顯示具有 ansible 標籤的文章。 顯示所有文章
顯示具有 ansible 標籤的文章。 顯示所有文章

2022年5月4日 星期三

透過ansible 匯出docker MySQL db

要把docker mysql container的資料倒出來

當然可以透過像MySql workbench倒回即可

但目標是透過ansible腳本可以遠端隨時把db dump出來

所以需要的是透過單一指令執行

基本作法是

先進入container

sudo docker exec -it mysql99 bash

再執行mysql dump指令

mysqldump -u root -p mydb > mydb.sql


可以簡化成由docker exec直接執行

sudo docker exec -it mysql99 bash -c 'mysqldump -u root -p mydb > mydb.sql'


但如果要自動化這有一個問題是,每次都需要輸入password

解決方式是 在my.cnf加入設定

[mysqldump]

user=xxx

password=xxx

指令可以再簡化連使用者都不用輸入 

sudo docker exec -it mysql99 bash -c 'mysqldump mydb > mydb.sql'


已經準備好自動化的指令

接下來就可以使用ansible腳本來執行

dump.yml

- name: Dump MySQL db

  hosts: myhost

  tasks:

    - name: Dump MySQL DB -e db要帶匯出的db名稱

      become: true

      shell:

        cmd: "docker exec -it contianerName bash -c 'mysqldump {{db}} > {{db}}_{{ ansible_date_time.date }}.sql'"

      register: output

    - debug:

        var: output

執行

ansible-playbook -i hosts.yml -e db=mydb dump.yml

就會將mydb dump到 mydb_20200501.sql這樣帶有日期的sql檔案

2022年4月6日 星期三

ansible 檢查檔案是否存在

在ansible內需要檢查檔案是否存在

以當作條件決定後續工作是否執行

檢查遠端主機檔案跟執行local端檔案

是有差異的


檢查要控制的遠端主機檔案(被ansible控制的主機)

- name: check the nginx template config exist

  stat:

    path: '{{遠端檔案路徑}}'

  register: stat_result


檢查主控主機上的檔案(也就是執行ansible的主機)

- name: check the nginx template config exist

  delegate_to: localhost

  stat:

    path: '{{本機檔案路徑}}'

  register: stat_result

作檔案檢查要特別注意不要使用become:true

以root權限執行

2022年4月5日 星期二

ansible 以ssh clone bitbucket git repository

以ansible git module 要git clone 一個repository

過去都會以https方式去 直接綁定帳密去clone最為簡單

- name: clone myrepo

  git:

    repo: 'https://{{git_user}}:{{git_password}}@bitbucket.org/myacc/myrepo.git'

    dest: '{{target_path}}'

    version: 'master'

    clone: true

但因為安全性考量bitbucket在2022/3/1後就不支援這樣直接綁帳密方式取得

改用ssh方式取

作業之前需先把要操作的主機的ssh設定到bitbuket的repo設定上

在要操作的主機

1.建立ssh key

  ~/.ssh ssh-keygen

2.複製public key內容

  cat id_rsa.pub

  複製內容

3.到bitbucket repo設定加入access_keys

  bitbuckey/myrepo/access_keys 加入

在ansible host上執行腳本

- name: clone myrepo

  git:

    repo: 'git@bitbucket.org:{{myacc}}/myrepo.git'

    dest: '{{target_path}}'

    version: 'master'

    clone: true

    accept_hostkey: yes

注意這裡多加上了accept_hostkey的設定

2022年4月1日 星期五

ansible 在使用loop或with_items時加入條件when判斷

目前有一個使用情境

在管理多台主機的nginx設定時

要寫一個更新nginx config設定檔的腳本

因為是要套用在多台主機上

因為設定檔 都會以j2樣板方式寫好再套用各主機資料產生config檔案

所以會先準備好多個樣板

ex:

api.conf.j2 設定api相關

web.conf.j2 設定web相關

service.conf.j2 設定其他各式服務

socket.conf.js 設定 socket服務


但也因為各主機屬性不一樣

並不是所有的主機都會同時有這些設定檔案


因此在寫ansible控制腳本時就會需要使用迴圈

判斷如果樣板檔案存在就使用樣板產生設定檔案的功能


- name: check the nginx template config exist
  with_items:
    - src: '../../files/nginx/default.conf.j2'
      dest: '/etc/nginx/sites-available/default.conf'
    - src: '../../files/nginx/conf/web.conf.j2'
      dest: '/etc/nginx/sites-available/conf/web.conf'
    - src: '../../files/nginx/conf/api.conf.j2'
      dest: '/etc/nginx/sites-available/conf/api.conf'
  delegate_to: localhost
  stat:
    path: '{{item.src}}'
  register: stat_result
- name: build the nginx template config
  become: true
  with_items: '{{stat_result.results}}'
  template:
    src: '{{item.item.src}}'
    dest: '{{item.item.dest}}'
  when: item.stat.exists
- name: restart nginx
  service:
    name: nginx
    state: restarted

