[RHCE] 학습 포인트, RHCE v9 Dumps

dan·2026년 2월 25일

Red Hat Linux

목록 보기
9/9

이번 포스팅에서는 RHCE v9 응시를 위해 수집한 Dump와 풀이를 담아보려 한다. Red Hat 공식 홈페이지에서는 RHCE의 주요 학습 포인트를 다음과 같이 제시한다.


1. 시험 대비를 위한 학습 포인트(Red Hat 공식)

시험 대비를 위한 학습 포인트

"Red Hat Certified System Engineer 시험 응시자는 다음 태스크를 수행할 수 있어야 합니다."

1. Red Hat Certified System Administrator(RHCSA)에게 기대되는 모든 태스크를 수행할 수 있어야 합니다.

> 필수 툴 이해 및 사용
> 실행 시스템 운영
> 로컬 스토리지 구성
> 파일 시스템 구축 및 구성
> 시스템 배포, 구성 및 유지 관리
> 사용자 및 그룹 관리
> 보안 관리
> 간단한 쉘 스크립트 분석

2. VS Code(Visual Studio Code)에 능숙하고 해당 편집기 내에서 다음 작업을 수행할 수 있어야 합니다.

> Git 리포지토리 복제
> 플레이북을 생성하고 GIT 리포지토리로 푸시
> ansible-navigator 구성
> Ansible 개발 컨테이너를 사용하여 플레이북 실행

3. Ansible의 핵심 구성 요소를 이해해야 합니다.

> 인벤토리
> 모듈
> 변수
> 팩트
> 반복문
> 조건부 작업
> 플레이
> 태스크 실패 처리
> 플레이북
> 구성 파일
> 롤
> 제공된 설명서를 사용하여 Ansible 모듈 및 커맨드에 대한 특정 정보 조회

4. Ansible을 설치 및 구성할 수 있습니다.

> 필수 패키지 설치
> ansible.cfg 생성 및 수정
> ansible-navigator.yml 수정
> 정적 호스트 인벤토리 파일 생성
> 정적 인벤토리를 생성하고 사용하여 호스트 그룹 정의

5. Ansible 관리형 노드를 구성할 수 있습니다.

> SSH 키를 생성하고 관리형 노드에 배포
> 관리형 노드에 대한 권한 에스컬레이션 구성
> 관리형 노드에 파일 배포

6. ansible-navigator로 플레이북을 실행할 수 있습니다.

> ansible-navigator로 플레이북을 실행하는 방법 이해
> ansible-navigator를 사용하여 사용 가능한 Ansible Content Collections에서 새 모듈을 찾아 사용
> ansible-navigator를 사용하여 인벤토리를 생성하고 Ansible 환경 구성

7. Ansible 플레이 및 플레이북을 생성할 수 있습니다.

> 일반적으로 사용되는 Ansible 모듈로 작업하는 방법 이해
> 변수를 사용하여 커맨드 실행 결과 검색
> 조건문을 사용하여 플레이 실행 제어
> 오류 처리 구성
> 플레이북을 생성하여 시스템을 지정된 상태로 구성

8. 롤 및 Ansible Content Collections를 사용할 수 있습니다.

> 롤 생성 및 사용
> 롤을 설치하고 플레이북에서 사용
> 콘텐츠 컬렉션을 설치하고 플레이북에서 사용
> 콘텐츠 컬렉션에서 관련 롤, 보조 모듈 및 기타 콘텐츠를 가져와 플레이북에서 사용

9. 다음과 호환되는 Ansible 모듈을 사용하여 표준 RHCSA 태스크를 자동화합니다.

> 소프트웨어 패키지 및 리포지토리
> 서비스
> 방화벽 규칙
> 파일 시스템
> 스토리지 기기
> 파일 콘텐츠
> 아카이빙
> 태스크 스케줄링
> 보안
> 사용자 및 그룹

10. 콘텐츠를 관리할 수 있습니다.

> 템플릿을 생성하고 사용하여 사용자 정의 구성 파일 생성
> 플레이북에서 Ansible Vault를 사용하여 민감한 데이터 보호

2. RHCE v9 Dumps

과제는 총 17개이다. Control Node에서는 playbook 생성 및 실행하며, Managed Nodes에서는 적용여부를 확인 및 검증한다.

