文章目录
- 1.saltstack模块介绍
- 2. SaltStack常用模块
- 2.1 SaltStack常用模块之network
- 2.1.1 network.active_tcp
- 2.1.2 network.calc_net
- 2.1.3 network.connect
- 2.1.4 network.default_route
- 2.1.5 network.get_fqdn
- 2.1.6 network.get_hostname
- 2.1.7 network.get_route
- 2.1.8 network.hw_addr
- 2.1.9 network.ifacestartswith
- 2.1.10 network.in_subnet
- 2.1.11 network.interface
- 2.1.12 network.interface_ip
- 2.1.13 network.interfaces
- 2.1.14 network.ip_addrs
- 2.1.15 network.netstat
- 2.1.17 network.reverse_ip
- 2.2 SaltStack常用模块之service
- 2.3 SaltStack常用模块之pkg
- 2.4 SaltStack常用模块之state
- 2.5 SaltStack常用模块之user
- 2.5 SaltStack常用模块之salt-cp
- 2.6 SaltStack常用模块之file
- 2.6.1 file.access
- 2.6.2 file.append
- 2.6.3 file.basename
- 2.6.4 file.dirname
- 2.6.5 file.check_hash
- 2.6.6 file.chattr
- 2.7.7 file.chown
- 2.7.8 file.copy
- 2.7.9 file.directory_exists
- 2.7.10 file.diskusage
- 2.7.11 file.file_exists
- 2.7.12 file.find
- 2.7.13 file.get_gid
- 2.7.14 file.get_group
- 2.7.15 file.get_hash
- 2.7.16 file.get_mode
- 2.7.17 file.get_selinux_context
- 2.7.18 file.get_sum
- 2.7.19 file.get_uid与file.get_user
- 2.7.20 file.gid_to_group
- 2.7.22 file.user_to_uid
- 2.7.23 file.uid_to_user
- 2.7.24 file.grep
- 2.7.25 file.is_blkdev
- 2.7.26 file.lsattr
- 2.7.27 file.mkdir
- 2.7.28 file.move
- 2.7.29 file.prepend
1.saltstack模块介绍
Module是日常使用SaltStack接触最多的一个组件,其用于管理对象操作,这也是SaltStack通过Push的方式进行管理的入口,比如我们日常简单的执行命令、查看包安装情况、查看服务运行情况等工作都是通过SaltStack Module来实现的。
当安装好Master和Minion包后,系统上会安装很多Module,大家可以通过以下命令查看支持的所有Module列表:
//查看所有module列表
[root@master ~]# salt 'minion' sys.list_modules
minion:
- acl
- aliases
- alternatives
- apache
- archive
- artifactory
- at
- .....后面省略
// 查看指定模块的函数
[root@master ~]# salt 'minion' sys.list_functions cmd
minion:
- cmd.exec_code
- cmd.exec_code_all
- cmd.has_exec
- cmd.powershell
- cmd.powershell_all
- cmd.retcode
- cmd.run
- cmd.run_all
- cmd.run_bg
- cmd.run_chroot
- cmd.run_stderr
- cmd.run_stdout
- cmd.script
- cmd.script_retcode
- cmd.shell
- cmd.shell_info
- cmd.shells
- cmd.tty
- cmd.which
- cmd.which_bin
//查看指定模块的用法
[root@master ~]# salt 'minion' sys.doc cmd
cmd.exec_code:
Pass in two strings, the first naming the executable language, aka -
python2, python3, ruby, perl, lua, etc. the second string containing
the code you wish to execute. The stdout will be returned.
All parameters from :mod:`cmd.run_all <salt.modules.cmdmod.run_all>` except python_shell can be used.
...此处省略N行...
//SaltStack默认也支持一次执行多个Module,Module之间通过逗号隔开,默认传参之间也是用逗号分隔,也支持指定传参分隔符号--args-separator=@即可
[root@master ~]# salt 'minion' test.echo,cmd.run,service.status hello,date,sshd
minion:
----------
cmd.run:
Wed Nov 3 15:46:50 CST 2021
service.status:
True
test.echo:
hello
2. SaltStack常用模块
2.1 SaltStack常用模块之network
2.1.1 network.active_tcp
返回所建立的tcp连接
[root@master ~]# salt 'minion' network.active_tcp
minion:
----------
0:
----------
local_addr:
192.168.101.120
local_port:
60160
remote_addr:
192.168.101.110
remote_port:
4505
1:
----------
local_addr:
192.168.101.120
local_port:
22
remote_addr:
192.168.101.1
remote_port:
53929
2:
----------
local_addr:
192.168.101.120
local_port:
22
remote_addr:
192.168.101.1
remote_port:
53930
2.1.2 network.calc_net
通过IP和子网掩码计算出网段
[root@master ~]# salt 'minion' network.calc_net 192.168.101.120 255.255.248.0
minion:
192.168.96.0/21
2.1.3 network.connect
测试minion至某一台服务器的网络是否连通
[root@master ~]# salt 'minion' network.connect baidu.com 80
minion:
----------
comment:
Successfully connected to baidu.com (220.181.38.148) on tcp port 80
result:
True
[root@master ~]# salt 'minion' network.connect 192.168.101.110 80
minion:
----------
comment:
Successfully connected to 192.168.101.110 (192.168.101.110) on tcp port 80
result:
True
2.1.4 network.default_route
查看默认路由
[root@master ~]# salt 'minion' network.default_route
minion:
|_
----------
addr_family:
inet
destination:
0.0.0.0
flags:
UG
gateway:
192.168.101.2
interface:
ens33
netmask:
0.0.0.0
|_
----------
addr_family:
inet6
destination:
::/0
flags:
!n
gateway:
::
interface:
lo
netmask:
|_
----------
addr_family:
inet6
destination:
::/0
flags:
!n
gateway:
::
interface:
lo
netmask:
2.1.5 network.get_fqdn
查看主机的fqdn(完全限定域名)
[root@master ~]# salt 'minion' network.get_fqdn
minion:
minion