說明
以兩段工作來執行
第1段是檢查所有檔案是否存在
第2段是以上面檢查的結果判斷是否執行樣板render
第1段以stat來檢查檔案得到的回應stat_result
取得的 stat_result.results 為loop結果
{
  item: 即為with_items的一項,
  stat: {
    exists: true|false 是否存在
  }
}
第2段就可以以stat_result.results當作迴圈的內容
以when判斷是否執行
這樣 就不會因為檔案不存在由造成loop有錯誤

另外當執行loop發生錯誤
loop 內其他的正常項目還是都會作完
但下一段動作會因為錯誤而不執行
如同sample code內 如果loop出錯
那下一個重啟nginx的動作將不會被執行

這裡有一個特別注意的地方是
要檢查本機上的檔案是否存在
需要加上delegate_to: localhost
而且不可以使用root
也就是不可使用become:true

2022年3月16日 星期三

ssh-copy-id ansible使用

在開發ansible佈署功能主要都是透過ssh

ssh連線時如果希望不用每次輸入密碼

要透過ssh-copy-id xxx@192.168.0.99

將本機的public key丟到遠端主機上

這樣之後就直接連線不需要輸入密碼


ex:

以ansible佈署的架構來看

假設區網內的幾台主機功能分別是

1.本機 192.168.0.60

2.控制機 192.168.0.99

3.應用ap 192.168.0.100

如果我們要透過控制機(99)去操作應用ap(100)

則需要在99上把99的public-key丟到100上

  ssh-copy-id user@192.168.0.100

如果ansible(99)要控制的是也是99上的程式

也要copy id給自己

  ssh-copy-id user@192.168.0.99

這樣在client機器上可以透過ssh控制control(99)機器去

代為操作99跟100的服務


2021年12月28日 星期二

ubuntu更新python 並安裝ansible

因為ansible安裝需要將ubuntu上的python更新到3.8以上

如果系統是ubuntu 20 已經是預設安裝python3 

也就是python 3.6.9

不要再安裝2.x的版本會造成問題


1.更新 repository

sudo add-apt-repository ppa:deadsnakes/ppa

sudo apt-get update


2.安裝python

sudo apt-get install python3.8


3.安裝update-alternatives 可以切換python版本

分別把舊的跟新的都設定上去

sudo update-alternatives --install /usr/bin/python3 python3 /usr/bin/python3.6 1

sudo update-alternatives --install /usr/bin/python3 python3 /usr/bin/python3.8 2


4.設定要使用哪個版本

sudo update-alternatives --config python3


5.更新pip3

sudo python3 -m pip install -U pip

sudo python3 -m pip install -U setuptools


6.安裝ansible

pip3 install ansible


7.若需要改alias

改.bashrc 

alias python=python3.8


安裝的流程 參考

https://www.itsupportwale.com/blog/how-to-upgrade-to-python-3-8-on-ubuntu-18-04-lts/

2021年11月29日 星期一

mysqld exporter使用

要監控mysql server狀態

安裝role

ansible-galaxy install cloudalchemy.mysqld_exporter

透過ansible安裝mysqld exporter

playbook.yml

- hosts: all

  become: true

  roles:

    - role: cloudalchemy.mysqld_exporter

      mysqld_exporter_dsn: "user:password@(dbHost:3306)/"

      mysqld_exporter_web_listen_address: "0.0.0.0:9104" 

參考連結

https://github.com/cloudalchemy/ansible-mysqld_exporter/blob/master/defaults/main.yml

2021年11月17日 星期三

由command line 傳遞變數給ansible 與docker-compose

1.由command line傳送變數給ansible

  command:

    ansible-playbook -i hosts.yml --extra-vars "a=2 b=3" tasks/xxx.yml

    ansible-playbook -i hosts.yml -e "a=2 b=3" tasks/xxx.yml

  ansible:

    tasks:

      - name: add folder

        file:

          state: directory

          path: '{{a}}'

2.由ansible command line傳送陣列變數給ansible

  以json傳遞

  command:

    ansible-playbook -i hosts.yml --extra-vars "{'myitems':[1,2,3]}" tasks/xxx.yml

  ansible:

    loop: {{myitems}}

    tasks:

      - name: add loop folder

        file:

          state: directory

          path: '{{item}}'

3.由command line傳送變數給docker-compose

  ex:

  command:

    port=12345 docker-compose up -d

  docker-compose:

    ports:

      - ${api_port}:12345

4.由command line傳送變數給ansible再傳給docker-compose

  ex:

  command:

    ansible-playbook -i hosts.yml --extra-vars "api_port=12345" tasks/ansible.yml

  ansible.yml:

    tasks:

    - name: Shell Start node-api-server

      shell:

        cmd: 'port={{api_port}} docker-compose --compatibility up -d'

  docker-compose.yml:

    ports:

