| OS | Package Manager | Commande |
|---|---|---|
| Ubuntu/Debian | apt |
sudo apt install ansible |
| RHEL/CentOS | dnf/yum |
sudo dnf install ansible |
| macOS | homebrew |
brew install ansible |
| Tout OS | pip |
pip install ansible |
| Requis | Détail |
|---|---|
| SSH | Ouvert et accessible depuis le Control Node |
| Python | Version 2.7+ ou 3.5+ (généralement préinstallé sur Linux) |
| Accès | Compte utilisateur avec permissions suffisantes |
Ubuntu/Debian :
sudo apt update
sudo apt install software-properties-common
sudo add-apt-repository --yes --update ppa:ansible/ansible
sudo apt install ansible
RHEL/CentOS 8+ :
sudo dnf install epel-release
sudo dnf install ansible
pip install ansible
ou pour une version spécifique
pip install ansible==2.15.0
Affiche la version et le chemin d'installation
$ ansible --version
ansible [core 2.15.0]
config file = /etc/ansible/ansible.cfg
collected module name list: ...
python version = 3.10.12 (...) (/usr/bin/python3)
ansible.cfg)ANSIBLE_CONFIG (variable d'environnement)./ansible.cfg (dans le répertoire courant)~/.ansible.cfg (dossier personnel)/etc/ansible/ansible.cfg (fichier global)[defaults]
inventory = ./inventory
remote_user = ansible
host_key_checking = False
timeout = 30
forks = 10
[privilege_escalation]
become = True
become_method = sudo
become_user = root
[ssh_connection]
pipelining = True
control_path = /tmp/ansible-ssh-%%h-%%p-%%r
| Paramètre | Valeur | Explication |
|---|---|---|
inventory |
./inventory |
Chemin vers le fichier d'inventaire |
remote_user |
ansible |
Utilisateur distant par défaut |
host_key_checking |
False |
Désactive la vérification SSH (développement) |
forks |
10 |
Nombre de connexions parallèles simultanées |
timeout |
30 |
Timeout de connexion SSH en secondes |
become |
True |
Active l'élévation de privilège (sudo) par défaut |
pipelining |
True |
Réduit le nombre de connexions SSH (performance) |
[root@lab-ansible ~]# adduser ansible
Changing password for user ansible.
[root@lab-ansible ansible]# passwd ansible
Changing password for user ansible.
New password:
Retype new password:
passwd: all authentication tokens updated successfully.
Création d'une paire de clés ed25519
su - ansible
mkdir .ssh ; chmod 700 .ssh
ssh-keygen -t ed25519 -C "ansible@lab-ansible" -f ~/.ssh/ansible-lab
Generating public/private ed25519 key pair.
Enter passphrase for "/home/ansible/.ssh/ansible-lab" (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/ansible/.ssh/ansible-lab
Your public key has been saved in /home/ansible/.ssh/ansible-lab.pub
The key fingerprint is:
SHA256:VwKTgjzJXCbQKWkkdPZ9SyhxtLAPOGih5zRDCOdz3g8 ansible@lab-ansible
The key's randomart image is:
+--[ED25519 256]--+
|===X.B+oo. |
|o=O %oB +o |
|.+B+.* = o. . |
|.+ *..+ o .o |
| . . E.S.. |
| o . |
| . |
| |
| |
+----[SHA256]-----+
[ansible@lab-ansible ~]$ eval "$(ssh-agent -s)"
Agent pid 1166
[ansible@lab-ansible ~]$ ssh add ~/.ssh/ansible-lab
ssh: Could not resolve hostname add: Name or service not known
[ansible@lab-ansible ~]$ ssh-add ~/.ssh/ansible-lab
Enter passphrase for /home/ansible/.ssh/ansible-lab:
Identity added: /home/ansible/.ssh/ansible-lab (ansible@lab-ansible)
Copie de la clé publique sur les serveurs cibles
ssh-copy-id -i ~/.ssh/ansible-lab.pub ansible@ansible-target01.lxd.stef.lan
/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/home/ansible/.ssh/ansible-lab.pub"
The authenticity of host 'ansible-target01.lxd.stef.lan (10.220.21.159)' can't be established.
ED25519 key fingerprint is SHA256:B+sgBCQ9I7REI2hsYtX8CZzMOs0iP/5S7eUZJad+ldM.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
ansible@ansible-target01.lxd.stef.lan's password:
Number of key(s) added: 1
Now try logging into the machine, with: "ssh -i /home/ansible/.ssh/ansible-lab 'ansible@ansible-target01.lxd.stef.lan'"
and check to make sure that only the key(s) you wanted were added.
/etc/ansible/hosts ou ./inventory
Groupe webserveursbash
Vérifie l'accès SSH sans mot de passe
ssh -i ~/.ssh/ansible-lab 'ansible@ansible-target01.lxd.stef.lan'
Last login: Mon Aug 10 22:18:43 2026 from 10.220.21.188
[ansible@ansible-target01 ~]$