1.循环
循环迭代任务
1.1.简单循环
openssl passwd -6 #字符加密
loop: #赋值列表
- value1
- value2
- ...{{item}} #迭代变量名称
#实例#
---
- name: create user
hosts: westos1
tasks:
- name: user westos1
user:
name: "{{item}}"
state: present
loop:
- westos1
- westos2
- westos3
1.2.循环散列或字典列表
---
- name: create user
hosts: westos1
tasks:
- name: user westos1
user:
name: "{{item.user}}"
password: "{{item.passwd}}"
state: present
loop:
- user: westos1
passwd: "$6$3QhRBJQsA72F21nW$Q9qt8YDXWhpWyFdCjUrPzQi4AROAAO0qaAgY.1mQENTyJ83Bn.cJWUWeNLSfCGpzjYu61Dhh8NUJh0/4pmyUp1"
- user: westos2
passwd: "$6$3QhRBJQsA72F21nW$Q9qt8YDXWhpWyFdCjUrPzQi4AROAAO0qaAgY.1mQENTyJ83Bn.cJWUWeNLSfCGpzjYu61Dhh8NUJh0/4pmyUp1"
- user: westos3
passwd: "$6$3QhRBJQsA72F21nW$Q9qt8YDXWhpWyFdCjUrPzQi4AROAAO0qaAgY.1mQENTyJ83Bn.cJWUWeNLSfCGpzjYu61Dhh8NUJh0/4pmyUp1"
2.条件
when:
- 条件1
- 条件2条件判断
= value == "字符串",value == 数字
< value < 数字
> value > 数字
<= value <= 数字
>= value >= 数字
!= value != 数字
is defined value value is defined 变量存在
is not defined value is not defined 变量不存在
in value is in value 变量为
not in value is not in value 变量不为
bool变量 为true value value的值为true
bool变量 false not value value的值为false
value in value2 value的值在value2列表中
案例
---
- name: messages
hosts: westos12
tasks:
- name: test
shell: test -e /mnt/file
ignore_errors: yes
register: OUTPUT- name: show messages
debug:
msg: /mnt/file is not find
when: OUTPUT.rc != 0- name: show messages
debug:
msg: /mnt/file is exist
when: OUTPUT.rc == 0
多条条件组合
when:
条件1 and 条件2
- 条件1
- 条件2when:
条件1 or 条件2when: >
条件1
or
条件2
案例:
---
- name: messages
hosts: westos12
tasks:
- name: show messages
debug:
msg: vdb is not find
when:
- ansible_facts['devices']['vdb'] is not defined
- inventory_hostname in "172.25.21.20"
- name: show messages
debug:
msg: vdb is exist
when:
- ansible_facts['devices']['vdb'] is defined
- inventory_hostname in "172.25.21.20"
测试题:
建立playbook ~/ansibles/lvm.yml要求如下:
*建立大小为1500M名为exam_lvm的lvm 在westos组中
*如果westos不存在请输出:
vg westos is not exist
*如果westos大小不足1500M请输出:
vg westos is less then 1500M
并建立800M大小的lvm
---
- name: create lvm
hosts: westos1
tasks:
- name: create 1500M lvm
lvol:
lv: exam_lvm
vg: westos
size: 1500M
when: ansible_facts['lvm']['vgs']['westos'] is defined
ignore_errors: yes
register: OUTPUT- name: debug size message
debug:
msg: vg westos is less than 1500M
when:
- ansible_facts['lvm']['vgs']['westos'] is defined
- OUTPUT.rc !=0- name: create 800M lvm
lvol:
lv: exam_lvm
vg: westos
size: 800M
when:
- ansible_facts['lvm']['vgs']['westos'] is defined
- OUTPUT.rc !=0- name: debug messages
debug:
msg: vg westos is not exist
when: ansible_facts['lvm']['vgs']['westos'] is not defined
3.触发器
notify: 触发器当遇到更改时触发handlers
handlers: 触发器触发后执行的动作
#实例#
---
- name: create virtualhost for web server
hosts: 172.25.0.254
vars_files:
./vhost_list.yml
tasks:
- name: create document
file:
path: "{{web2.document}}"
state: directory
- name: create vhost.conf
copy:
dest: /etc/httpd/conf.d/vhost.conf
content:
