Ansible/Network-20180606-ansible for cisco-ansible-vault加密登录密钥

41 篇文章 0 订阅
11 篇文章 0 订阅

Problem

隐藏登陆密码

Solution

# 创建 vault.yml
ansible-vault create vault.yml
New Vault password:
Confirm New Vault password:

# vault.yml
---
username: cisco
password: cisco
# backup_conf.yml
---
- hosts: ios_devices
  gather_facts: no
  connection: local
  vars_files:
  - vault.yml

  tasks:
  - name: SYS | Define provider
    set_fact:
      provider:
        host: "{{ inventory_hostname }}"
        username: "{{ mgmt_username }}"
        password: "{{ mgmt_password }}"
        auth_pass: "{{ mgmt_enable }}"
        authorize: yes

  - name: IOS | Show Run
    ios_command:
      provider: "{{ provider }}"
      commands:
        - show configuration
    register: config

  - debug: msg="{{ config }}"

  - name: SYS | copy config to local
    copy:
      content: "{{ config.stdout[0] }}"
      dest: "/tmp/config"
# 调用命令

# 命令行获取密钥
ansible-playbook -i inventory/ --ask-vault-pass backup_conf.yml
# 文件获取密钥
ansible-playbook -i inventory/ --vault-password-file VAULT_PASSWORD_FILENAME backup_conf.yml
# 多个文件,2.4新加特性,用于一个配置文件中含有多个不同密钥加密字段的情况
ansible-playbook -i inventory/ --vault-id VAULT_PASSWORD_FILENAME_1,VAULT_PASSWORD_FILENAME_2 backup_conf.yml

Reference

Ansible credentials management

There are at least 4 possible methods on howto handle secret data within ansible playbooks.

http://www.uni-koeln.de/~pbogusze/posts/Ansible_credentials_management.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值