2.1.6 network.get_hostname
获取主机名
[root@master ~]# salt 'minion' network.get_hostname
minion:
minion
2.1.7 network.get_route
查询到一个目标网络的路由信息
[root@master ~]# salt 'minion' network.get_route 192.168.101.210
minion:
----------
destination:
192.168.101.210
gateway:
None
interface:
ens33
source:
192.168.101.120
2.1.8 network.hw_addr
返回指定网卡的MAC地址
[root@master ~]# salt 'minion' network.hw_addr ens33
minion:
00:0c:29:f0:e5:49
2.1.9 network.ifacestartswith
从特定CIDR检索接口名称
[root@master ~]# salt 'minion' network.ifacestartswith 192.168
minion:
- ens33
- virbr0
2.1.10 network.in_subnet
判断当前主机是否在某一个网段内
[root@master ~]# salt 'minion' network.in_subnet 192.168.101.0/24
minion:
True
2.1.11 network.interface
返回指定网卡的信息
[root@master ~]# salt 'minion' network.interface ens33
minion:
|_
----------
address:
192.168.101.120
broadcast:
192.168.101.255
label:
ens33
netmask:
255.255.255.0
2.1.12 network.interface_ip
返回指定网卡的IP地址
[root@master ~]# salt 'minion' network.interface_ip ens33
minion:
192.168.101.120
2.1.13 network.interfaces
返回当前系统中所有的网卡信息
[root@master ~]# salt 'minion' network.interfaces
minion:
----------
ens33:
----------
hwaddr:
00:0c:29:f0:e5:49
inet:
|_
----------
address:
192.168.101.120
broadcast:
192.168.101.255
label:
ens33
netmask:
255.255.255.0
inet6:
|_
----------
address:
fe80::45d1:1ca8:5c61:6479
prefixlen:
64
scope:
link
up:
True
lo:
----------
hwaddr:
00:00:00:00:00:00
inet:
|_
----------
address:
127.0.0.1
broadcast:
None
label:
lo
netmask:
255.0.0.0
inet6:
|_
----------
address:
::1
prefixlen:
128
scope:
host
up:
True
virbr0:
----------
hwaddr:
52:54:00:a7:19:59
inet:
|_
----------
address:
192.168.122.1
broadcast:
192.168.122.255
label:
virbr0
netmask:
255.255.255.0
up:
True
virbr0-nic:
----------
hwaddr:
52:54:00:a7:19:59
up:
False
2.1.14 network.ip_addrs
返回一个IPv4的地址列表
该函数将会忽略掉127.0.0.1的地址
[root@master ~]# salt 'minion' network.ip_addrs
minion:
- 192.168.101.120
- 192.168.122.1
2.1.15 network.netstat
返回所有打开的端口和状态
[root@master ~]# salt ‘minion’ network.netstat
minion:
|_
----------
inode:
2004
local-address:
0.0.0.0:111
program:
1/systemd
proto:
tcp
recv-q:
0
remote-address:
0.0.0.0:*
send-q:
0
state:
LISTEN
user:
0
|_
----------
inode:
40365
local-address:
192.168.122.1:53
program:
1970/dnsmasq
....后面省略
2.1.16 network.ping
使用ping命令测试到某主机的连通性
[root@master ~]# salt 'minion' network.ping baidu.com
minion:
PING baidu.com (220.181.38.148) 56(84) bytes of data.
64 bytes from 220.181.38.148 (220.181.38.148): icmp_seq=2 ttl=128 time=567 ms
64 bytes from 220.181.38.148 (220.181.38.148): icmp_seq=3 ttl=128 time=647 ms
64 bytes from 220.181.38.148 (220.181.38.148): icmp_seq=4 ttl=128 time=59.3 ms
--- baidu.com ping statistics ---
4 packets transmitted, 3 received, 25% packet loss, time 7928ms
rtt min/avg/max/mdev = 59.274/424.571/647.158/260.354 ms
2.1.17 network.reverse_ip
返回一个指定的IP地址的反向地址
[root@master ~]# salt 'minion' network.reverse_ip 192.168.101.120
minion:
120.101.168.192.in-addr.arpa
2.2 SaltStack常用模块之service
2.2.1 service.available
判断指定的服务是否可用
[root@master ~]# salt 'minion' service.available httpd
minion:
True
[root@master ~]# salt 'minion' service.available nginx
minion:
False
2.2.2 service.get_all
获取所有正在运行的服务
[root@master ~]# salt 'minion' service.get_all
minion:
- ModemManager
- NetworkManager
- NetworkManager-dispatcher
- NetworkManager-wait-online
- accounts-daemon
- alsa-restore
- alsa-state
- anaconda
- anaconda-direct
- anaconda-fips
- anaconda-nm-config
- anaconda-noshell
......后面省略
2.2.3 service.disabled
检查指定服务是否开机不自动启动
[root@master ~]# salt 'minion' service.disabled httpd
minion:
False
2.2.4 service.enabled
检查指定服务是否开机自动启动
[root@master ~]# salt 'minion' service.enabled httpd
minion:
True
2.2.5 service.disable
设置指定服务开机不自动启动
[root@master ~]# salt 'minion' service.disable httpd
minion:
True
2.2.6 service.enable
设置指定服务开机自动启动
[root@master ~]# salt 'minion' service.enable httpd
minion:
True
2.2.7 service.reload
重新加载指定服务
[root@master ~]# salt 'minion' service.reload httpd
minion:
True
2.2.8 service.stop
停止指定服务
[root@master ~]# salt 'minion' service.stop httpd
minion:
True
2.2.9 service.start
启动指定服务
[root@master ~]# salt 'minion' service.start httpd
minion:
True
2.2.10 service.restart
重启指定服务
[root@master ~]# salt 'minion' service.restart httpd
