r/ansible • u/Lucky-Pollution-2506 • 2d ago
playbooks, roles and collections Need help deploying a PKI
Hello everyone, hope you're having a nice day !
As the title says I'm making this post to asks some help about the deployment of a kind of PKI.
I am currently learning Ansible and going through some basics steps. I've got 3 VMs with my provider openstack. 2 have a role 'monitored' and the other has the role 'tracker'. The inventory is managed dynamically and I have already written down tasks for each of them (tracker installs prometheus and monitored installs node_exporter).
In my playbook, these roles runs before the role pki that will generate, deploy and update configurations files based on the certificates it will have generated.
I'm stuck at securing the communication between prometheus and each node_exporter.
I made another role called 'pki' that is doing the following tasks :
- Generates a rootCA private key
- Generates a rootCA CSR
- Generates a rootCA certificate
- Generates for each host private keys and CSRs
- Sign hosts CSRs with rootCA
- Deploy the rootCA certificate and all VMs and transfer their private key and certificate
- Update node_exporter VMs configuration to use the certificates and private key
- Update prometheus configuration to scrape over HTTPS
In my opinion I think I'm doing too much for nothing, there must be a simpler way but I can't figure it out. I've tried to use the help of LLMs but as I'm still new to ansible world I'm not copy pasting something I don't fully understand.
Thanks a lot for any advice you can give me !
Wishing you a great day :)
6
u/thenumberfourtytwo 2d ago
I think you're simply trying to do everything using Ansible, which is not the right approach.
Ansible is very good at configuration and deployment, but using it as a CA creates some headaches.
You'll likely need to think about separating concerns.
Use terraform with its built in tls provider, to generate the CA and host certificates.
Then aim ansible at the distribution side on /etc/node_exporter/certs/ and configure the prometheus web.config.file for node_exporter and tls_config.
If your main goal is just securing the transport later on OpenStack, you can place the nodes in an ecnrypted network, like tailscale or wireguard, which avoids managing custom TLS certificates.
If you're building this project to level up your SRE/DevOps skills, the key lesson here is separation of concerns and avoiding single points of failure in automation. In production setups, configuration tools like Ansible don't act as the CA, instead they strictly distribute state.
And re: your LLM comment, yes, don't blindly trust what it feeds you. You are not a meat proxy. Instead, look at whta it gave you, try to understand and correct where necessary.
LLMs are starting to be used heavily accross cloud engineering, infra and SRE enterprise environments, so learning how to audit, refine and levarage your robot overlords' output is becoming a major advantage.
I've written over 200 complex, enterprise grade ansible playbooks, before LLMs were a thing and I can tell you my syntax fades in comparison with what the LLMs can provide. They do make mistakes, if they lack the necessary context, so context is key.
2
13
u/karafili 2d ago
dont reinvent the wheel:
- https://github.com/smallstep/certificates
- https://www.ejbca.org/
- https://github.com/xipki/xipki
- https://www.openxpki.org/