How can I install and configure Ansible on an Ubuntu Azure VM using a service principal for authentication?
0 reputation · 18 Jan 2021, 16:34 UTC
0 reputation · 18 Jan 2021, 16:34 UTC
I need to run Ansible playbooks against Azure resources from an Ubuntu 22.04 virtual machine in Azure, authenticating with a service principal instead of interactive login. The setup must ensure that the required Ansible version and the azure.azcollection modules are available, and that the service principal credentials are provided securely without exposing them in plain text or command history.
What are the necessary repository and package steps to install Ansible on Ubuntu 22.04 in an Azure VM? How should I store or pass the service principal credentials (appId, password, tenant, subscription ID) so that Ansible's Azure modules can use them safely? What minimal validation can confirm that Ansible is able to authenticate and manage Azure resources after configuration?
26525 reputation · 19 Jan 2021, 01:25 UTC
This procedure outlines how to set up Ansible on an Ubuntu 22.04 Azure VM and configure it to authenticate to Azure using a service principal. The steps are based on the general guidance for installing Ansible on a Linux virtual machine provided in the Microsoft Learn article (source 1). Because the article does not cover service‑principal handling or the azure.azcollection, the following steps include commonly‑used practices; verify each step in your environment and adjust as needed.
~/.azure/credentials file with appropriate permissions.azure_rm_resourcegroup_info module.sudo apt-get purge -y ansible and delete the pip‑installed collection with pip uninstall azure.azcollection. Remove any credential files or Key Vault secrets you created.These steps assume you have sudo access on the VM and that the Azure CLI (az) is already installed; if not, install it per Microsoft’s documentation before creating the service principal.
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 18 Jan 2021, 19:25 UTC
One correction and one alternative worth flagging.
The collection should be installed with ansible-galaxy collection install azure.azcollection, not pip — pip cannot install Ansible collections. What pip installs is the collection's Python dependencies, typically from its requirements-azure.txt file. Mixing these up is a common source of "module not found" errors after an otherwise successful-looking setup.
Second, since the playbooks run on an Azure VM, consider a system-assigned managed identity instead of a service principal. Enable it on the VM, grant the identity an RBAC role on the target subscription or resource group, and the azure.azcollection modules will authenticate without any stored secret at all. That removes the secret-rotation and credential-file concerns entirely — service principal client secrets expire, and an expired secret tends to surface as an opaque auth failure at the worst time.
If you must use a service principal (e.g., cross-tenant access), prefer least privilege: Contributor is broader than needed for read-only inventory. Verify with ansible-inventory -i azure_rm.yml --list before running real playbooks. Exact env var names and plugin options vary by collection version, so confirm against your installed version via ansible-galaxy collection list.