验证集合
使用 ansible-galaxy 验证集合
安装完成后,您可以验证已安装集合的内容是否与服务器上的集合内容一致。此功能要求集合安装在配置的集合路径之一中,并且该集合存在于配置的 galaxy 服务器之一上。
ansible-galaxy collection verify my_namespace.my_collection
ansible-galaxy collection verify 命令在执行成功时不会有输出。如果集合已被修改,被更改的文件将列在集合名称下方。
ansible-galaxy collection verify my_namespace.my_collection
Collection my_namespace.my_collection contains modified content in the following files:
my_namespace.my_collection
plugins/inventory/my_inventory.py
plugins/modules/my_module.py
您可以使用 -vvv 标志来显示更多信息,例如已安装集合的版本和路径、用于验证的远程集合 URL 以及验证成功的输出结果。
ansible-galaxy collection verify my_namespace.my_collection -vvv
...
Verifying 'my_namespace.my_collection:1.0.0'.
Installed collection found at '/path/to/ansible_collections/my_namespace/my_collection/'
Remote collection found at 'https://galaxy.ansible.com/download/my_namespace-my_collection-1.0.0.tar.gz'
Successfully verified that checksums for 'my_namespace.my_collection:1.0.0' match the remote collection
如果您安装的是预发布版本或非最新版本的集合,应指定具体版本进行验证。如果省略版本号,则将使用服务器上可用的最新版本来验证已安装的集合。
ansible-galaxy collection verify my_namespace.my_collection:1.0.0
除了使用 namespace.collection_name:version 格式外,您还可以通过 requirements.yml 文件提供要验证的集合。requirements.yml 中列出的依赖项不包含在 verify 过程中,应单独进行验证。
ansible-galaxy collection verify -r requirements.yml
不支持针对 tar.gz 文件进行验证。如果您的 requirements.yml 包含 tar 文件的路径或安装 URL,您可以使用 --ignore-errors 标志,以确保文件中所有使用 namespace.name 格式的集合都能被处理。
验证已签名的集合
如果集合由 发行服务器 (distribution server) 签名,服务器将提供 ASCII 铠甲 (ASCII armored) 形式的独立签名,用于在利用 MANIFEST.json 验证集合内容之前,先验证 MANIFEST.json 的真实性。此选项并非在所有发行服务器上都可用。请参阅 分发集合 以查看支持集合签名的服务器列表。有关在安装时如何验证已签名集合的信息,请参阅 安装带有签名验证的集合。
验证已安装的签名集合
ansible-galaxy collection verify my_namespace.my_collection --keyring ~/.ansible/pubring.kbx
使用 --signature 选项,通过额外的签名来验证在命令行界面 (CLI) 中提供的集合名称。此选项可以使用多次以提供多个签名。
ansible-galaxy collection verify my_namespace.my_collection --signature https://examplehost.com/detached_signature.asc --signature file:///path/to/local/detached_signature.asc --keyring ~/.ansible/pubring.kbx
此外,您还可以使用 requirements.yml 文件来验证集合签名。
ansible-galaxy collection verify -r requirements.yml --keyring ~/.ansible/pubring.kbx
当从发行服务器安装集合时,服务器提供的用于验证集合真实性的签名将与已安装的集合一起保存。当提供 --offline 选项时,这些数据将被用于验证集合的内部一致性,而无需再次查询发行服务器。
ansible-galaxy collection verify my_namespace.my_collection --offline --keyring ~/.ansible/pubring.kbx