最近部门需要线上部署产品中间件,研究了ansbile,多多百度,写了一套基于ansible-playbook的自动化部署脚本,目前主要部署jdk,nginx,mysql,etcd集群.
版本列表如下:
Centos 7.9
Ansible 2.2.0
Jdk 1.8.26
Nginx 1.20.0
Mysql 5.7.31
Etcd 3.3.25
- ansible的安装的playbook配置
deploy
├── ansible.cfg
├── clean.sh
├── etcd.yml
├── hosts
├── jdk.yml
├── mysql.yml
├── nginx.yml
├── readme
├── roles
│ ├── etcd
│ │ ├── files
│ │ │ ├── etcd
│ │ │ └── etcdctl
│ │ ├── tasks
│ │ │ └── main.yml
│ │ ├── templates
│ │ │ ├── etcd.conf.j2
│ │ │ └── etcd.service.j2
│ │ └── vars
│ │ └── main.yml
│ ├── jdk
│ │ ├── files
│ │ │ └── jdk-8u261-linux-x64.tar.gz
│ │ ├── handlers
│ │ ├── meta
│ │ ├── tasks
│ │ │ └── main.yml
│ │ ├── templates
│ │ └── vars
│ │ └── main.yml
│ ├── mysql
│ │ ├── files
│ │ │ └── mysql-5.7.31-linux-glibc2.12-x86_64.tar.gz
│ │ ├── handlers
│ │ ├── meta
│ │ ├── tasks
│ │ │ └── main.yml
│ │ ├── templates
│ │ │ ├── my.cnf.j2
│ │ │ ├── setpassword.sh.j2
│ │ │ └── start_mysql.sh.j2
│ │ └── vars
│ │ └── main.yml
│ └── nginx
│ ├── files
│ │ └── nginx.tar.gz
│ ├── handlers
│ ├── meta
│ ├── tasks
│ │ └── main.yml
│ ├── templates
│ │ └── nginx.conf.j2
│ └── vars
│ └── main.yml
└── vars
└── global.yml
- 创建yunwei用户并设置密码
[root@linux03 ~]# useradd -md /data/yunwei -s /bin/bash yunwei
[root@linux03 ~]# echo 'rl@2022'|passwd --stdin yunwei
更改用户 yunwei 的密码 。
passwd:所有的身份验证令牌已经成功更新。
- 上传ansible包并配置yum源(需要root用户或sudo权限)
- 安装createrepo
[root@linux03 ~]# yum install createrepo -y
Loaded plugins: fastestmirror
Loading mirror speeds from cached hostfile
Package createrepo-0.9.9-28.el7.noarch already installed and latest version
Nothing to do
[root@linux03 ~]# cd /data/yunwei/
[root@linux03 yunwei]# ls
ansible ansible.tar.gz yum.sh
[root@linux03 yunwei]# sh -x yum.sh
需要采用root用户 或者 sudo权限执行-----
Loaded plugins: fastestmirror
Loading mirror speeds from cached hostfile
Package createrepo-0.9.9-28.el7.noarch already installed and latest version
Nothing to do
Spawning worker 0 with 4 pkgs
Spawning worker 1 with 4 pkgs
Workers Finished
Saving Primary metadata
Saving file lists metadata
Saving other metadata
..........此处省略1000字.............
Dependency Installed:
PyYAML.x86_64 0:3.10-11.el7 libyaml.x86_64 0:0.1.4-11.el7_0
python-babel.noarch 0:0.9.6-8.el7 python-backports.x86_64 0:1.0-8.el7
python-backports-ssl_match_hostname.noarch 0:3.5.0.1-1.el7 python-cffi.x86_64 0:1.6.0-5.el7
python-crypto.x86_64 0:2.6.1-1.el7.centos python-enum34.noarch 0:1.0.4-1.el7
python-httplib2.noarch 0:0.7.7-3.el7 python-idna.noarch 0:2.4-1.el7
python-ipaddress.noarch 0:1.0.16-2.el7 python-jinja2.noarch 0:2.7.2-2.el7
python-keyczar.noarch 0:0.71c-2.el7 python-markupsafe.x86_64 0:0.11-10.el7
python-paramiko.noarch 0:2.1.1-9.el7 python-ply.noarch 0:3.4-11.el7
python-pycparser.noarch 0:2.14-1.el7 python-setuptools.noarch 0:0.9.8-7.el7
python-six.noarch 0:1.9.0-2.el7 python2-cryptography.x86_64 0:1.7.2-2.el7
python2-pyasn1.noarch 0:0.1.9-7.el7 sshpass.x86_64 0:1.05-1.el7.rf
Complete!