1. Ansible 설치 및 기본 설정

*Ansible을 설치하고 다음과 같이 설정하세요.*

- node1 is a member of ”dev” host group
- node2 is a member of ”test” host group
- node3, node4 is a member of ”prod” host group
- node5 is a member of ”balancers” host group
- “prod” group is a member of the ”webservers” host group
- collections_path is /home/admin/ansible/mycollections
- roles_path is /home/admin/ansible/roles

나의 답안:

# 계정: root
# 1) ansible 설치 및 디렉토리 생성
dnf install ansible-* -y
mkdir ansible
cd ansible

# 2) inventory 작성
vi inventory

[dev]
node1

[test]
node2

[prod]
node3  
node4

[balancers]
node5

[webservers:children]
prod

:wq

# 3) ansible.cfg 작성
ansible-config init --disabled >> ansible.cfg
vi ansible.cfg

## 경로1:경로2:경로3 -> 지정경로:기본경로 (우선순위 탐색)
[defaults]
inventory=/home/admin/ansible/inventory  
collections_path=/home/admin/ansible/mycollections:~/.ansible/collections:/usr/share/ansible/collections 
roles_path=/home/admin/ansible/roles:/usr/share/ansible/roles/
remote_user=admin

[privilege_escalation]
become=true  
become_method=sudo  
become_user=root  
become_ask_pass=false

:wq

# 4) 검증
ansible all -a "whoami"
ansible all -m ping

2. YUM Repository 설정

/home/admin/ansible/yum_repo.yml 플레이북을 통해서 모든 노드에 대해 다음과 같이 yum repository를 설정하세요.

- 이름은 EX294_BaseOS 입니다.
- description은 EX294 baseos software 입니다.
- 레포지토리 주소는 http://redhat.example.com/repo/BaseOS 입니다.
- gpg 확인이 활성화 됩니다.
- gpgkey 의 url은 http://redhat.example.com/rhel/rhel-gpg-key 입니다.
- 레포지토리가 활성화됩니다.

- 이름은 EX294_AppStream 입니다.
- description은 EX294 appstream software 입니다.
- 레포지토리 주소는 http://redhat.example.com/repo/Appstream 입니다.
- gpg 확인이 활성화 됩니다.
- gpgkey 의 url은 http://redhat.example.com/rhel/rhel-gpg-key 입니다.
- 레포지토리가 활성화됩니다.

나의 답안:

# 1) yum_repo.yml 작성
vi yum_repo.yml

---
- name: yum
  hosts: all
  tasks:
    - name: Add EX294_BaseOS repository
      yum_repository:
        name: EX294_BaseOS
        description: EX294 baseos software
        baseurl: http://redhat.example.com/repo/BaseOS
        gpgcheck: true
        gpgkey: http://redhat.example.com/rhel/rhel-gpg-key
        enabled: true

    - name: Add EX294_AppStream repository
      yum_repository:
        name: EX294_AppStream
        description: EX294 appstream software
        baseurl: http://redhat.example.com/repo/AppStream
        gpgcheck: true
        gpgkey: http://redhat.example.com/rhel/rhel-gpg-key
        enabled: true

:wq

# 2) 실행
ansible-playbook yum_repo.yml

# 3) 검증
dnf clean all
dnf repolist -v

3. Collection 설치

컬렉션 아티팩트를 설치하고 컬렉션을 /home/admin/ansible/mycollections 에 설치하세요.

- https://redhat.example.com/download/ansible-posix-1.5.1.tar.gz
- https://redhat.example.com/download/community-general-5.4.0.tar.gz
- https://redhat.example.com/download/redhat-rhel_system_roles-1.15.1.tar.gz

나의 답안:

su - admin
# 1) 디렉토리 생성 및 파일 다운로드
mkdir -p /home/admin/ansible/mycollections
cd /home/admin/ansible/mycollections

wget https://redhat.example.com/download/ansible-posix-1.5.1.tar.gz
wget https://redhat.example.com/download/community-general-5.4.0.tar.gz
wget https://redhat.example.com/download/redhat-rhel_system_roles-1.15.1.tar.gz

# 2-1) 방법 1: .yml 파일로 설치
vi requirements.yml

---
collections:
  - name: /home/admin/ansible/mycollections/ansible-posix-1.5.1.tar.gz
  - name: /home/admin/ansible/mycollections/community-general-5.4.0.tar.gz
  - name: /home/admin/ansible/mycollections/redhat-rhel_system_roles-1.15.1.tar.gz

:wq

cd ..

