authentication - 如果不存在,则使用 Ansible 创建用户和组
问题描述
我有一个定制的要求。
无论uid,gid是什么,检查用户是否
tomuser
属于组并且存在;tomuser
然后什么也不做,即我们很好。如果组
tomuser
不存在,则tomuser
使用. 创建组gid
1900
。如果用户
tomuser
不存在创建用户tomuser
并gid
1900
在组中分配tomuser
。最后,如果
uid, gid
1900
在创建用户和组时已经在使用,那么更喜欢uid,gid
as2020
并且如果它也在使用中,那么任何随机唯一数字都适用于两者。
下面是我能想到的,我理解这不是理想的解决方案;但我也遇到了问题
剧本如下:
- name: Check tomuser user in passwd file
tags: always
ignore_errors: yes
block:
- group:
name: tomuser
gid: "{{ item }}"
loop:
- "1900"
- "2020"
register: groupcreated
when: "tomuser" in groups
- debug:
msg: "GROUP tomuser does not exists or is empty"
when: 'tomuser' not in groups and not groups['tomuser']
- debug:
msg: "GROUP tomuser does not exists"
when: 'tomuser' not in groups
- debug:
msg: "GROUP tomuser is empty"
when: not groups['tomuser']
- raw: "cat /etc/passwd |grep -i tomuser"
register: tomusercheck
输出:
TASK [Check tomcat USER on server] *************************************************************************************************************************************
task path: /app/patch/patch.yml:81
fatal: [10.9.9.44]: FAILED! => {
"reason": "Syntax Error while loading YAML.\n did not find expected key\n\nThe error appears to be in '/app/patch/checktomuser.yml': line 11, column 30, but may\nbe elsewhere in the file depending on the exact syntax problem.\n\nThe offending line appears to be:\n\n gid: '1900'\n when: \"tomuser\" in groups\n ^ here\nThis one looks easy to fix. It seems that there is a value started\nwith a quote, and the YAML parser is expecting to see the line ended\nwith the same kind of quote. For instance:\n\n when: \"ok\" in result.stdout\n\nCould be written as:\n\n when: '\"ok\" in result.stdout'\n\nOr equivalently:\n\n when: \"'ok' in result.stdout\"\n"
请建议。
解决方案
知道了。也应该是幂等的。
---
- hosts: my_host
become: true
tasks:
- name: determine available groups
getent:
database: group
- name: determine available users
getent:
database: passwd
- name: set group with gid 1900 when not available
group:
name: tomuser
gid: 1900
when:
- "'tomuser' not in ansible_facts.getent_group"
- "'1900' not in item.value"
loop: "{{ ansible_facts.getent_group | dict2items }}"
- name: set group with gid 2020 when not available
group:
name: tomuser
gid: 2020
when:
- "'tomuser' not in ansible_facts.getent_group"
- "'2020' not in item.value"
loop: "{{ ansible_facts.getent_group | dict2items }}"
- name: create random number
set_fact:
random_num: "{{ range(1500, 2000) | random(seed=item) }}"
run_once: yes
with_items:
- string
- name: set group with random gid when 2020 already in use
group:
name: tomuser
gid: "{{ random_num }}"
when:
- "'tomuser' not in ansible_facts.getent_group"
- "'2020' in item.value"
loop: "{{ ansible_facts.getent_group | dict2items }}"
- name: set fact when tomuser exists
set_fact:
user_exists: true
when: '"tomuser" in item.key'
loop: "{{ ansible_facts.getent_passwd | dict2items }}"
- name: set fact when tomuser does not exists
set_fact:
user_exists: false
when: '"tomuser" not in item.key'
loop: "{{ ansible_facts.getent_passwd | dict2items }}"
- name: set user with uid 1900, and group tomuser when not available
user:
name: tomuser
uid: 1900
group: tomuser
when:
- not user_exists
- "'1900' not in item.value[1]"
loop: "{{ ansible_facts.getent_passwd | dict2items }}"
- name: set user with uid 2020, and group tomuser when not available
user:
name: tomuser
uid: 2020
group: tomuser
when:
- not user_exists
- "'2020' not in item.value[1]"
loop: "{{ ansible_facts.getent_passwd | dict2items }}"
- name: set user with random uid, and group tomuser when not available
user:
name: tomuser
uid: "{{ random_num }}"
group: tomuser
when:
- not user_exists
- "'2020' in item.value[1]"
loop: "{{ ansible_facts.getent_passwd | dict2items }}"
推荐阅读
- google-app-engine - 从 App Engine 在 Google Compute Engine 中执行 python 脚本
- android - 与 Expo 反应本机应用程序。APK 安装但无法打开 - 入口点?
- ruby - GraphQL API 失去连接
- c - 在 C 中超过 1024x1024 矩阵时,总线错误/核心转储
- loops - 来自循环回归的stata绘制系数
- sql - 使用 HAVING 还是 WHERE?
- javascript - 为从标签发出的请求设置自定义引荐来源网址
- excel - Excel DSTDEV 不使用范围内的标题
- android - 如何在文本视图中创建可点击的链接?
- django - 尽管在响应标头中,但 Django CORS 标头“Access-Control-Allow-Origin”丢失