- 上传安装包deploy.tar.gz至yunwei用户
[yunwei@linux03 ~]$ tar zxf deploy.tar.gz
[yunwei@linux03 ~]$ ls
ansible ansible.tar.gz deploy deploy.tar.gz yum.sh
- 将ansible.cfg内容复制至/etc/ansible/ansible.cfg
[yunwei@linux03 deploy]$ pwd
/data/yunwei/deploy
[yunwei@linux03 deploy]$ cat ansible.cfg
[defaults]
# 跳过 ssh 首次连接提示验证
host_key_checking=False
# 关闭警告提示
command_warnings=False
deprecation_warnings=False
- 修改hosts文件,参照如下
[yunwei@linux03 deploy]$ cat hosts
[jdk]
192.168.56.119 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
192.168.56.117 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
[nginx]
192.168.56.117 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
[mysql]
192.168.56.119 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
[etcd-cluster]
192.168.56.119 etcdname=etcd01 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
192.168.56.116 etcdname=etcd02 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
192.168.56.117 etcdname=etcd03 ansible_ssh_port=22 ansible_ssh_user=cloudos ansible_ssh_pass=rl@2022
注:
1.etcd集群需要配置etcdname,用于修改配置文件,建议不动
2.安装etcd用户需要配置sudo权限
- 修改vars/global.yml文件
[yunwei@linux03 vars]$ cat global.yml
---
global:
app:
install:
home: /data/cloudos/apps
env: /data/cloudos/.bashrc
var:
mysql:
install:
# mysql安装用户
owner: cloudos
# mysql组
group: cloudos
# mysql安装服务器ip
host: 192.168.56.119
# mysql端口
port: 3306
root:
# mysql root用户密码
pass: hcmp@123
db:
# 数据库用户
user: hcmp
# 数据库密码
pass: hcmp@123
etcd:
etcdnodes: "etcd01=http://192.168.56.119:2380,etcd02=http://192.168.56.116:2380,etcd03=http://192.168.56.117:2380"
nginx:
port: 8080
注:etcdnodes的参数etcd01-etcd03与hosts的etcdname对应,需要同时修改,建议不动
- 安装过程演示
- 安装jdk
[yunwei@linux03 deploy]$ ansible-playbook jdk.yml -i hosts
PLAY [jdk] *********************************************************************
TASK [jdk : 创建jdk安装目录] *********************************************************
changed: [192.168.56.119]
changed: [192.168.56.117]
TASK [jdk : 拷贝、解压jdk安装包] *******************************************************
changed: [192.168.56.117]
changed: [192.168.56.119]
TASK [jdk : 设置环境变量] ************************************************************
changed: [192.168.56.119] => (item={u'position': u'EOF', u'value': u'\n'})
changed: [192.168.56.117] => (item={u'position': u'EOF', u'value': u'\n'})
changed: [192.168.56.119] => (item={u'position': u'EOF', u'value': u'export JAVA_HOME=/data/cloudos/apps/java/jdk1.8.0_261'})
changed: [192.168.56.117] => (item={u'position': u'EOF', u'value': u'export JAVA_HOME=/data/cloudos/apps/java/jdk1.8.0_261'})
changed: [192.168.56.119] => (item={u'position': u'EOF', u'value': u'export PATH=$JAVA_HOME/bin:$PATH'})
changed: [192.168.56.117] => (item={u'position': u'EOF', u'value': u'export PATH=$JAVA_HOME/bin:$PATH'})
changed: [192.168.56.119] => (item={u'position': u'EOF', u'value': u'export CLASSPATH=.:$JAVA_HOME/lib/dt.jar:$JAVA_HOME/lib/tools.jar'})
changed: [192.168.56.117] => (item={u'position': u'EOF', u'value': u'export CLASSPATH=.:$JAVA_HOME/lib/dt.jar:$JAVA_HOME/lib/tools.jar'})
TASK [jdk : enforce env] *******************************************************
changed: [192.168.56.119]
changed: [192.168.56.117]
PLAY RECAP *********************************************************************
192.168.56.117 : ok=4 changed=4 unreachable=0 failed=0
192.168.56.119 : ok=4 changed=4 unreachable=0 failed=0
登录117主机,查看结果
[yunwei@linux03 deploy]$ ssh cloudos@192.168.56.117
cloudos@192.168.56.117's password:
Last login: Sun Mar 6 22:14:35 2022 from linux03