# 2-2) 방법 1 - 실행
ansible-galaxy collection install -r requirements.yml -p /home/admin/ansible/mycollections

# 3) 방법 2: ansible-galaxy로 설치
ansible-galaxy collection install /home/admin/ansible/mycollections/redhat-rhel_system_roles-1.15.1.tar.gz -p /home/admin/ansible/mycollections
ansible-galaxy collection install [ 설치하고 싶은 파일 경로 ] -p [ 설치할 디렉토리 경로 ]

# 4) 검증
ansible-galaxy collection list -p /home/admin/ansible/mycollections

4. Package 설치

다음을 수행하는 플레이북 /home/admin/ansible/packages.yml을 생성하세요.

- php, mariadb 패키지가 dev, test 그리고 prod 호스트에 설치 됩니다.
- RPM Development Tools 패키지가 dev 호스트에 설치됩니다.
- dev 호스트의 모든 패키지가 최신 버전으로 업데이트 됩니다.

나의 답안:

# 1) packages.yml 작성
vi packages.yml

---
- name: install packages
  hosts:
    - dev
    - test
    - prod
  become: true
  tasks:
    - name: install php and mariadb
      yum:
        name:
          - php
          - mariadb-server
        state: latest

- name: install Development Tools
  hosts: dev
  become: true
  tasks:
    - name: install developer tools
      yum:
        name: "@RPM Development Tools"
        state: latest

    - name: update all
      yum:
        name: '*'
        state: latest

:wq

# 2) 실행
ansible-playbook packages.yml

5. Role 사용하기(1)

다음 동작을 수행하는 /home/admin/ansible/timesync.yml 플레이북을 생성하세요.

- 모든 관리 호스트에서 동작합니다.
- timesync 역할을 사용합니다.
- NTP provider를 활성화 합니다.
- 타임 서버를 time.bora.net로 설정합니다.
- iburst를 활성화 합니다.

나의 답안:

# 1) timesync.yml 작성
vi timesync.yml

---
- name: Manage timesync with bora servers
  hosts: all
  become: true
  vars:
    timesync_ntp_servers: # 표준변수
      - hostname: time.bora.net
        iburst: true
  roles:
    - fedora.linux_system_roles.timesync

:wq

ansible-playbook timesync.yml

# 2) 검증
timedatectl status
chronyc sources -v
-------------------------------------
# 표준변수 확인
/usr/share/docs/[role명]/roles/ 이하의 .readme 파일

6. Role 사용하기(2)

다음 동작을 수행하는 /home/admin/ansible/selinux.yml을 생성하세요.

- 모든 관리 호스트에서 동작합니다.
- selinux 역할을 사용합니다.
- 정책의 targeted으로 설정됩니다.
- 상태는 enforcing으로 설정됩니다.

나의 답안:

# 1) selinux.yml 작성
vi selinux.yml

---
- name: selinux
  hosts: all
  vars:
    - selinux_policy: targeted
    - selinux_state: enforcing
  roles:
    - fedora.linux_system_roles.selinux

:wq

# 2) 실행
ansible-playbook selinux.yml

7-A. Roles 설치

/home/admin/ansible/roles/requirements.yml 와 Ansible Galaxy를 사용하여 역할을 /home/admin/ansible/roles에 설치하세요.

- http://redhat.example.com/materials/haproxy.tar
    - 이 역할의 이름은 balancer 이여야 합니다.
- http://redhat.example.com/materials/phpinfo.tar
    - 이 역할의 이름은 phpinfo 이여야 합니다.
    

나의 답안:

# 1) 디렉토리 생성 및 requirements.yml 작성
mkdir roles
vi roles/requirements.yml

---
- name: balancer
  src: http://redhat.example.com/materials/haproxy.tar

- name: phpinfo
  src: http://redhat.example.com/materials/phpinfo.tar

:wq

# 2) 실행
ansible-galaxy install -r roles/requirements.yml -p roles/

# 3) 검증
ls -al roles/

7-B. Roles 설치 및 사용하기

다음 요구사항을 갖는 /home/admin/ansible/roles.yml 이라는 이름의 플레이북을 생성합니다.

