ansible ssh to json_query 循环中的响应值

ansible ssh to json_query response values in loop

团队,我收到了来自 json_query 的回复,这是一个字典 key:value,我想遍历所有值和 运行 每个值的 ssh 命令

下面是我所有节点的列表

- name: "Fetch all nodes from clusters using K8s facts"
k8s_facts:
  kubeconfig: $WORKSPACE
  kind: Node
  verify_ssl: no
register: node_list

- debug:
  var: node_list | json_query(query)
vars:
  query: 'resources[].{node_name: metadata.name, nodeType: metadata.labels.nodeType}'

任务[3_validations_on_ssh:调试]

ok: [target1] => {
    "node_list | json_query(query)": [
        {
            "nodeType": null,
            "node_name": "host1"
        },
        {
            "nodeType": "gpu",
            "node_name": "host2"
        },
        {
            "nodeType": "gpu",
            "node_name": "host3"
        }
    ]
}

要编写的剧本:解析 node_name 并在所有主机 1-3

的 ssh 命令中使用它

- name: "Loop on all nodeNames and ssh."
shell: ssh -F ~/.ssh/ssh_config bouncer@{{ item }}.internal.sshproxy.net "name -a"
register: ssh_result_per_host
failed_when: ssh_result_per_host.rc != 0
with_item: {{ for items in query.node_name }}
- debug:
  var: ssh_result_per_host.stdout_lines

错误输出:

> The offending line appears to be:
        failed_when: ssh_result_per_host.rc != 0
        with_item: {{ for items in query.node_name }}
                    ^ here

当我循环时,解决方案 2 也失败了:

          shell: ssh -F ~/.ssh/ssh_config bouncer@{{ item.metadata.name }}.sshproxy.internal.net "name -a"
        loop: "{{ node_list.resources }}"
        loop_control:
          label: "{{ item.metadata.name }}"

输出溶胶 2:

failed: [target1] (item=host1) => {"msg": "Invalid options for debug: shell"}
failed: [target1] (item=host2) => {"msg": "Invalid options for debug: shell"}
fatal: [target1]: FAILED! => {"msg": "All items completed"}

不是with_item而是with_items
您不能使用 with_item: {{ for items in query.node_name }} 将值保存到变量并在 with_items: {{ new_variable }}

中使用该变量

扩展 Ash 的正确答案:

  - name: "Fetch all nodes from clusters using K8s facts"
    k8s_facts:
      kubeconfig: $WORKSPACE
      kind: Node
      verify_ssl: no
    register: node_list

  - set_fact:
      k8s_node_names: '{{ node_list | json_query(query) | map(attribute="node_name") | list }}'
    vars:
      query: 'resources[].{node_name: metadata.name, nodeType: metadata.labels.nodeType}'

  - name: "Loop on all nodeNames and ssh."
    shell: ssh -F ~/.ssh/ssh_config bouncer@{{ item }}.internal.sshproxy.net "name -a"
    register: ssh_result_per_host
    with_items: '{{ k8s_node_names }}'

另外,除非你真的只是想 运行 那个 one ssh 命令,ansible 思考这个问题的方式是通过 add_host::

- hosts: localhost
  connection: local
  gather_facts: no
  tasks:
  # ... as before, to generate the  "k8s_node_names" list
  - add_host:
      hostname: '{{ item }}.internal.sshproxy.net'
      groups:
      - the_k8s_nodes
      ansible_ssh_username: bouncer
      # whatever other per-host variables you want
    with_items: '{{ k8s_node_names }}'

# now, run the playbook against those nodes
- hosts: the_k8s_nodes
  tasks:
  - name: run "name -a" on the host
    command: name -a
    register: whatever

这是一个人为的例子,因为如果你真的只想获取 kubernetes 节点列表并在剧本中使用这些节点,你可以使用 a dynamic inventory script