Ceph ansible ssh port 변경 시 설치 불가

beomjin·2025년 3월 14일

Ceph ansible을 수행하여 custom된 ceph를 설치할 때 ssh port가 변경되면 문제가 발생하고있다.
다음과 같은 ansible log를 확인할 수 있다.

[user@bjdev-control-01 cloudx]$ ss -nltp
State                   Recv-Q                  Send-Q                                     Local Address:Port                                     Peer Address:Port                  Process
LISTEN                  0                       128                                              0.0.0.0:2222               

내 테스트 머신의 포트는 22에서 2222로 변경하고 진행하였다.

이상태로 ceph ansible을 수행하면 다음과 같이 에러가 발생한다.

Friday 07 February 2025  12:49:53 +0900 (0:00:00.080)       0:00:58.622 *******
fatal: [bjdev-control-01 -> bjdev-ceph-01]: FAILED! => {"changed": false, "msg": "file not found: /etc/ceph/ceph.pub"}
 
NO MORE HOSTS LEFT *******************************************************************************************************************************************************************************************
 
PLAY RECAP ***************************************************************************************************************************************************************************************************
bjdev-ceph-01              : ok=8    changed=2    unreachable=0    failed=0    skipped=2    rescued=0    ignored=0
bjdev-ceph-02              : ok=8    changed=2    unreachable=0    failed=0    skipped=2    rescued=0    ignored=0
bjdev-ceph-03              : ok=8    changed=2    unreachable=0    failed=0    skipped=2    rescued=0    ignored=0
bjdev-compute-01           : ok=6    changed=1    unreachable=0    failed=0    skipped=4    rescued=0    ignored=0
bjdev-control-01           : ok=8    changed=2    unreachable=0    failed=1    skipped=4    rescued=0    ignored=0
bjdev-control-02           : ok=6    changed=1    unreachable=0    failed=0    skipped=4    rescued=0    ignored=0
bjdev-control-03           : ok=6    changed=1    unreachable=0    failed=0    skipped=4    rescued=0    ignored=0
 
Friday 07 February 2025  12:49:55 +0900 (0:00:01.133)       0:00:59.756 *******
===============================================================================
burrito.ceph : Rocky Linux | Install packages on ceph servers ---------------------------------------------------------------------------------------------------------------------------------------- 17.35s
Gathering Facts -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- 16.13s
burrito.ceph : Rocky Linux | Install prerequisite packages -------------------------------------------------------------------------------------------------------------------------------------------- 9.01s
burrito.ceph : Rocky Linux | Install packages on ceph clients ----------------------------------------------------------------------------------------------------------------------------------------- 8.50s
burrito.ceph : Bootstrap | check ceph nodes are ready ------------------------------------------------------------------------------------------------------------------------------------------------- 2.37s
burrito.ceph : Bootstrap | set up insecure local registry for podman ---------------------------------------------------------------------------------------------------------------------------------- 2.28s
burrito.ceph : Bootstrap | bootstrap ceph cluster ----------------------------------------------------------------------------------------------------------------------------------------------------- 1.93s
burrito.ceph : sshkey | get ssh public key from the bootstrap node ------------------------------------------------------------------------------------------------------------------------------------ 1.13s
burrito.ceph : Main | include os specific tasks ------------------------------------------------------------------------------------------------------------------------------------------------------- 0.31s
burrito.ceph : Common | include os specific variables ------------------------------------------------------------------------------------------------------------------------------------------------- 0.22s
burrito.ceph : Rocky Linux | Install online packages -------------------------------------------------------------------------------------------------------------------------------------------------- 0.19s
burrito.ceph : Common | include default variables ----------------------------------------------------------------------------------------------------------------------------------------------------- 0.18s
burrito.ceph : Bootstrap | already bootstrapped ------------------------------------------------------------------------------------------------------------------------------------------------------- 0.08s

ceph.pub 키를 생성하지 못하여 발생하는데 사실 해당 task를 보기 전 이전 task에서 어떻게 수행됐는지 확인이 먼저 필요하다.