minion:
True
2.2.11 service.status
查看指定服务的状态
[root@master ~]# salt 'minion' service.status httpd
minion:
True
2.2.12 service.missing
服务的反面。如果命名的服务不可用,则返回真实。
[root@master ~]# salt '*' service.missing httpd
master:
False
minion:
False
node2:
True
2.3 SaltStack常用模块之pkg
2.3.1 pkg.download
只下载软件包但不安装
此功能将会下载指定的软件包,但是需要在minion端安装yum-utils,可以使用 cmd.run 进行远程安装
[root@master ~]# salt 'minion' pkg.download make
minion:
----------
make:
/var/cache/yum/packages/make-4.2.1-11.el8.x86_64.rpm //下载好的软件放在这里
2.3.2 pkg.file_list
列出指定包或系统中已安装的所有包的文件
//列出已安装的apache软件包提供的所有文件
[root@master ~]# salt 'minion' pkg.file_list httpd
minion:
----------
errors:
files:
- /etc/httpd/conf
- /etc/httpd/conf.d/autoindex.conf
- /etc/httpd/conf.d/userdir.conf
- /etc/httpd/conf.d/welcome.conf
- /etc/httpd/conf.modules.d
- /etc/httpd/conf.modules.d/00-base.conf
- /etc/httpd/conf.modules.d/00-dav.conf
- /etc/httpd/conf.modules.d/00-lua.conf
- /etc/httpd/conf.modules.d/00-mpm.conf
- /etc/httpd/conf.modules.d/00-optional.conf
- /etc/httpd/conf.modules.d/00-proxy.conf
- /etc/httpd/conf.modules.d/00-systemd.conf
- /etc/httpd/conf.modules.d/01-cgi.conf
....后面省略
//当不提供参数时,将会列出当前系统中所有已安装软件的文件列表
[root@master ~]# salt 'minion' pkg.file_list
minion:
----------
errors:
files:
- /lib/kbd/keymaps/legacy
- /lib/kbd/keymaps/legacy/amiga
- /lib/kbd/keymaps/legacy/amiga/amiga-de.map.gz
- /lib/kbd/keymaps/legacy/amiga/amiga-us.map.gz
- /lib/kbd/keymaps/legacy/atari
- /lib/kbd/keymaps/legacy/atari/atari-de.map.gz
- /lib/kbd/keymaps/legacy/atari/atari-se.map.gz
- /lib/kbd/keymaps/legacy/atari/atari-uk-falcon.map.gz
- /lib/kbd/keymaps/legacy/atari/atari-us.map.gz
- /lib/kbd/keymaps/legacy/i386
- /lib/kbd/keymaps/legacy/i386/azerty
- /lib/kbd/keymaps/legacy/i386/azerty/azerty.map.gz
- /lib/kbd/keymaps/legacy/i386/azerty/be-latin1.map.gz
- /lib/kbd/keymaps/legacy/i386/azerty/fr-latin0.map.gz
- /lib/kbd/keymaps/legacy/i386/azerty/fr-latin1.map.gz
- /lib/kbd/keymaps/legacy/i386/azerty/fr-latin9.map.gz
2.3.3 pkg.group_info
查看包组的信息
[root@master ~]# salt 'minion' pkg.group_info "Development Tools"
minion:
----------
conditional:
default:
- asciidoc
- byacc
- ctags
- diffstat
- elfutils-libelf-devel
- git
- intltool
- jna
- ltrace
- patchutils
- perl-Fedora-VSP
- perl-Sys-Syslog
- perl-generators
- pesign
- source-highlight
- systemtap
- valgrind
- valgrind-devel
description:
A basic development environment.
group:
Development Tools
id:
None
mandatory:
- autoconf
- automake
- binutils
- bison
- flex
- gcc
- gcc-c++
- gdb
- glibc-devel
- libtool
- make
- pkgconf
- pkgconf-m4
- pkgconf-pkg-config
- redhat-rpm-config
- rpm-build
- rpm-sign
- strace
optional:
- cmake
- expect
- rpmdevtools
- rpmlint
type:
package group
2.3.4 pkg.group_list
列出系统中所有的包组
[root@master ~]# salt 'minion' pkg.group_list
minion:
----------
available:
- Backup Client
- Conflicts AppStream
- Debugging Tools
- Desktop Debugging and Performance Tools
- .NET Core Development
- FTP Server
- GNOME Applications
- Graphics Creation Tools
- Guest Agents
- Internet Applications
- Java Platform
- Legacy X Window System Compatibility
- Office Suite and Productivity
- Atomic Host ostree support
- KVM platform specific packages
- Hyper-v platform specific packages
- Remote Desktop Clients
- RPM Development Tools
- TeX formatting system
- Virtualization Client
- Virtualization Hypervisor
- Virtualization Platform
- Virtualization Tools
- Basic Web Server
- Additional Development
- Anaconda tools
- Base
- Conflicts BaseOS
- Development Tools
......后面省略
2.3.5 pkg.install
安装软件
[root@master ~]# salt 'minion' pkg.install make
minion:
----------
make:
----------
new:
1:4.2.1-11.el8
old:
2.3.6 pkg.list_downloaded
列出已下载到本地的软件包
[root@master ~]# salt 'minion' pkg.list_downloaded
minion:
----------
2.3.7 pkg.list_pkgs
以字典的方式列出当前已安装的软件包
[root@master ~]# salt 'minion' pkg.list_pkgs
minion:
----------
GConf2:
3.2.6-22.el8
ModemManager:
1.10.8-2.el8
ModemManager-glib:
1.10.8-2.el8
NetworkManager:
1:1.30.0-0.3.el8
NetworkManager-adsl:
1:1.30.0-0.3.el8
NetworkManager-bluetooth:
1:1.30.0-0.3.el8
NetworkManager-config-server:
1:1.30.0-0.3.el8
NetworkManager-libnm:
......后面省略
2.3.8 pkg.owner
列出指定文件是由哪个包提供的