"<VirtualHost *:{{web1.port}}>\n\tServerName {{web1.name}}\n\tDocumentRoot {{web1.document}}\n\tCustomLog logs/{{web1.name}}.log combined\n</VirtualHost>\n\n<VirtualHost *:{{web2.port}}>\n\tServerName {{web2.name}}\n\tDocumentRoot {{web2.document}}\n\tCustomLog logs/{{web2.name}}.log combined\n</VirtualHost>"
notify:
restart apachehandlers:
- name: restart apache
service:
name: httpd
state: restarted
---
- name: install web
hosts: westos1
tasks:
- name: install
dnf:name: httpd
state: latest
- name: start vsftpd
service:
name: vsftpd
state: started
enabled: yes
- name: firewalled
firewalld:
zone: public
service: http
permanent: yes
state: enabled
immediate: yes
- name: configure port
lineinfile:
path: /etc/httpd/conf/httpd.conf
line: Listen "{{port}}"
regexp: "^Listen"
backrefs: yes
notify:
- firewalld
- restart apache
handlers:
- name: firewalld
firewalld:
port: "{{port}}/tcp"
state: enabled
permanent: yes
immediate: yes
- name: restart apache
service:
name: httpd
state: restarted
案例:
---
- name: install vsftpd
hosts: westos1
tasks:
- name: install vsftpd
dnf:
name: vsftpd
state: latest
notify:
- restart vsftpd
- firewalld
- name: configure
lineinfile:
path: /etc/vsftpd/vsftpd.conf
regexp: "^anonymous_enable"
line: "anonymous_enable={{state}}"
notify:
- restart vsftpd
handlers:
- name: restart vsftpd
service:
name: vsftpd
state: restarted
- name: firewalld
firewalld:
service: ftp
state: enabled
permanent: yes
immediate: yes
4.处理失败任务
4.1.ignore_errors
作用:
当play遇到任务失败是会终止
ignore_errors: yes 将会忽略任务失败使下面的任务继续运行
#实例#
- name: test
dnf:
name: westos
state: latest
ignore_errors: yes
- name: create file
file:
path: /mnt/westos
state: touch
4.2.force_handlers
作用:
当任务失败后play被终止也会调用触发器进程
#example
---
- name: apache change port
hosts: 172.25.0.254
force_handlers: yes
vars:
http_port: 80
tasks:
- name: configure apache conf file
lineinfile:
path: /etc/httpd/conf/httpd.conf
regexp: "^Listen"
line: "Listen {{ http_port }}"
notify: restart apache- name: install error
dnf:
name: westos
state: latesthandlers:
- name: restart apache
service:
name: httpd
state: restarted
enabled: yes
---
- name: install vsftpd
hosts: westos1
force_handlers: yes
tasks:
- name: install vsftpd
dnf:
name: vsftpd
state: latest
notify:
- restart vsftpd
- firewalld
- name: mistake
dnf:
name: westos
state: latest
- name: configure
lineinfile:
path: /etc/vsftpd/vsftpd.conf
regexp: "^anonymous_enable"
line: "anonymous_enable={{state}}"
notify:
- restart vsftpd
handlers:
- name: restart vsftpd
service:
name: vsftpd
state: restarted
- name: firewalld
firewalld:
service: ftp
state: enabled
permanent: yes
immediate: yes
4.3.changed_when
作用:
控制任务在何时报告它已进行更改
changed_when=false #改了也报告没改
changed_when=true #没改也报告改了
---
- name: apache change port
hosts: 172.25.0.254
force_handlers: yes
vars:
http_port: 8080
tasks:
- name: configure apache conf file
lineinfile:
path: /etc/httpd/conf/httpd.conf
regexp: "^Listen"
line: "Listen {{ http_port }}"
changed_when: true
notify: restart apache
handlers:
- name: restart apache
service:
name: httpd
state: restarted
enabled: yes
---
- name: install vsftpd
hosts: westos1
tasks:
- name: install vsftpd
dnf:
name: vsftpd
state: latest
notify:
- restart vsftpd/home/westos
- firewalld