[cloudos@linux03 ~]$ java -version
java version "1.8.0_261"
Java(TM) SE Runtime Environment (build 1.8.0_261-b12)
Java HotSpot(TM) 64-Bit Server VM (build 25.261-b12, mixed mode)
- 安装nginx
[yunwei@linux03 deploy]$ ansible-playbook nginx.yml -i hosts -t install
PLAY [nginx] *******************************************************************
TASK [nginx : 删除原来安装的nginx目录] **************************************************
ok: [192.168.56.117]
TASK [nginx : 创建nginx安装目录] *****************************************************
ok: [192.168.56.117]
TASK [nginx : 解压nginx安装文件] *****************************************************
changed: [192.168.56.117]
TASK [nginx : 更新nginx.conf配置文件] ************************************************
changed: [192.168.56.117]
TASK [nginx : 启动nginx] *********************************************************
changed: [192.168.56.117]
PLAY RECAP *********************************************************************
192.168.56.117 : ok=5 changed=3 unreachable=0 failed=0
登录117主机,查看结果
[yunwei@linux03 deploy]$ ssh cloudos@192.168.56.117
cloudos@192.168.56.117's password:
Last login: Sun Mar 6 22:18:55 2022 from linux03
[cloudos@linux03 ~]$ ps -ef | grep nginx
cloudos 3930 1 0 22:18 ? 00:00:00 nginx: master process sbin/nginx -p /data/cloudos/apps/nginx
cloudos 3931 3930 0 22:18 ? 00:00:00 nginx: worker process
cloudos 4024 4006 0 22:19 pts/2 00:00:00 grep --color=auto nginx
- 安装mysql
[yunwei@linux03 deploy]$ ansible-playbook mysql.yml -i hosts
PLAY [mysql] *******************************************************************
TASK [mysql : 删除原来安装的 MySQL 目录] ************************************************
ok: [192.168.56.119]
TASK [mysql : 创建 MySQL 安装目录] ***************************************************
ok: [192.168.56.119]
TASK [mysql : 解压 MySQL 安装文件] ***************************************************
changed: [192.168.56.119]
TASK [mysql : 移动 MySQL 工作目录] ***************************************************
changed: [192.168.56.119]
TASK [mysql : 新建 data|logs|sbin 目录] ********************************************
changed: [192.168.56.119] => (item=data)
changed: [192.168.56.119] => (item=logs)
changed: [192.168.56.119] => (item=sbin)
TASK [mysql : mysql 初始化] *******************************************************
changed: [192.168.56.119]
TASK [mysql : 生成 my.cnf 文件] ****************************************************
changed: [192.168.56.119]
TASK [mysql : 生成 setpassword.sh] ***********************************************
changed: [192.168.56.119]
TASK [mysql : 启动 mysql] ********************************************************
changed: [192.168.56.119]
TASK [mysql : 等待 mysql 启动完成] ***************************************************
ok: [192.168.56.119]
TASK [mysql : 停止 mysql] ********************************************************
skipping: [192.168.56.119]
TASK [mysql : 修改 root 初始密码] ****************************************************
changed: [192.168.56.119]
TASK [mysql : 给 hcmp 数据库用户授权] **************************************************
changed: [192.168.56.119]
TASK [mysql : 配置环境变量] **********************************************************
changed: [192.168.56.119]
PLAY RECAP *********************************************************************
192.168.56.119 : ok=13 changed=10 unreachable=0 failed=0
登录119主机,查看结果
[yunwei@linux03 deploy]$ ssh cloudos@192.168.56.119
cloudos@192.168.56.119's password:
Last login: Sun Mar 6 22:21:54 2022 from 192.168.56.117
[cloudos@localhost ~]$ ps -ef | grep mysql
