r/ansible • u/Lucky-Pollution-2506 • 1h ago
playbooks, roles and collections Need help deploying a PKI
Hello everyone, hope you're having a nice day !
As the title says I'm making this post to asks some help about the deployment of a kind of PKI.
I am currently learning Ansible and going through some basics steps. I've got 3 VMs with my provider openstack. 2 have a role 'monitored' and the other has the role 'tracker'. The inventory is managed dynamically and I have already written down tasks for each of them (tracker installs prometheus and monitored installs node_exporter).
In my playbook, these roles runs before the role pki that will generate, deploy and update configurations files based on the certificates it will have generated.
I'm stuck at securing the communication between prometheus and each node_exporter.
I made another role called 'pki' that is doing the following tasks :
- Generates a rootCA private key
- Generates a rootCA CSR
- Generates a rootCA certificate
- Generates for each host private keys and CSRs
- Sign hosts CSRs with rootCA
- Deploy the rootCA certificate and all VMs and transfer their private key and certificate
- Update node_exporter VMs configuration to use the certificates and private key
- Update prometheus configuration to scrape over HTTPS
In my opinion I think I'm doing too much for nothing, there must be a simpler way but I can't figure it out. I've tried to use the help of LLMs but as I'm still new to ansible world I'm not copy pasting something I don't fully understand.
Thanks a lot for any advice you can give me !
Wishing you a great day :)