- balancers 호스트 그룹에서 실행되며 balancer 역할을 사용하는 play가 포함되어야 합니다. 이 역할은 webservers 호스트 그룹 내의 호스트 사이에서 웹 서버 요청을 로드 밸런싱하는 서비스를 구성합니다.
  예를 들어 [http://node5.domain1.example.com/](http://node5.domain1.example.com/을) 을 브라우징하면 다음 출력이 생성됩니다.
  - Welcome to [node3.domain1.example.com](http://node3.domain1.example.com) on 192.168.56.133
  브라우저를 다시 로드하면 대체 웹 서버에서 출력을 생성합니다.
  - Welcome to [node4.domain1.example.com](http://node4.domain1.example.com) on 192.168.56.134
  
- webservers 호스트 그룹에서 실행되며 phpinfo 역할을 사용하는 play가 포함되어야 합니다. webservers 호스트 그룹 내의 호스트에서 /hello.php URL로 브라우징하면 다음 출력이 생성됩니다.
  - Hello PHP World from FQDN
  여기서 FQDN은 호스트의 완전한 도메인 이름입니다. 
  예를 들어 http://node3.domain1.example.com/hello.php 를 브라우징하면 다음 출력이 생성됩니다.
  - Hello PHP World from node3.domain1.example.com
  http://node4.domain1.example.com/hello.php 를 브라우징하면, PHP 구성의 여러 세부 정보와 함께 다음과 같은 출력이 생성됩니다.
  - Hello PHP World from node4.domain1.example.com
  

나의 답안:

# 1) roles.yml 작성
vi roles.yml

---
- name: phpinfo
  hosts: webservers
  become: true
  roles:
    - phpinfo

- name: balancer
  hosts: balancers
  become: true
  roles:
    - balancer

:wq

# 2) 실행
ansible-playbook roles.yml

# 3) 검증
curl http://node5
curl http://node5
curl http://node3/hello.php
curl http://node4/hello.php

8. New Role 생성 및 사용하기

다음을 수행하는 /home/admin/ansible/roles/apache 역할을 생성하세요.

- httpd 가 설치되고 부팅 시 자동 실행됩니다.
- 방화벽이 활성화 되고 웹 서버에 대한 접근이 허용 됩니다.
- index.html.j2 가 /var/www/html/index.html 에 생성되고 아웃풋은 다음과 같습니다.
    - Welcome to [HOSTNAME] on [IPADDRESS]
- HOSTNAME 은 해당 노드의 정규 도메인 이름이고 IPADDRESS는 호스트의 IP 주소입니다.
- /home/admin/ansible/newrole.yml 플레이북을 통해 역할이 수행 됩니다:
- 플레이북은 webservers 호스트 그룹의 호스트에서 실행됩니다.

나의 답안:

# 1) 디렉토리, 파일 생성
mkdir -p roles/apache/tasks
mkdir -p roles/apache/templates

touch roles/apache/tasks/main.yml
touch roles/apache/templates/index.html.j2

# 2-1) index.html.j2 생성
vi roles/apache/templates/index.html.j2

Welcome to {{ ansible_fqdn }} on {{ ansible_default_ipv4.address }}

:wq

# 2-2) main.yml 작성
cd /home/admin/ansible
ansible-galaxy init roles/apache

vi roles/apache/tasks/main.yml

---
- name: Install httpd
  yum:
    name: httpd
    state: latest

- name: Start httpd
  service:
    name: httpd
    enabled: true
    state: started

- name: Enable firewalld
  service:
    name: firewalld
    enabled: true
    state: started

- name: Configure firewall for HTTP service
  firewalld:
    service: http
    state: enabled
    permanent: true
    immediate: true

- name: Deploy index.html template
  template:
    src: index.html.j2
    dest: /var/www/html/index.html

:wq

# 3) newrole.yml 작성
cd /home/admin/ansible
vi newrole.yml

---
- name: Deploy apache role
  hosts: webservers
  become: true
  roles:
    - apache

:wq

# 4) 실행
ansible-playbook newrole.yml

# 5) 검증
curl http://node3
curl http://node4
----------------------------------------------------
# 환경변수 체크:
ansible localhost -m setup | more
수동으로 체크

9. Logical Volume 생성하기

모든 노드에서 실행되는 /home/admin/ansible/lv.yml 플레이북을 만들어 다음을 수행 하십시오.

- 논리 볼륨은 research 볼륨 그룹에 생성됩니다.
- 논리 볼륨 이름은 data 입니다.
- 크기는 1500 Mib 입니다.
- ext4 파일 시스템으로 논리 볼륨을 포맷합니다.
- 논리 볼륨이 생성될 수 없는 경우 다음과 같은 오류 메시지가 출력됩니다.
- Could not create logical volume of that size
- 출력 후 800MiB가 대신 생성됩니다.
- 볼륨 그룹 research가 없는 경우 "Volume group does not exist" 가 출력됩니다.
- 논리 볼륨은 마운트되지 않습니다.

