본문으로 건너뛰기
Ansible Galaxy - Git 저장소를 활용하여 Role 의존성 관리하기

Ansible Galaxy - Git 저장소를 활용하여 Role 의존성 관리하기

2017년 2월 16일

Git 저장소에 Ansible Role 올리기

먼저, Ansible Role 을 개발하기 위한 Git repository를 생성한다. 그리고, Ansible Role 초기 프로젝트 구조를 Ansible Galaxy 를 사용하여 생성한다.

  • Git repository 를 로컬 머신에 복제한다.
1
$ git clone "https://github.com/xxxxx/sample-role.git"
  • Ansible Role 초기 디렉토리 및 파일 생성한다.
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
$ ansible-galaxy init --force sample-role
- sample-role was created successfully

$ tree sample-role/
sample-role/
├── README.md
├── defaults
│   └── main.yml
├── files
├── handlers
│   └── main.yml
├── meta
│   └── main.yml
├── tasks
│   └── main.yml
├── templates
├── tests
│   ├── inventory
│   └── test.yml
└── vars
    └── main.yml
  • Ansible Role 개발을 진행 한 뒤에 Git repository 에 Push
1
$ git commit * -m "Add ansible role" && git push

Git 저장소로부터 Ansible Role 가져오기

  • 방법 1) Ansible Galaxy CLI 명령을 통해 다운로드
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
$ ansible-galaxy install git+https://github.com/xxxx/sample-role.git,master -p roles/

$ tree roles/
roles/
└── sample-role
    ├── README.md
    ├── defaults
    │   └── main.yml
    ├── handlers
    │   └── main.yml

    ├── meta
    │   └── main.yml
    ├── tasks
    │   └── main.yml
    ├── tests
    │   ├── inventory
    │   └── test.yml
    └── vars
        └── main.yml
  • 방법 2) 의존성 파일에 명시하고 CLI 명령을 통해 다운로드
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
$ vi requirements.yml
- src: git+https://github.com/xxxx/sample-role.git
  version: master

$ ansible-galaxy install -r requirements.yml -p roles/
- extracting sample-role to roles/sample-role
- sample-role was installed successfully

$ tree roles/
roles/
└── sample-role
    ├── README.md
    ├── defaults
    │   └── main.yml
    ├── handlers
    │   └── main.yml

    ├── meta
    │   └── main.yml
    ├── tasks
    │   └── main.yml
    ├── tests
    │   ├── inventory
    │   └── test.yml
    └── vars
        └── main.yml

‘requirements.yml’ 작성하기

  • src
    • username.role_name : Ansible Galaxy 공식 저장소에 등록된 Ansible Role 을 다운로드할 때 사용.
    • url : Ansible Galaxy 에서 지원하는 SCM으로부터 다운로드할 때 사용.
  • scm
    • 연동할 SCM 이름을 명시. 디폴트 값은 ‘git’ (ansible-galaxy 2.2.1.0 기준으로 git, hg 만 지원)
  • version
    • tag 명 / commit hash 값 / branch 이름을 명시. 디폴트는 ‘master’
    • SCM 으로부터 가져올 때에만 사용.
  • name
    • 다운로드한 Ansible Role 의 이름을 명시. 기본적으로는 Ansible Galaxy에 등록된 이름 혹은 Git repository 의 이름을 사용.

아래 예시를 참고!

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
# from galaxy
- src: yatesr.timezone

# from GitHub
- src: https://github.com/bennojoy/nginx

# from GitHub, overriding the name and specifying a specific tag
- src: https://github.com/bennojoy/nginx
  version: master
  name: nginx_role

# from a webserver, where the role is packaged in a tar.gz
- src: https://some.webserver.example.com/files/master.tar.gz
  name: http-role

# from Bitbucket
- src: git+http://bitbucket.org/willthames/git-ansible-galaxy
  version: v1.4

# from Bitbucket, alternative syntax and caveats
- src: http://bitbucket.org/willthames/hg-ansible-galaxy
  scm: hg

# from GitLab or other git-based scm
- src: git@gitlab.company.com:mygroup/ansible-base.git
  scm: git
  version: "0.1"  # quoted, so YAML doesn't parse this as a floating-point value

PS. 사내 GitLab 같은 private 저장소의 Role 을 가져오는 경우에는 위의 마지막 예시처럼 git@... 형태의 SSH 주소를 쓰는 것이 가장 편했다. ansible-galaxy 가 내부적으로 git clone 을 호출하기 때문에, 해당 장비에서 ssh -T git@gitlab.company.com 으로 접속이 되는 상태라면 별도의 설정 없이 그대로 동작한다. HTTPS 주소에 토큰을 넣는 방법도 가능은 하지만, requirements.yml 이 저장소에 같이 올라가므로 추천하지 않는다.

그리고, version 에 브랜치 이름을 적어두면 설치할 때마다 다른 코드를 받아올 수 있으니 운영 환경에서는 tag 나 commit hash 로 고정해두는 것이 안전하다.

참고 링크