우선 ansible로 debug한 내용을 확인해보면 이 전 task인 Bootstrap 에서 실패하는 걸 확인할 수 있다.

TASK [ceph : Bootstrap | bootstrap ceph cluster] 
Saturday 08 February 2025  10:09:02 +0900 (0:00:00.844)       0:00:40.894 *****
...
changed: [bjdev-control-01 -> bjdev-ceph-01] => {
    "changed": true,
    "cmd": [
        "cephadm",
        "--image",
        "***.***.***.***:port/ceph/ceph:v18.2.1",
        "bootstrap",
        "--allow-overwrite",
        "--mon-ip",
        "***.***.***.***",
        "--skip-dashboard",
        "--skip-firewalld",
        "--skip-monitoring-stack",
        "--ssh-user",
        "user"
    ],
    "delta": "0:00:01.094066",
    "end": "2025-02-08 10:08:40.893346",
    "failed_when_result": false,
    "invocation": {
        "module_args": {
            "_raw_params": "cephadm    --image ***.***.***.***:port/ceph/ceph:v18.2.1    bootstrap     --allow-overwrite    --mon-ip ***.***.***.***    --skip-dashboard    --skip-firewalld    --skip-monitoring-stack    --ssh-user clex",
            "_uses_shell": false,
            "argv": null,
            "chdir": null,
            "creates": null,
            "executable": null,
            "expand_argument_vars": true,
            "removes": null,
            "stdin": null,
            "stdin_add_newline": true,
            "strip_empty_ends": true
        }
    },
    "msg": "non-zero return code",
    "rc": 1,
    "start": "2025-02-08 10:08:39.799280",
    "stderr": "Error: \n** Please verify your user's ssh configuration and make sure:\n- User user must have passwordless sudo access\n\n\nERROR: \n** Please verify your user's ssh configuration and make sure:\n- User clex must have passwordless sudo access",
    "stderr_lines": [
        "Error: ",
        "** Please verify your user's ssh configuration and make sure:",
        "- User clex must have passwordless sudo access",
        "",
        "",
        "ERROR: ",
        "** Please verify your user's ssh configuration and make sure:",
        "- User clex must have passwordless sudo access"
    ],
    "stdout": "Verifying ssh connectivity using standard pubkey authentication ...\nAdding key to clex@localhost authorized_keys...\nNon-zero exit code 255 from ssh -o StrictHostKeyChecking=no -i /tmp/ssh_key_3b8ec3c8-e5b9-11ef-be45-525400aed7d8 -o PasswordAuthentication=no clex@bjdev-ceph-01 sudo echo\nssh: stderr ssh: connect to host bjdev-ceph-01 port 22: Connection refused\n\n\n\t***************\n\tCephadm hit an issue during cluster installation. Current cluster files will NOT BE DELETED automatically to change\n\tthis behaviour you can pass the --cleanup-on-failure. To remove this broken cluster manually please run:\n\n\t   > cephadm rm-cluster --force --fsid 3b8eab04-e5b9-11ef-be45-525400aed7d8\n\n\tin case of any previous broken installation user must use the rm-cluster command to delete the broken cluster:\n\n\t   > cephadm rm-cluster --force --zap-osds --fsid <fsid>\n\n\tfor more information please refer to https://docs.ceph.com/en/latest/cephadm/operations/#purging-a-cluster\n\t***************",
    "stdout_lines": [
        "Verifying ssh connectivity using standard pubkey authentication ...",
        "Adding key to clex@localhost authorized_keys...",
        "Non-zero exit code 255 from ssh -o StrictHostKeyChecking=no -i /tmp/ssh_key_3b8ec3c8-e5b9-11ef-be45-525400aed7d8 -o PasswordAuthentication=no clex@bjdev-ceph-01 sudo echo",
        "ssh: stderr ssh: connect to host bjdev-ceph-01 port 22: Connection refused",
        "",
        "",
        "\t***************",
        "\tCephadm hit an issue during cluster installation. Current cluster files will NOT BE DELETED automatically to change",
        "\tthis behaviour you can pass the --cleanup-on-failure. To remove this broken cluster manually please run:",
        "",
        "\t   > cephadm rm-cluster --force --fsid 3b8eab04-e5b9-11ef-be45-525400aed7d8",
        "",
        "\tin case of any previous broken installation user must use the rm-cluster command to delete the broken cluster:",
        "",
        "\t   > cephadm rm-cluster --force --zap-osds --fsid <fsid>",
        "",
        "\tfor more information please refer to https://docs.ceph.com/en/latest/cephadm/operations/#purging-a-cluster",
        "\t***************"
    ]
}