cloudos 4024 1 0 22:21 ? 00:00:00 /bin/sh bin/mysqld_safe --defaults-file=/data/cloudos/apps/mysql/my.cnf
cloudos 4250 4024 0 22:21 ? 00:00:00 /data/cloudos/apps/mysql/bin/mysqld --defaults-file=/data/cloudos/apps/mysql/my.cnf --basedir=/data/cloudos/apps/mysql --datadir=/data/cloudos/apps/mysql/data --plugin-dir=/data/cloudos/apps/mysql/lib/plugin --log-error=/data/cloudos/apps/mysql/logs/mysqld.log --pid-file=/data/cloudos/apps/mysql/data/mysqld.pid --socket=/data/cloudos/apps/mysql/mysql.sock --port=3306
cloudos 4552 4533 0 22:24 pts/1 00:00:00 grep --color=auto mysql
[cloudos@localhost ~]$ mysql -u root -p --socket=/data/cloudos/apps/mysql/mysql.sock
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 5
Server version: 5.7.31-log MySQL Community Server (GPL)
Copyright (c) 2000, 2020, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
mysql> show databases;
+--------------------+
| Database |
+--------------------+
| information_schema |
| mysql |
| performance_schema |
| sys |
+--------------------+
4 rows in set (0.00 sec)
mysql>
- 安装etcd集群,用户必须拥有sudo权限
[yunwei@linux03 deploy]$ ansible-playbook etcd.yml -i hosts
PLAY [etcd-cluster] ************************************************************
TASK [etcd : 删除原来安装的 etcd 目录] **************************************************
ok: [192.168.56.116]
ok: [192.168.56.119]
ok: [192.168.56.117]
TASK [etcd : create data directory for etcd] ***********************************
changed: [192.168.56.116]
changed: [192.168.56.119]
changed: [192.168.56.117]
TASK [etcd : copy etcd to nodes] **********************************************
changed: [192.168.56.117]
changed: [192.168.56.119]
changed: [192.168.56.116]
TASK [etcd : copy etcdctl to nodes] ********************************************
changed: [192.168.56.119]
changed: [192.168.56.116]
changed: [192.168.56.117]
TASK [etcd : create data directory for etcd] ***********************************
changed: [192.168.56.116]
changed: [192.168.56.119]
changed: [192.168.56.117]
TASK [etcd : create conf directory for etcd] ***********************************
changed: [192.168.56.116]
changed: [192.168.56.119]
changed: [192.168.56.117]
TASK [etcd : provide etcd.conf to nodes] ***************************************
changed: [192.168.56.116]
changed: [192.168.56.119]
changed: [192.168.56.117]
TASK [etcd : provide etcd.service to nodes] ************************************
ok: [192.168.56.116]
ok: [192.168.56.119]
ok: [192.168.56.117]
TASK [etcd : start etcd service] ***********************************************
changed: [192.168.56.117]
changed: [192.168.56.116]
changed: [192.168.56.119]
PLAY RECAP *********************************************************************
192.168.56.116 : ok=10 changed=8 unreachable=0 failed=0
192.168.56.117 : ok=10 changed=8 unreachable=0 failed=0
192.168.56.119 : ok=10 changed=8 unreachable=0 failed=0
登录主机116,显示结果
[root@linux02 system]# su - cloudos
Last login: Sun Mar 6 22:30:57 EST 2022 on pts/1
[cloudos@linux02 ~]$ export ETCDCTL=3
[cloudos@linux02 ~]$ cd apps/etcd/
bin/ cfg/ data/
[cloudos@linux02 ~]$ cd apps/etcd/bin/
[cloudos@linux02 bin]$ ./etcdctl member list
43dc553e4afe2e44: name=etcd03 peerURLs=http://192.168.56.117:2380 clientURLs=http://192.168.56.117:2379 isLeader=false
7fe540e391278451: name=etcd01 peerURLs=http://192.168.56.119:2380 clientURLs=http://192.168.56.119:2379 isLeader=false
b7269082304de739: name=etcd02 peerURLs=http://192.168.56.116:2380 clientURLs=http://192.168.56.116:2379 isLeader=true