나의 답안:

# 1) lv.yml 작성
vi lv.yml

---
- name: lvcreate
  hosts: all
  tasks:
    - block:
        - name: Create a logical volume of 1500 MiB
          lvol:
            vg: research
            lv: data
            size: 1500m

        - name: Format the logical volume (1500 MiB)
          filesystem:
            fstype: ext4
            dev: /dev/research/data

      rescue:
        - debug:
            msg: "Could not create logical volume of that size"

        - name: Create a logical volume of 800 MiB
          lvol:
            vg: research
            lv: data
            size: 800m

        - name: Format the logical volume (800 MiB)
          filesystem:
            fstype: ext4
            dev: /dev/research/data
          when: ansible_lvm.vgs.research is defined

        - debug:
            msg: "Volume group does not exist"
          when: ansible_lvm.vgs.research is undefined
:wq

# 2) 실행
ansible-playbook lv.yml

# 3) 검증
lvdisplay
vgdisplay

10. Hosts(Inventory) 파일 작성

- http://redhat.example.com/material/hosts.j2 에서 초기 파일을 /home/admin/ansible에 다운로드 합니다.
- 파일을 완성하여 템플릿을 준비합니다.
- /home/admin/ansible/hosts.yml로 다운로드합니다.
- /home/admin/ansible/hosts.yml 플레이북은 dev 호스트 그룹의 호스트에서 /etc/myhosts 파일을 생성합니다.
- 플레이북이 실행되면 호스트에 다음과 같은 내용이 /etc/myhosts 에 저장됩니다.

127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4  
::1         localhost localhost.localdomain localhost6 localhost6.localdomain6

node1.example.com 10.40.162.24 node1  
node2.example.com 10.40.162.25 node2  
node5.example.com 10.40.162.28 node5  
node3.example.com 10.40.162.26 node3  
node4.example.com 10.40.162.27 node4
*노드의 순서는 중요하지 않습니다.

나의 답안:

# 1) hosts.j2 파일 다운로드 및 내용 확인
wget http://redhat.example.com/material/hosts.j2 -O /home/admin/ansible/hosts.j2
vi hosts.j2

127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1         localhost localhost.localdomain localhost6 localhost6.localdomain6

{% for host in groups['all'] %}
{{ hostvars[host]['ansible_facts']['fqdn'] }} {{ hostvars[host]['ansible_facts']['default_ipv4']['address'] }} {{ hostvars[host]['ansible_facts']['hostname'] }}
{% endfor %}

# 1-1) hosts.j2 파일에 내용이 없을 경우 대비
cat /etc/hosts >> hosts.j2

# 2) hosts.yml 작성
vi hosts.yml

---
- name: Generate hosts file
  hosts: dev
  become: true
  tasks:
    - name: Create /etc/myhosts file using template
      template:
        src: hosts.j2
        dest: /etc/myhosts
      when: ansible_hostname in groups.dev

:wq

# 2) 실행
ansible-playbook hosts.yml

# 3) 검증
ansible dev -m shell -a "cat /etc/myhosts"

11. Contents 수정하기

다음을 수행하는 /home/admin/ansible/issue.yml 을 작성하세요.

- 모든 관리 노드에서 실행됩니다.
- /etc/issue 파일의 내용이 다음과 같이 변경됩니다.
- dev 호스트 그룹의 호스트에서는 다음과 같은 내용이 있습니다: Development
- test 호스트 그룹의 호스트에서는 다음과 같은 내용이 있습니다: Test
- prod 호스트 그룹의 호스트에서는 다음과 같이 변경됩니다: Production

나의 답안:

# 1) issue.yml 작성
vi issue.yml

---
- name: issue
  hosts: all
  tasks:
    - name: Configure issue for 'Development'
      copy:
        dest: /etc/issue
        content: Development
      when: ansible_hostname in groups.dev

    - name: Configure issue for 'Test'
      copy:
        dest: /etc/issue
        content: Test
      when: ansible_hostname in groups.test

    - name: Configure issue for 'Production'
      copy:
        dest: /etc/issue
        content: Production
      when: ansible_hostname in groups.prod

:wq

# 2) 실행
ansible-playbook issue.yml

# 3) 검증
ansible all -m shell -a "cat /etc/issue"

12. Web Contents 디렉토리 생성하기

다음을 수행하는 /home/admin/ansible/webcontent.yml 플레이북을 생성하세요.