[root@master ~]# salt 'minion' pkg.owner /usr/sbin/apachectl
minion:
httpd
[root@master ~]# salt 'minion' pkg.owner /usr/sbin/apachectl /etc/httpd/conf/httpd.conf
minion:
----------
/etc/httpd/conf/httpd.conf:
httpd
/usr/sbin/apachectl:
httpd
2.3.9 pkg.remove
卸载指定软件
[root@master ~]# salt 'minion' cmd.run 'rpm -qa|grep make'
minion:
make-4.2.1-11.el8.x86_64
[root@master ~]# salt 'minion' pkg.remove make
minion:
----------
make:
----------
new:
old:
1:4.2.1-11.el8
//若要卸载多个文件,中间需要用逗号隔开
2.3.10 pkg.upgrade
升级系统中所有的软件包或升级指定的软件包
[root@master ~]# salt 'minion' pkg.upgrade name=openssl
minion:
----------
openssl:
----------
new:
1:1.1.1k-4.el8
old:
1:1.1.1g-11.el8
openssl-libs:
----------
new:
1:1.1.1k-4.el8
old:
1:1.1.1g-11.el8
2.3.11 pkg.version
查看版本
[root@master ~]# salt 'minion' pkg.version httpd
minion:
2.4.37-40.module_el8.5.0+852+0aafc63b
2.4 SaltStack常用模块之state
2.4.1 state.show_highstate
显示当前系统中有哪些高级状态
[root@master ~]# salt 'minion' state.show_highstate
minion:
----------
apache-install:
----------
__env__:
base
__sls__:
web.apache.install
pkg:
|_
----------
name:
httpd
- installed
|_
----------
order:
10000
apache-service:
----------
__env__:
base
__sls__:
web.apache.install
service:
|_
----------
name:
httpd
|_
----------
enable:
True
- running
|_
----------
order:
10001
2.4.2 state.highstate
执行高级状态
[root@master ~]# salt 'minion' state.highstate
minion:
----------
ID: apache-install
Function: pkg.installed
Name: httpd
Result: True
Comment: All specified packages are already installed
Started: 17:47:30.334844
Duration: 1576.814 ms
Changes:
----------
ID: apache-service
Function: service.running
Name: httpd
Result: True
Comment: The service httpd is already running
Started: 17:47:31.942752
Duration: 44.762 ms
Changes:
Summary for minion
------------
Succeeded: 2
Failed: 0
------------
Total states run: 2
Total run time: 1.622 s
2.4.3 state.show_state_usage
显示当前系统中的高级状态执行情况
[root@master ~]# salt 'minion' state.show_state_usage
minion:
----------
base:
----------
count_all:
3
count_unused:
2
count_used:
1
unused:
- database.mariadb.install
- top
used:
- web.apache.install
dev:
----------
count_all:
0
count_unused:
0
count_used:
0
unused:
used:
prod:
----------
count_all:
0
count_unused:
0
count_used:
0
unused:
used:
test:
----------
count_all:
0
count_unused:
0
count_used:
0
unused:
used:
2.4.4 state.show_top
返回minion将用于highstate的顶级数据
[root@master ~]# salt 'minion' state.show_top
minion:
----------
base:
- web.apache.install
2.4.5 state.top
执行指定的top file,而不是默认的
[root@master ~]# salt 'minion' state.top top.sls
minion:
----------
ID: apache-install
Function: pkg.installed
Name: httpd
Result: True
Comment: All specified packages are already installed
Started: 17:50:24.582561
Duration: 1570.327 ms
Changes:
----------
ID: apache-service
Function: service.running
Name: httpd
Result: True
Comment: The service httpd is already running
Started: 17:50:26.154407
Duration: 49.025 ms
Changes:
Summary for minion
------------
Succeeded: 2
Failed: 0
------------
Total states run: 2
Total run time: 1.619 s
2.4.6 state.show_sls
显示 master 上特定sls或sls文件列表中的状态数据
[root@master ~]# salt 'minion' state.show_sls web.apache.install
minion:
----------
apache-install:
----------
__env__:
base
__sls__:
web.apache.install
pkg:
|_
----------
name:
httpd
- installed
|_
----------
order:
10000
apache-service:
----------
__env__:
base
__sls__:
web.apache.install
service:
|_
----------
name:
httpd
|_
----------
enable:
True
- running
|_
----------
order:
10001
2.5 SaltStack常用模块之user
2.5.1 user.add
user.add:在minion端上创建一个用户。
[root@master ~]# salt 'minion' user.add jtluo
minion:
True
2.5.2 user.info
返回用户信息。
[root@master ~]# salt 'minion' user.info jtluo
minion:
----------
fullname:
gid:
1002
groups:
- jtluo
home:
/home/jtluo
homephone:
name:
jtluo
other:
passwd:
x
roomnumber:
shell:
/bin/bash
uid:
1002
workphone:
2.5.3 user.getent
返回所有系统用户信息的列表
[root@master ~]# salt 'minion' user.getent
minion:
|_
----------
fullname:
root
gid:
0
groups:
- root
home:
/root
homephone:
name:
root
other:
passwd:
x
roomnumber:
shell:
/bin/bash
uid:
0
workphone:
|_
----------
fullname:
bin
gid:
1
groups:
- bin
home:
/bin
......后面省略
2.5.4 user.chgid
修改用户Gid
[root@master ~]# salt 'minion' cmd.run 'id jtluo'
minion:
