host13dossh-copy-id $hostdoneVérifier que les connexions sur les 3 hosts s’effectuent sans mot de passe
Section titled “Vérifier que les connexions sur les 3 hosts s’effectuent sans mot de passe”ssh host11Vérifier sur les 3 hosts que le compte centos fait partie des sudoers
Section titled “Vérifier sur les 3 hosts que le compte centos fait partie des sudoers”sudo cat /etc/sudoers.d/sadmin
sadmin ALL=(ALL)NOPASSWD: ALLConfiguration Ansible
Section titled “Configuration Ansible”Créer un fichier inventaire avec les 3 hosts
Section titled “Créer un fichier inventaire avec les 3 hosts”vi inventory
host11host12host13Vérifier si Ansible fonctionne en utilisant le module ping
Section titled “Vérifier si Ansible fonctionne en utilisant le module ping”ansible all -m ping -i inventory
host11 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "ping": "pong"}host12 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "ping": "pong"}host13 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "ping": "pong"}Utiliser un agent ssh
Section titled “Utiliser un agent ssh”eval $(ssh-agent)ssh-add .ssh/id_rsa