- dev 호스트 그룹의 노드에서 실행됩니다.
- /webdev 디렉토리를 생성합니다.
- webdev 그룹이 소유합니다.
- 일반 권한은 소유자 = 읽기+쓰기+실행, 그룹: 읽기+쓰기+실행, 다른 사용자= 읽기+실행
- 특수 권한은 그룹 ID가 설정됩니다.
- 심볼릭 링크로 /var/www/html/webdev와 /webdev 를 링크하세요.
- /webdev/index.html 파일을 생성하고 해당 파일 내용은 "Development" 입니다.
- dev 호스트 그룹 노드의 리 디렉토리를 브라우징 하면 "Development" 가 출력되어야 합니다.

나의 답안:

# 1) webcontent.yml 작성
vi webcontent.yml

---
- name: Set for web
  hosts: dev
  tasks:
    - name: Create directory
      file:
        path: /webdev
        group: webdev
        mode: 2775
        state: directory
        setype: httpd_sys_content_t

    - name: create symbolic link
      file:
        src: /webdev
        dest: /var/www/html/webdev
        state: link

    - name: Create html file
      copy:
        dest: /webdev/index.html
        content: Development
        setype: httpd_sys_content_t

# 2) 실행
ansible-playbook webcontent.yml

# 3) 검증
curl http://node3/webdev/

13. 하드웨어 보고서(hwreport) 작성

다음을 수행하는 /home/admin/ansible/hwreport.yml 플레이북을 생성하세요.

- 모든 관리노드에서 실행됩니다.
- 다음 내용이 들어있는 /root/hwreport.txt 출력파일을 생성합니다.
    - 인벤토리 호스트이름
    - 총 메모리 용량(MB)
    - BIOS 버전
    - 디스크 장치 vda의 크기
    - 디스크 장치 vdb의 크기
- 출력 파일의 각 줄에는 하나의 '키 = 값' 쌍이 포함됩니다.
- http://redhat.example.com/materials/hwreport.txt 에서 hwreport.txt를 /home/admin/ansible에 다운로드합니다.
- /root/hwreport.txt 를 올바른 값으로 수정합니다.
- 해당 항목 값이 없으면 "NONE"이 표시됩니다.

나의 답안:

# 1) hwreport.yml 작성
vi hwreport.yml

---
- name: hwreport
  hosts: all
  vars:
    hw_all:
      - hw_name: HOST
        hw_cont: "{{ inventory_hostname | default('NONE' , true) }}"
      - hw_name: TOTALMEM
        hw_cont: "{{ ansible_memtotal_mb | default('NONE' , true) }}"
      - hw_name: BIOSVER
        hw_cont: "{{ ansible_bios_version | default('NONE' , true) }}"
      - hw_name: vdaSIZE
        hw_cont: "{{ ansible_devices.vda.size | default('NONE' , true) }}"
      - hw_name: vdbSIZE
        hw_cont: "{{ ansible_devices.vdb.size| default('NONE' , true) }}"
  tasks:
    - name: download hwreport.txt
      get_url:
        url: http://redhat.example.com/materials/hwreport.txt
        dest: /root/hwreport.txt

    - name: write hw report
      lineinfile:
        path: /root/hwreport.txt
        regexp: "^{{ item.hw_name }}="
        line: "{{ item.hw_name }}={{ item.hw_cont }}"
      loop: "{{ hw_all }}"

# 2) 실행
ansible-playbook hwreport.yml

# 3) 검증
ansible all -m shell -a "cat /root/hwreport.txt"

14. Ansible Vault Password 생성하기

다음과 같은 password 저장소를 생성합니다.

- 저장소 이름은 /home/admin/ansible/locker.yml 입니다.
- 저장소의 내용은 다음과 같습니다 :
    - pw_developer의 값은 Imadev 입니다.
    - pw_manager의 값은 Imasmgr 입니다.
- 저장소를 암호화 하며 비밀번호는 whenyouwishuponstar 입니다.
- 비밀번호는 /home/admin/ansible/secret.txt 에 저장됩니다.