      - ${api_port}:12345

2021年11月9日 星期二

透過 ansible 限制docker-compose 執行的cpu與記憶體

 實際場域遇到一個狀況

在Window Server運行node api server

發生node吃掉100%cpu 而讓系統無法回應


將node api server以docker佈署到Linux主機上

希望可以限制每個continainer的資源

限制可使用的cpu與記憶體

佈署docker container是透過ansible執行

ansible設定docker-compose的cpu限制 在3.x版後就不支援了

只能透過docker執行

要透過docker-compose執行 只能透過shell執行


安裝

1.docker-compose.yml

node-api-server:

  image: node:12.22.7-alpine3.14

  container_name: node-api-server

  working_dir: /usr/src/NODE_API_SERVER/bin

  restart: always

  command: >

    sh -c 'node index'

  volumes:

    - '/home/vagrant/project_pools:/usr/src/'

  ports:

    - 12345:12345

    - 9229:9229

  deploy:

    resources:

      limits:

        cpus: '0.40'

        memory: '300M'

2.ansible 安裝檔 install.yml

tasks

  - name: build docker

    become: true

    docker_compose:

      project_src: 'docker-comose檔案所在的目錄'

3.ansible 執行檔start.yml

tasks:

  - name: Shell Start node-api-server

    shell:

      cmd: docker-compose --compatibility up -d

      chdir: 'docker-comose檔案所在的目錄'

      

參考

https://blog.yowko.com/docker-compose-3-cpu-memory-limit/

2020年8月9日 星期日

nginx 設定檔讀取與ansible安裝範例

在安裝好nginx 可以看到/etc/nginx下包含了
nginx.conf
conf.d/
sites-enabled/
sites-available/
幾個目錄
通常我們做異動修改的都會是sites-available/下
檢視一下幾個目錄之間的關係
nginx讀取的設定檔入口是nginx.conf檔案
可以看到包含了
include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;
也就是說預設會去讀讀目錄是在sites-enabled
而在sites-enabled目錄下看到只有一個default的檔案

實際運作的方式
可以sites-available/ 下建立default.conf
然後把default.conf 做symblelink到sites-enabled/default
就可以
以 ansible做nginx的設定與安裝範例如下

---
- name: Install host nginx
  hosts: all
  become: yes
  tasks:
    - name: ensure nginx is at the latest version
      apt: name=nginx state=latest
    - name: start nginx
      service:
        name: nginx
        state: started
    - name: copy the nginx main config
      copy:
        src: ../../files/nginx/default.conf
        dest: /etc/nginx/sites-available/default.conf
    - name: remove old nginx conf
      file:
        path: /etc/nginx/sites-available/conf
        state: absent
    - name: copy conf folder to sites-available
      copy:
        src: ../../files/nginx/conf
        dest: /etc/nginx/sites-available
    - name: create symlink
      file:
        src: /etc/nginx/sites-available/default.conf
        dest: /etc/nginx/sites-enabled/default
        state: link
    - name: restart nginx
      service:
        name: nginx
        state: restarted

2020年7月28日 星期二

ansible安裝與 建立ssh連線

1.linux安裝
sudo apt-add-repository ppa:ansible/ansible
sudo apt-get update
sudo apt-get isntall ansible
測試 ansible --version

2.產生主控端ssh key
sshkey-gen
# 產生 ~/.ssh/id_rsa(private key) id_rsa.pub(public key)

3.複製主控端的id到遠端(被控端)
ssh-copy-id myuser@192.168.0.99
之後使用ssh myuser@192.168.0.9 就不需要輸入密碼

4.設定連線主機資資訊hosts.yml
all:
hosts:
  my-99:
    ansible_host: 192.168.0.99
    ansible_port: 22
    ansible_ssh_private_key_file: "~/.ssh./id_rsa" 
    ansible_user: myuser
    ansible_sudo_pass:

5.測試連線
ansible all -i hosts.yml -m ping
或
ansible my-99 -i hosts.yml

2018年5月20日 星期日

ansible-galaxy使用

透過ansible-galaxy 可以找到許多已經寫好的role直接使用
不需要在自己寫,找可以用的role 需要確認要使用的os版本
對應上 比較不會有問題
以下是基本使用上的注意要點
一.安裝roles
1.安裝在global
  ansible-galaxy install xxxx.xxx(由網站找到)
  取得的roles會存在 ~/.ansible/roles/下
  所有的專案都可以吃的到global安裝的role
  但如果有需要因不同專案有不同設定的部分
  建議不要用這樣安裝在global 因為會所有的都吃到同樣設定
2.安裝在指定目錄下
  ansible-galaxy install --roles-path . xxx
  透過--roles-path 指定安裝的目錄
  .則裝在目前所在的目錄下
3.透過設定檔案一次安裝多個role
  ansible-galaxy install --role-path ./roles -r install_roles.yml
  將要安裝的role列表寫在 指定的yml檔案下
  檔案的設定可參考
  https://galaxy.ansible.com/intro
4.設定執行環境
  在playbook下執行role 系統會在幾個預設的位置
  找安裝的role 預設值為
  ~/.ansible/roles:/usr/share/ansible/roles:/etc/ansible/roles
  若在專案內要自訂尋找role安裝的的路徑
  可以在專案的ansible.cfg內設定
  roles_path = ./roles 指定要找roles的位置
5.使用role
  在playbook內使用
  roles:
  - { role: xxxx.xxx }
  執行