uid=1002(jtluo) gid=1002(jtluo) groups=1002(jtluo)
[root@master ~]# salt 'minion' user.chgid 'jtluo' 1001
minion:
True
[root@master ~]# salt 'minion' cmd.run 'id jtluo'
minion:
uid=1002(jtluo) gid=1001(abb) groups=1001(abb)
2.5.5 user.chuid
修改用户UID
[root@master ~]# salt 'minion' cmd.run 'id jtluo'
minion:
uid=1002(jtluo) gid=1001(abb) groups=1001(abb)
[root@master ~]# salt 'minion' user.chuid 'jtluo' 1003
minion:
True
[root@master ~]# salt 'minion' cmd.run 'id jtluo'
minion:
uid=1003(jtluo) gid=1001(abb) groups=1001(abb)
2.5.6 user.list_groups
列出指定用户所属组的列表。
[root@master ~]# salt 'minion' user.list_groups jtluo
minion:
- abb
2.5.7 user.rename
修改指定用户的用户名
[root@master ~]# salt 'minion' user.rename jtluo luojiatian
minion:
False //虽然返回False但是操作是成功完成了的
[root@master ~]# salt 'minion' user.info luojiatian
minion:
----------
fullname:
gid:
1001
groups:
- abb
home:
/home/jtluo
homephone:
name:
luojiatian
other:
passwd:
x
roomnumber:
shell:
/bin/bash
uid:
1003
workphone:
user.delete
在minion端删除一个用户
[root@master ~]# salt 'minion' user.delete luojiatian
minion:
True
2.5 SaltStack常用模块之salt-cp
salt-cp能够很方便的把 master 上的文件批量传到 minion上
//拷贝单个文件到目标主机的/usr/src目录下
[root@master ~]# salt 'minion' cmd.run 'ls /usr/src/'
minion:
debug
kernels
[root@master ~]# salt-cp 'minion' /etc/passwd /usr/src/
minion:
----------
/usr/src/passwd:
True
[root@master ~]# salt 'minion' cmd.run 'ls /usr/src/'
minion:
debug
kernels
passwd
//拷贝多个文件到目标主机的/usr/src目录下
[root@master ~]# salt-cp 'minion' /etc/shadow /etc/group /usr/src
minion:
----------
/usr/src/group:
True
/usr/src/shadow:
True
[root@master ~]# salt 'minion' cmd.run 'ls /usr/src/'
minion:
debug
group
kernels
passwd
shadow
2.6 SaltStack常用模块之file
2.6.1 file.access
检查指定路径是否存在
[root@master ~]# salt 'minion' cmd.run 'ls /usr/src/'
minion:
debug
group
kernels
passwd
shadow
//存在时
[root@master ~]# salt 'minion' file.access /usr/src/passwd f
minion:
True
//不存在时
[root@master ~]# salt 'minion' file.access /usr/src/abc f
minion:
False
检查指定文件的权限信息
[root@master ~]# salt 'minion' cmd.run 'ls -l /usr/src/'
minion:
total 12
drwxr-xr-x. 2 root root 6 May 19 2020 debug
-rw-r--r--. 1 root root 1007 Nov 4 15:51 group
drwxr-xr-x. 2 root root 6 May 19 2020 kernels
-rw-r--r--. 1 root root 2672 Nov 4 15:50 passwd
-rw-r--r--. 1 root root 1372 Nov 4 15:51 shadow
[root@master ~]# salt 'minion' file.access /usr/src/passwd r //是否有读权限
minion:
True
[root@master ~]# salt 'minion' file.access /usr/src/passwd w //是否有写权限
minion:
True
[root@master ~]# salt 'minion' file.access /usr/src/passwd x //是否有执行权限
minion:
False
2.6.2 file.append
往一个文件里追加内容,若此文件不存在则会报异常
[root@master ~]# salt 'minion' cmd.run 'ls /opt/'
minion:
jtluo
[root@master ~]# salt 'minion' file.append /opt/jtluo "aabb" "accd" "sadaf"
minion:
Wrote 3 lines to "/opt/jtluo"
[root@master ~]# salt 'minion' cmd.run 'cat /opt/jtluo'
minion:
aabb
accd
sadaf
2.6.3 file.basename
获取指定路径的基名
[root@master ~]# salt 'minion' file.basename /opt/jtluo
minion:
jtluo
2.6.4 file.dirname
获取指定路径的目录名
[root@master ~]# salt 'minion' file.dirname /usr/src/passwd
minion:
/usr/src
2.6.5 file.check_hash
检查指定的文件与hash字符串是否匹配,匹配则返回 True 否则返回 False
[root@master ~]# salt 'minion' cmd.run 'md5sum /etc/passwd'
minion:
3ad206aa2aa36774a8f7467eaa71ce54 /etc/passwd
[root@master ~]# salt 'minion' file.check_hash /etc/passwd 3ad206aa2aa36774a8f7467eaa71ce54
minion:
True
[root@master ~]# salt 'minion' file.check_hash /etc/passwd 3ad206aa2aa36774a8f7467eaa71ce55
minion:
False
2.6.6 file.chattr
修改指定文件的属性
属性 | 对文件的意义 | 对目录的意义 |
---|---|---|
a | 只允许在这个文件之后追加数据,不允许任何进程覆盖或截断这个文件 | 只允许在这个目录下建立和修改文件,而不允许删除任何文件 |
i | 不允许对这个文件进行任何的修改,不能删除、更改、移动 | 任何的进程只能修改目录之下的文件,不允许建立和删除文件给指定文件添加属性 |
# 查看文件本来的属性
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/jtluo"
minion:
-------------------- /opt/jtluo
# 给指定文件添加属性
[root@master ~]# salt 'minion' file.chattr /opt/jtluo operator=add attributes=ai
minion:
True
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/jtluo"
minion:
----ia-------------- /opt/jtluo
//尝试覆盖/opt/test.sh文件的内容
[root@master ~]# salt 'minion' cmd.run "echo '123' > /opt/jtluo"
minion:
/bin/sh: /opt/jtluo: Operation not permitted(操作不允许)
ERROR: Minions returned with non-zero exit code
//尝试删除
[root@master ~]# salt 'minion' cmd.run "rm -rf /opt/jtluo"