- name: configure
lineinfile:
path: /etc/vsftpd/vsftpd.conf
regexp: "^anonymous_enable"
line: "anonymous_enable={{state}}"
changed_when: true
notify:
- restart vsftpd
handlers:
- name: restart vsftpd
service:
name: vsftpd
state: restarted
- name: firewalld
firewalld:
service: ftp
state: enabled
permanent: yes
immediate: yes
---
- name: install vsftpd
hosts: westos1
tasks:
- name: install vsftpd
dnf:
name: vsftpd
state: latest
notify:
- restart vsftpd
- firewalld
- name: configure
lineinfile:
path: /etc/vsftpd/vsftpd.conf
regexp: "^anonymous_enable"
line: "anonymous_enable={{state}}"
changed_when: false
notify:
- restart vsftpd
handlers:
- name: restart vsftpd
service:
name: vsftpd
state: restarted
- name: firewalld
firewalld:
service: ftp
state: enabled
permanent: yes
immediate: yes
4.4.failed_when
当符合条件时强制任务失败
failed_when =true
当没有任何错误时设定了参数就会失败结束
failed_when =false
当有任何错误时设定了参数就会成功执行
---
- name: test
hosts: 172.25.0.254
tasks:
- name: shell
shell: echo hello
register: westos
failed_when: "'hello' in westos.stdout"
---
- name: install vsftpd
hosts: westos1
tasks:
- name: install vsftpd
dnf:
name: vsftpd
state: latestfailed_when: true
notify:
- restart vsftpd
- firewalld
- name: configure
lineinfile:
path: /etc/vsftpd/vsftpd.conf
regexp: "^anonymous_enable"
line: "anonymous_enable={{state}}"
notify:
- restart vsftpd
handlers:
- name: restart vsftpd
service:
name: vsftpd
state: restarted
- name: firewalld
firewalld:
service: ftp
state: enabled
permanent: yes
immediate: yes
4.5.block
block: #定义要运行的任务
rescue: #定义当block句子中出现失败任务后运行的任务
always: #定义最终独立运行的任务
---
- name: test
hosts: westos
tasks:
- name: check
block:
- name:
shell: test -e /mnt/file
- name:
debug:
msg: /mnt/file is exist
rescue:
- name:
debug:
msg: /mnt/file is not exist
always:
- name:
debug:
msg: bye
#测试练习#
建立playbook ~/westos.yml要求如下:
建立大小为1500M名为/dev/vdb1的设备
如果/dev/vdb不存在请输入:
/dev/vdb is not exist
如果/dev/vdb大小不足2G请输出:
/dev/vdb is less then 2G
并建立800M大小的/dev/vdb1
此设备挂载到/westos上
---
- name: create vdb
hosts: all
tasks:
- name: check vdb
debug:
msg: vdb is not exist
when: ansible_facts['devices']['vdb'] is not defined
- name: create /dev/vdb1
block:
- name: check size 2G
parted:
device: /dev/vdb
number: 1
state: present
part_end: 2GiB
when: ansible_facts['devices']['vdb'] is defined
notify:
- remove 2G
- create vdb1
- create filesystem
- mount /dev/vdb1
rescue:
- name: create 800M
parted:
device: /dev/vdb
state: present
number: 1
part_end: 800MiB
notify:
- create filesystem
- mount /dev/vdb1
when: ansible_facts['devices']['vdb'] is defined
always:
- name: create mount point
file:
path: /westos
state: directoryhandlers:
- name: remove 2G
parted:
device: /dev/vdb
number: 1state: present
part_end: 1500MiB
- name: create filesystem
filesystem:
fstype: xfs
dev: /dev/vdb1
force: yes
- name: mount /dev/vdb1
mount:
path: /westos
src: /dev/vdb1
fstype: xfs
state: mounted
state: present
part_end: 1500MiB
- name: create filesystem
filesystem:
fstype: xfs
dev: /dev/vdb1
force: yes
- name: mount /dev/vdb1
mount:
path: /westos
src: /dev/vdb1
fstype: xfs
state: mounted