1.准备三台机器做域名解析(一台ansible机器,一台web机器,一台数据库机器)
#在ansible机器操作
[root@server1 ~]# vim /etc/hosts
10.36.192.202 webserver1
10.36.192.197 webserver2
[root@server1 ~]# vim /etc/ansible/hosts
[web]
webserver1
webserver2
2.创建roles目录,在此生成对应的目录结构
[root@server1 ~]# mkdir /roles
[root@server1 ~]# cd /roles/
#生成nginx角色
[root@server1 roles]# ansible-galaxy init nginx
#生成php角色
[root@server1 roles]# ansible-galaxy init php
#生成mysql角色
[root@server1 roles]# ansible-galaxy init mysql
#生成wordpress角色
[root@server1 roles]# ansible-galaxy init wordpress
3.nginx角色操作
#nginx目录结构
3.1 在templates下面存放一个nginx魔板配置文件
# For more information on configuration, see:
# * Official English Documentation: http://nginx.org/en/docs/
# * Official Russian Documentation: http://nginx.org/ru/docs/
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;
# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;
events {
worker_connections 1024;
}
http {
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
'$status $body_bytes_sent "$http_referer" '
'"$http_user_agent" "$http_x_forwarded_for"';
access_log /var/log/nginx/access.log main;
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 4096;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Load modular configuration files from the /etc/nginx/conf.d directory.
# See http://nginx.org/en/docs/ngx_core_module.html#include
# for more information.
include /etc/nginx/conf.d/*.conf;
server {
listen {{ nginxport }};
listen [::]:80;
server_name _;
root /usr/share/nginx/html/wordpress;
# Load configuration files for the default server block.
include /etc/nginx/default.d/*.conf;
location / {
root /usr/share/nginx/html/wordpress;
index index.php;
}
location ~ \.php$ {
root /usr/share/nginx/html/wordpress;
fastcgi_pass 127.0.0.1:9000;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
error_page 404 /404.html;
location = /404.html {
}
error_page 500 502 503 504 /50x.html;
location = /50x.html {
}
}
# Settings for a TLS enabled server.
#
# server {
# listen 443 ssl http2;
# listen [::]:443 ssl http2;
# server_name _;
# root /usr/share/nginx/html;
#
# ssl_certificate "/etc/pki/nginx/server.crt";
# ssl_certificate_key "/etc/pki/nginx/private/server.key";
# ssl_session_cache shared:SSL:1m;
# ssl_session_timeout 10m;
# ssl_ciphers HIGH:!aNULL:!MD5;
# ssl_prefer_server_ciphers on;
#
# # Load configuration files for the default server block.
# include /etc/nginx/default.d/*.conf;
#
# error_page 404 /404.html;
# location = /40x.html {
# }
#
# error_page 500 502 503 504 /50x.html;
# location = /50x.html {
# }
# }
}
3.2 在tasks/main.yml编写任务剧本
---
# tasks file for nginx
- name: 下载本地源
get_url: url=http://10.36.192.100/yum-server.sh dest=/root
- name: 配置本地源
shell: sh /root/yum-server.sh
- name: 安装nginx
yum: name=nginx state=present
- name: 拷贝配置文件
template: src=/roles/nginx/templates/nginx.conf dest=/etc/nginx/nginx.conf
notify: hahaha
- name: 启动nginx
service: name=nginx state=started
3.3 在vars/main.yml给变量赋值
---
# vars file for nginx
nginxport: 81
3.4 在handlers/main.yml下面编写tasks/main.yml的notify
---
# handlers file for nginx
- name: hahaha
service: name=nginx state=restarted
3.5 修改tests/test.yml(修改localhost为要操作的机器,如webserver1)
---
- hosts: webserver1
remote_user: root
roles:
- nginx
3.6 运行nginx角色
[root@server1 roles]# ansible-playbook /roles/nginx/tests/test.yml
#运行截图
4.在php目录操作
4.1 在tasks/main.yml编写剧本
---
# tasks file for php
- name: 安装php1
shell: yum install -y http://rpms.remirepo.net/enterprise/remi-release-7.rpm
- name: 安装php2
yum: name=php80-php-xsl,php80-php,php80-php-cli,php80-php-devel,php80-php-gd,php80-php-pdo,php80-php-mysql,php80-php-fpm
- name: 启动php
service: name=php80-php-fpm state=started
4.2 修改tests/test.yml(修改localhost为要操作的机器,如webserver1)
---
- hosts: webserver1
remote_user: root
roles:
- php
4.3 运行php
[root@server1 roles]# ansible-playbook /roles/php/tests/test.yml
5. 在mysql目录操作
5.1 在tasks/main.yml编写剧本
---
# tasks file for mysql
- name: 下载本地源
get_url: url=http://10.36.192.100/yum-server.sh dest=/root
- name: 配置本地源
shell: sh /root/yum-server.sh
- name: 安装数据库
shell: yum -y install mysql-server
- name: 启动数据库
service: name=mysqld state=started
5.2 运行mysql角色目录
[root@server1 roles]# ansible-playbook /roles/mysql/tests/test.yml
5.3 在webserver2机器进入mysql授权
#跳过输入密码登录数据库
[root@webserver2 ~]# vim /etc/my.cnf
skip-grant-tables
#重启数据库
[root@webserver2 ~]# systemctl restart mysqld
#登录数据库
[root@webserver2 ~]# mysql
#设置数据库登录密码
mysql> update mysql.user set authentication_string=password('qf@123') where user='root' and host='localhost';
Query OK, 0 rows affected, 1 warning (0.01 sec)
Rows matched: 1 Changed: 0 Warnings: 1
mysql> flush privileges;
Query OK, 0 rows affected (0.01 sec)
#创建一个数据库
mysql> create database wordpress;
#授权用户
mysql> grant all on wordpress.* to 'wordpress'@'%' identified by 'qf@123';
mysql> flush privileges;
6. 创建wordpress角色
6.1 将wordpress的包放在files文件下
[root@server1 ~]# ls /roles/wordpress/files/
wordpress-6.4.1-zh_CN.tar.gz
6.2 在tasks/main.yml
---
# tasks file for wordpress
- name: 解压wordpress包
unarchive: src=/roles/wordpress/files/wordpress-6.4.1-zh_CN.tar.gz dest=/usr/share/nginx/html
6.3 运行
[root@server1 nginx]# cd /roles/wordpress/tests/test.yml