minion:
rm: cannot remove '/opt/jtluo': Operation not permitted
ERROR: Minions returned with non-zero exit code
给目录添加属性
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/"
minion:
-------------------- /opt/
[root@master ~]# salt 'minion' file.chattr /opt/ operator=add attributes=ai
minion:
True
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/"
minion:
----ia-------------- /opt/
//尝试删除目录/opt/
[root@master ~]# salt 'minion' cmd.run "rm -rf /opt/"
minion:
rm: cannot remove '/opt/jtluo': Operation not permitted
ERROR: Minions returned with non-zero exit code
给指定文件去除属性
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/jtluo"
minion:
----ia-------------- /opt/jtluo
[root@master ~]# salt 'minion' file.chattr /opt/jtluo operator=remove attributes=ai
minion:
True
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/jtluo"
minion:
-------------------- /opt/jtluo //移除成功
给指定目录去除属性
[root@master ~]# salt 'minion' file.chattr /opt/ operator=remove attributes=ai
minion:
True
[root@master ~]# salt 'minion' cmd.run "lsattr -d /opt/"
minion:
-------------------- /opt/
2.7.7 file.chown
设置指定文件的属主属组,必须两个都指定
[root@master ~]# salt 'minion' cmd.run "ls -l /opt/jtluo"
minion:
-rw-r--r--. 1 root root 16 Nov 4 16:08 /opt/jtluo
[root@master ~]# salt 'minion' file.chown /opt/jtluo ljt(用户) lrr(组)
minion:
None
[root@master ~]# salt 'minion' cmd.run "ls -l /opt/jtluo "
minion:
-rw-r--r--. 1 ljt lrr 16 Nov 4 16:08 /opt/jtluo
2.7.8 file.copy
在远程主机上直接复制文件在远程主机上
//# 将/opt/jtluo 文件复制到/tmp目录下,也叫jtluo
[root@master opt]# salt 'minion' file.copy /opt/jtluo /tmp/jtluo
minion:
True
[root@master opt]# salt 'minion' cmd.run 'ls -l /tmp/'
minion:
total 4
-rw-r--r--. 1 ljt lrr 16 Nov 4 16:35 jtluo
在远程主机上覆盖并拷贝目录,将会覆盖同名文件或目录
[root@master opt]# salt 'minion' cmd.run 'ls -l /tmp/'
minion:
total 4
-rw-r--r--. 1 ljt lrr 16 Nov 4 16:35 jtluo
//将/usr/src目录复制到/tmp目录下叫123
[root@master opt]# salt 'minion' file.copy /usr/src /tmp/123 recurse=True
minion:
True
[root@master opt]# salt 'minion' cmd.run 'ls -l /tmp/'
minion:
total 4
drwxr-xr-x. 4 root root 75 Nov 4 16:37 123
-rw-r--r--. 1 ljt lrr 16 Nov 4 16:35 jtluo
//查看/tmp/123内容
[root@master opt]# salt 'minion' cmd.run 'ls -l /tmp/123'
minion:
total 12
drwxr-xr-x. 2 root root 6 Nov 4 16:37 debug
-rw-r--r--. 1 root root 1007 Nov 4 16:37 group
drwxr-xr-x. 2 root root 6 Nov 4 16:37 kernels
-rw-r--r--. 1 root root 2672 Nov 4 16:37 passwd
-rw-r--r--. 1 root root 1372 Nov 4 16:37 shadow
2.7.9 file.directory_exists
判断指定目录是否存在,存在则返回 True ,否则返回 False
[root@master opt]# salt 'minion' file.directory_exists /tmp/123
minion:
True
[root@master opt]# salt 'minion' cmd.run "ls /tmp/"
minion:
123
jtluo
2.7.10 file.diskusage
递归计算指定路径的磁盘使用情况并以字节为单位返回
[root@master opt]# salt 'minion' file.diskusage /root/
minion:
14013310
[root@master opt]# salt 'minion' cmd.run 'du -sb /root'
minion:
14024300 /root
[root@master opt]# salt 'minion' cmd.run 'du -sh /root'
minion:
14M /root
2.7.11 file.file_exists
判断指定文件是否存在
[root@master opt]# salt 'minion' file.file_exists /tmp/jtluo
minion:
True
[root@master opt]# salt 'minion' cmd.run "ls /tmp/"
minion:
123
jtluo
2.7.12 file.find
类似 find 命令并返回符合指定条件的路径列表
选项包括匹配条件:
name = path-glob # 区分大小写
iname = path-glob # 不区分大小写
regex = path-regex # 区分大小写
iregex = path-regex # 不区分大小写
type = file-types # 匹配任何列出的类型
user = users # 匹配任何列出的用户
group = groups # 匹配任何列出的组
size = [+-]number[size-unit] # 默认单位=字节
mtime = interval # 从日期开始修改
grep = regex # 搜索文件内容
and/oractions :
delete [= file-types] # 文件类型 # default type = 'f'
exec = command [arg ...] # 命令 # where {} is replaced by pathname
print [= print-opts] # 打印
and/or depth criteria:
maxdepth = maximum depth to transverse in path
mindepth = minimum depth to transverse before checking files or directories
# 最大深度=横向路径的最大深度
# 检查文件或目录前的最小横向深度
默认的操作是print=path
path-glob:
* = 匹配零个或多个字符
? = 匹配任意字符
[abc] = 匹配a, b或c
[!abc] or [^abc] = 匹配除a, b, c之外的任何东西
[x-y] = 匹配字符x到y
[!x-y] or [^x-y] = 匹配除了字符x到y以外的任何字符
{a,b,c} = 匹配 a or b or c
path-regex: 用于匹配路径名的Python正则表达式模式
file-types:由下列一个或多个字符组成的字符串:
a: 所有文件类型
b: 块设备
c: 字符设备
d: 目录
p: FIFO(命名管道)
f: 普通文件
l: 符号链接
s: 套接字
users: 由空格和/或逗号分隔的用户名和/或uid列表
groups: 由空格和/或逗号分隔的组名和/或gids列表
size-unit:
b: bytes 字节
k: kilobytes kb