디버그 로그에서 보면 "ssh: stderr ssh: connect to host bjdev-ceph-01 port 22: Connection refused" 와 같은 로그가 발생한다.
내 ceph node와 22 port로 통신한다.
근데 ansible.cfg에는 remote_port가 2222로 잘 정의되어있다.

이 경우는 cephadm의 문제인데, cephadm으로 구성 시 ssh port를 별도로 지정하는 옵션 자체가 없어서 발생하는 문제이다.

Ref :: https://docs.ceph.com/en/octopus/cephadm/operations/

그러면 playbook에서 몇가지 내용을 추가하자.

$ cat roles/ceph/tasks/bootstrap.yml
---
...
+- name: Create ssh config file.
+  blockinfile:
+    path: "/tmp/.ssh/config"
+    create: yes
+    mode: 0600
+    block: |
+      StrictHostKeyChecking no
+      UserKnownHostsFile /dev/null
+      Port {{ ansible_port }}
+  delegate_to: "{{ groups['mons'][0] }}"
+  when: ansible_port != 22
 
- name: Bootstrap | bootstrap ceph cluster
  ansible.builtin.command: >-
    cephadm \
        --image {{ quay_image_repo }}/ceph/ceph:{{ ceph_version }} \
        bootstrap {{ ceph_bootstrap_params }} \
        --allow-overwrite \
        --mon-ip {{ hostvars[groups['mons'][0]]['ansible_' + storage_iface_name].ipv4.address }} \
        --skip-dashboard \
        --skip-firewalld \
        --skip-monitoring-stack \
+        {% if ansible_port != 22 %}
+        --ssh-config "/tmp/.ssh/config" \
+        {% endif %}
        --ssh-user {{ ansible_user }}
  become: true
  register: _res
  delegate_to: "{{ groups['mons'][0] }}"
  run_once: true
  failed_when: _res.rc not in [0, 1]
...

create ssh config file을 생성하는 task를 추가하고, 해당 task는 22 port가 아니면 ssh/config파일을 생성, 이후 bootstrap시 --ssh-config 로 config파일을 가지고 bootstrap을 할 수 있도록 수정하자.

이후 ceph ansible을 수행하면 다음과 같다.

[user@bjdev-control-01 cloudx]$ sudo ceph -s
  cluster:
    id:     e870fa90-e5da-11ef-b024-525400aed7d8
    health: HEALTH_OK
 
  services:
    mon: 1 daemons, quorum bjdev-ceph-01 (age 2m)
    mgr: bjdev-ceph-01.onzaxn(active, since 117s)
    osd: 3 osds: 3 up (since 32s), 3 in (since 68s)
    rgw: 1 daemon active (1 hosts, 1 zones)
 
  data:
    pools:   9 pools, 9 pgs
    objects: 227 objects, 582 KiB
    usage:   85 MiB used, 300 GiB / 300 GiB avail
    pgs:     9 active+clean

잘 설치 된다.

즉 문제는 cephadm의 ssh port 에 대한 옵션이 없어 ssh config를 만들어 그걸로 ssh port통신을 할 수 있도록 변경하는 것이다.

0개의 댓글