나의 답안:

# 1) secret.txt 생성
echo "whenyouwishuponstar" > /home/admin/ansible/secret.txt
chmod 0600 /home/admin/ansible/secret.txt

# 2) ansible.cfg에 vault 비밀번호 설정
vi /home/admin/ansible/ansible.cfg
vault_password_file=/home/admin/ansible/secret.txt

# 3) locker.yml 작성 + 암호화
vi locker.yml

pw_developer: Imadev
pw_manager: Imasmgr

ansible-vault encrypt locker.yml

# 4) 검증
ansible-vault view locker.yml

15. User Account 생성하기

http://redhat.example.com/materials/user_list2.yml 를 /home/admin/ansible 에 저장합니다.

locker.yml을 사용하여 /home/admin/ansible/users.yml이라는 플레이북을 생성하여 다음과 같이 유저를 생성합니다.

- 직무가 developer인 사용자는 다음과 같이 구성됩니다 :
    - dev 및 test 호스트 그룹의 관리 노드에서 생성됩니다.
    - pw_developer 변수에서 비밀번호를 할당 받고, 30일 후에 비밀번호가 만료되도록 설정합니다.
    - 부가 그룹 devops의 멤버가 됩니다.
- 직무가 manager인 사용자는 다음과 같이 구성됩니다 :
    - prod 호스트 그룹의 관리 노드에서 생성됩니다.
    - pw_manager 변수에서 비밀번호를 할당 받으며, 30일 후에 비밀번호가 만료 되도록 설정합니다.
    - 부가그룹 opsmgr 멤버가 됩니다.
- 비밀번호는 SHA512 해시 형식입니다.
- /home/admin/ansible/secret.txt를 사용해 작동합니다.

나의 답안:

기존 user_list.yml 내용
---
users:
  - name: AliceJohnson
    job: manager
  - name: BobSmith
    job: developer
  - name: CarolWilliams
    job: manager
  - name: DavidBrown
    job: developer
---
# 1) users.yml 작성
vi users.yml

---
- name: download user_list.yml
  hosts: localhost
  become: true
  tasks:
    - name: download user_list.yml
      get_url:
        url: http://redhat.example.com/materials/user_list.yml
        dest: /home/admin/ansible

- name: create user
  hosts:
    - dev
    - test
  become: true
  vars_files:
    - user_list.yml
    - locker.yml

  tasks:
    - name: Create group for developer
      group:
        name: devops
        state: present

    - name: Create user for developer
      user:
        name: "{{ item.name }}"
        password: "{{ pw_developer | password_hash('sha512') }}"
        groups: devops
        state: present
        password_expire_max: 30
      loop: "{{ users }}"
      when: item.job == "developer"

- name: create user
  hosts: prod
  become: true
  vars_files:
    - user_list.yml
    - locker.yml

  tasks:
    - name: Create group for manager
      group:
        name: opsmgr
        state: present

    - name: Create user for manager
      user:
        name: "{{ item.name }}"
        password: "{{ pw_manager | password_hash('sha512') }}"
        groups: opsmgr
        state: present
        password_expire_max: 30
      loop: "{{ users }}"
      when: item.job == "manager"

# 2) 실행
ansible-playbook users.yml

16. Ansible Vault 비밀번호 재생성(rekey)

기존 ansible vault를 rekey 하십시오.

- http://redhat.example.com/materials/salaries.yml을 /home/admin/ansible 에 다운하십시오.
- 해당 파일의 패스워드는 insecure4sure 입니다.
- 새로운 패스워드는 bbqw3fd980123c 입니다.
- 변경된 패스워드는 유지됩니다.

나의 답안:

cd /home/admin/ansible
wget http://redhat.example.com/materials/salaries.yml
ansible-vault rekey --ask-vault-pass salaries.yml

Vault password:
New Vault password:
Confirm New Vault password:
Rekey Successful

# 검증
ansible-vault view salaries.yml

17. Cron job 생성

다음을 수행하는 /home/admin/ansible/cron.yml의 플레이북을 만드세요.

유저 natasha는 2분마다 logger "EX294 in progress"를 실행하는 크론 작업을 생성합니다.

나의 답안:

vi cron.yml

---
- name: cron job for ansible
  hosts: all
  tasks:
    - name: add cron
      cron:
        name: loggercron
        minute: "*/2"
        user: natasha
        job: logger "EX294 in progress"

ansible-playbook cron.yml
profile
Hello Engineering World

0개의 댓글