m: megabytes mb
g: gigabytes gb
t: terabytes tb
interval:
[<num>w] [<num>d] [<num>h] [<num>m] [<num>s]
where:
w: week 周
d: day 天
h: hour 小时
m: minute 分钟
s: second 秒
Print-opts:由逗号和/或空格分隔的下列一个或多个列表:
group: :组名
md5: 文件内容的md5摘要
mode: 文件权限(以整数形式)
mtime: 最后一次修改时间(as time_t)
name: file basename
path: 文件的绝对路径
size: 以字节为单位的文件大小
type: 文件类型
user: 用户名
示例:
[root@master ~]# salt 'minion' file.find / type=f name=\*.bak size=+10m
minion:
[root@master ~]# salt 'minion' file.find /var mtime=+30d size=+10m print=path,size,mtime
minion:
|_
- /var/cache/PackageKit/8/metadata/appstream-8-x86_64/packages/centos-backgrounds-85.8-1.el8.noarch.rpm
- 22610348
- 1626327864
|_
- /var/cache/PackageKit/8/metadata/appstream-8-x86_64/packages/llvm-compat-libs-11.0.1-1.module_el8.5.0+840+21214faf.x86_64.rpm
- 30581900
- 1626327776
[root@master ~]# salt 'minion' file.find /var/log name=\*.[0-9] mtime=+30d size=+10m delete
minion:
//查找根下面的文件以.bak结尾的
[root@master ~]# salt 'minion' file.find / type=f name=\*.bak
minion:
- /etc/nsswitch.conf.bak
//打印目录/var下的大于10M的用户,大小,修改时间
[root@master ~]# salt 'minion' file.find /var size=+10m print=user,size,mtime
minion:
|_
- root
- 11610028
- 1635764316
|_
- root
- 12859831
- 1635764313
|_
- root
- 12904035
- 1635763752
|_
- root
- 12904035
- 1635763854
|_
- root
- 13311037
- 1635763748
|_
- root
- 13311037
- 1635763849
|_
- root
- 15764432
- 1635763893
|_
- root
- 17922016
- 1635764306
|_
- root
- 19307608
- 1635764030
|_
- root
- 20035475
- 1635764337
|_
- root
- 22610348
- 1626327864
|_
- root
- 23928892
- 1635764351
|_
- root
- 30581900
- 1626327776
|_
- root
- 31228456
- 1635764205
|_
- root
- 39424284
- 1635764217
|_
- root
- 99794944
- 1635932561
|_
- root
- 112605228
- 1635764376
|_
- root
- 169244452
- 1635764295
|_
- sssd
- 11567160
- 1636014621
// 删除/var/log/目录下的以*.[0-9].log的文件
[root@master ~]# salt 'minion' file.find /var/log name=\*.[0-9].log delete
minion:
- /var/log/Xorg.9.log
- /var/log/vmware-network.1.log
- /var/log/vmware-network.2.log
- /var/log/vmware-network.3.log
- /var/log/vmware-network.4.log
- /var/log/vmware-network.5.log
- /var/log/vmware-network.6.log
- /var/log/vmware-network.7.log
- /var/log/vmware-network.8.log
- /var/log/vmware-network.9.log
2.7.13 file.get_gid
获取指定文件的gid
[root@master ~]# salt 'minion' file.chown /opt/jtluo lrr ljt
minion:
None
[root@master ~]# salt 'minion' cmd.run 'id ljt'
minion:
uid=1000(ljt) gid=1000(ljt) groups=1000(ljt),10(wheel)
// 获取
[root@master ~]# salt 'minion' file.get_gid /opt/jtluo
minion:
1000
2.7.14 file.get_group
获取指定文件的组名
[root@master ~]# salt 'minion' file.get_group /opt/jtluo
minion:
ljt
2.7.15 file.get_hash
获取指定文件的hash值,该值通过 sha256 算法得来
[root@master ~]# salt 'minion' file.get_hash /opt/jtluo
minion:
862bfc353644d086c41b68e6fefb83e285625f78d22ba51673fb7baed8160525
[root@master ~]# salt 'minion' cmd.run 'sha256sum /opt/jtluo'
minion:
862bfc353644d086c41b68e6fefb83e285625f78d22ba51673fb7baed8160525 /opt/jtluo
2.7.16 file.get_mode
获取指定文件的权限,以数字方式显示
[root@master ~]# salt 'minion' file.get_mode /root/anaconda-ks.cfg
minion:
0600
2.7.17 file.get_selinux_context
获取指定文件的 SELINUX 上下文信息
[root@master ~]# salt 'minion' file.get_selinux_context /var/log
minion:
system_u:object_r:var_log_t:s0
2.7.18 file.get_sum
按照指定的算法计算指定文件的特征码并显示,默认使用的sha256算法。
该函数可使用的算法参数有:
- md5
- sha1
- sha224
- sha256 (default)
- sha384
- sha512
//查看默认的特征码(sha256)
[root@master ~]# salt 'minion' file.get_sum /etc/httpd/conf/httpd.conf
minion:
49d17066363644a212d3b3e6874bbfe63d16a107d693d90bacb88d4a90f85ebb
//指定查看特征码MD5
[root@master ~]# salt 'minion' file.get_sum /etc/httpd/conf/httpd.conf md5
minion:
58b5c2fed6c4f0731b258eff25e7b5e1
2.7.19 file.get_uid与file.get_user
获取指定文件的 uid 或 用户名
//获取/tmp/jtluo的UID
[root@master ~]# salt 'minion' file.get_uid /tmp/jtluo
minion:
1000
//获取/tmp/jtluo的用户
[root@master ~]# salt 'minion' file.get_user /tmp/jtluo
minion:
ljt
//获取/tmp/jtluo的gid
[root@master ~]# salt 'minion' file.get_gid /tmp/jtluo
minion:
1003
//获取/tmp/jtluo的组
[root@master ~]# salt 'minion' file.get_group /tmp/jtluo
minion:
lrr
2.7.20 file.gid_to_group
将指定的 gid 转换为组名并显示
[root@master ~]# salt 'minion' file.gid_to_group 0
minion:
root
2.7.22 file.user_to_uid
将指定的用户转换为uid显示
[root@master ~]# salt 'minion' file.user_to_uid ljt
