ansible 使用local_action解密Vault加密的模板
示例
您可以使用该local_action模块运行依赖于保管库加密模板的播放。
---
- name: Decrypt template
local_action: "shell {{ view_encrypted_file_cmd }} {{ role_path }}/templates/template.enc > {{ role_path }}/templates/template"
changed_when: False
- name: Deploy template
template:
xx_src=templates/template
dest=/home/user/file
- name: Remove decrypted template
local_action: "file path={{ role_path }}/templates/template state=absent"
changed_when: False请注意changed_when:False。如果您使用角色扮演幂等测试,这一点很重要-否则,每次您运行剧本时,都会发出更改信号。在中,group_vars/all.yml您可以设置一个全局解密命令以供重用,例如,如view_encrypted_file_cmd。
group_vars/all.yml
---
view_encrypted_file_cmd: "ansible-vault --vault-password-file {{ lookup('env', 'ANSIBLE_VAULT_PASSWORD_FILE') }} view"现在,在运行播放时,您需要将ANSIBLE_VAULT_PASSWORD_FILE环境变量设置为指向您的Vault密码文件(理想情况下具有绝对路径)。
热门推荐
10 朋友新年祝福语大全 简短
11 新年祝福语简短大方兔年
12 搬新家礼物祝福语简短
13 同学见面花束祝福语简短
14 五一假期祝福语幽默简短
15 离职欢送敬酒祝福语简短
16 对学弟的祝福语简短
17 考老师辞职祝福语简短
18 祝福语驱散霉运的话简短