minion:
1000
2.7.23 file.uid_to_user
将指定的uid转换为用户显示
[root@master ~]# salt 'minion' file.uid_to_user 0
minion:
root
2.7.24 file.grep
在指定文件中检索指定内容
该函数支持通配符,若在指定的路径中用通配符则必须用双引号引起来
[root@master ~]# salt 'minion' file.grep /etc/passwd "^root"
minion:
----------
pid:
205871
retcode:
0
stderr:
stdout:
root:x:0:0:root:/root:/bin/bash
[root@master ~]# salt 'minion' file.grep /tmp/jtluo "^root"
minion:
----------
pid:
207553
retcode:
1
stderr:
stdout:
best
master
service
[root@master ~]# salt 'minion' file.grep /tmp/jtluo service -- -i -B2
minion:
----------
pid:
209217
retcode:
1
stderr:
stdout:
service
[root@master ~]# salt 'minion' file.grep /tmp/jtluo service -- -i -l
minion:
----------
pid:
212716
retcode:
1
stderr:
stdout:
/tmp/jtluo
2.7.25 file.is_blkdev
判断指定的文件是否是块设备文件
[root@master ~]# salt 'minion' file.is_blkdev /dev/sr0
minion:
True
2.7.26 file.lsattr
检查并显示出指定文件的属性信息
# 查看属性
[root@master ~]# salt 'minion' cmd.run 'lsattr /etc/passwd'
minion:
-------------------- /etc/passwd
# 添加属性a
[root@master ~]# salt 'minion' cmd.run 'chattr +a /etc/passwd'
minion:
# 查看添加结果
[root@master ~]# salt 'minion' cmd.run 'lsattr /etc/passwd'
minion:
-----a-------------- /etc/passwd
# 删除添加的属性a
[root@master ~]# salt 'minion' cmd.run 'chattr -a /etc/passwd'
minion:
[root@master ~]# salt 'minion' cmd.run 'lsattr /etc/passwd'
minion:
-------------------- /etc/passwd
2.7.27 file.mkdir
创建目录并设置属主、属组及权限
[root@master ~]# salt 'minion' file.mkdir /opt/ljt ljt lrr 755
minion:
True
[root@master ~]# salt 'minion' cmd.run "ls -l /opt/"
minion:
total 4
-rw-r--r--. 1 lrr ljt 16 Nov 4 16:08 jtluo
drwxr-xr-x. 2 ljt lrr 6 Nov 4 17:10 ljt
2.7.28 file.move
移动或重命名
[root@master ~]# salt 'minion' file.move /opt/ljt /mnt/jtluo
minion:
----------
comment:
'/opt/ljt' moved to '/mnt/jtluo'
result:
True
[root@master ~]# salt 'minion' cmd.run 'ls /mnt/'
minion:
hgfs
jtluo
2.7.29 file.prepend
把文本插入指定文件的开头
[root@master ~]# salt minion cmd.run 'cat /opt/lll'
minion:
asda
woe
fc
[root@master ~]# salt minion file.prepend /opt/lll "dd" "cc"
minion:
Prepended 2 lines to "/opt/lll"
[root@master ~]# salt minion cmd.run 'cat /opt/lll'
minion:
dd
cc
asda
woe
fc
2.7.30 file.read
读取文件内容
[root@master ~]# salt minion cmd.run 'cat /opt/lll'
minion:
dd
cc
asda
woe
fc
[root@master ~]# salt minion file.read /opt/lll
minion:
dd
cc
asda
woe
fc
2.7.31 file.readdir
列出指定目录下的所有文件或目录,包括隐藏文件
[root@master ~]# salt minion file.readdir /root
minion:
- .
- ..
- .bash_logout
- .bash_profile
- .bashrc
- .cshrc
- .tcshrc
- anaconda-ks.cfg
- .cache
- .dbus
- initial-setup-ks.cfg
- .ICEauthority
- .config
- .local
- 桌面
- 下载
- 模板
- 公共
- 文档
- 音乐
- 图片
- 视频
- .esd_auth
- .pki
- .ssh
- .ansible
- .bash_history
- 1
- .mysql_history
- .viminfo
2.7.32 file.remove
删除指定的文件或目录,若给出的是目录,将递归删除
[root@master ~]# salt 'minion' cmd.run 'ls /mnt/'
minion:
hgfs
jtluo
[root@master ~]# salt 'minion' file.remove '/mnt/jtluo'
minion:
True
[root@master ~]# salt 'minion' cmd.run 'ls /mnt/'
minion:
hgfs
2.7.33 file.rename
重命名文件或目录
[root@master ~]# salt 'minion' cmd.run 'ls /mnt/'
minion:
hgfs
[root@master ~]# salt 'minion' file.rename /mnt/hgfs /mnt/aa
minion:
True
[root@master ~]# salt 'minion' cmd.run 'ls /mnt/'
minion:
aa
2.7.34 file.set_mode
给指定文件设置权限
[root@master ~]# salt 'minion' cmd.run 'ls -l /mnt/'
minion:
total 0
drwxr-xr-x. 2 root root 6 Jul 12 19:24 aa
[root@master ~]# salt 'minion' file.set_mode /mnt/aa 0777
minion:
0777
[root@master ~]# salt 'minion' cmd.run 'ls -l /mnt/'
minion:
total 0
drwxrwxrwx. 2 root root 6 Jul 12 19:24 aa
2.7.35 file.symlink
给指定的文件创建软链接
[root@master ~]# salt 'minion' cmd.run 'ls -l /mnt/'
minion:
total 0
drwxrwxrwx. 2 root root 6 Jul 12 19:24 aa
[root@master ~]# salt 'minion' file.symlink /mnt/aa /mnt/bb
minion:
True
[root@master ~]# salt 'minion' cmd.run 'ls -l /mnt/'
minion:
total 0
drwxrwxrwx. 2 root root 6 Jul 12 19:24 aa
lrwxrwxrwx. 1 root root 7 Nov 7 21:28 bb -> /mnt/aa
2.7.36 file.write
往一个指定的文件里覆盖写入指定内容
[root@master ~]# salt 'minion' cmd.run 'cat /opt/jtluo'
minion:
aabb
accd
sadaf
[root@master ~]# salt 'minion' file.write /opt/jtluo "hello" "haha" "xixi"
minion:
Wrote 3 lines to "/opt/jtluo"
[root@master ~]# salt 'minion' cmd.run 'cat /opt/jtluo'
minion:
hello
haha
xixi