You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Ansible动态字典fact中使用lookup插件遇阻求助

问题:Ansible中动态构建用户ID的Lookup未执行

问题场景

调用Oracle Fusion API为用户分配角色时,通过字典定义角色与用户的对应关系,使用lookup插件查询角色ID和用户ID。角色ID的查询正常返回结果,但用户ID的查询仅输出字符串形式的lookup语句,未实际执行API调用。

原定义字典

fusion_roles_for_users:
  ORA_ASM_APPLICATION_IMPLEMENTATION_CONSULTANT_JOB:
    - Automation_Test
    - Automation_Test2
  ORA_FND_IT_SECURITY_MANAGER_JOB:
    - Automation_Test

原任务代码

- name: Build Payload
  ansible.builtin.set_fact:
    roles_to_assign: "{{
      roles_to_assign | default([])
      + [{
          'role': role_id_query,
          'members': [prefix] | product(item.value) | map('join') | list | product([suffix]) | map('join') | list
        }]
    }}"
  loop: "{{ fusion_roles_for_users | dict2items }}"
  vars:
    role_id_uri: "{{ lookup('ansible.builtin.url', 'https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Roles?filter=name%20eq%20%22{{ item.key }}%22', headers=headers, split_lines=false) }}"
    role_id_query: "{{ role_id_uri | json_query('Resources[0].id') }}"

    prefix: !unsafe "{{ lookup('ansible.builtin.url', 'https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Users?filter=username%20eq%20%22"
    suffix: !unsafe "%22', headers=headers, split_lines=false) }}"

    headers:
      Authorization: Basic {{ encoded_rest_api_bearer }}
      Content-Type: application/json

- debug: var=roles_to_assign

执行结果

ok: [localhost] => {
    "roles_to_assign": [
        {
            "members": [
                "{{ lookup('ansible.builtin.url', 'https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Users?filter=username%20eq%20%22Automation_Test%22', headers=headers, split_lines=false) }}",
                "{{ lookup('ansible.builtin.url', 'https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Users?filter=username%20eq%20%22Automation_Test2%22', headers=headers, split_lines=false) }}"
            ],
            "role": "705A91417EDF41718059A52527453C7D"
        },
        {
            "members": [
                "{{ lookup('ansible.builtin.url', 'https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Users?filter=username%20eq%20%22Automation_Test%22', headers=headers, split_lines=false) }}"
            ],
            "role": "72F1E3209CFF4F5FA92003F9632322D2"
        }
    ]
}

解决方案

问题根源:通过字符串拼接生成的lookup语句只是普通文本,Ansible不会二次解析执行这些字符串。需要直接对每个用户名调用lookup插件并解析结果。

修改后的任务代码:

- name: Build Payload
  ansible.builtin.set_fact:
    roles_to_assign: "{{
      roles_to_assign | default([])
      + [{
          'role': role_id_query,
          'members': item.value | map('lookup', 'ansible.builtin.url', user_url_template, headers=headers, split_lines=false) | map('json_query', 'Resources[0].id') | list
        }]
    }}"
  loop: "{{ fusion_roles_for_users | dict2items }}"
  vars:
    role_id_uri: "{{ lookup('ansible.builtin.url', 'https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Roles?filter=name%20eq%20%22{{ item.key }}%22', headers=headers, split_lines=false) }}"
    role_id_query: "{{ role_id_uri | json_query('Resources[0].id') }}"
    # 定义用户查询的URL模板,{}会被map传递的用户名替换
    user_url_template: "https://<oracle-url>.oraclecloud.com/hcmRestApi/scim/Users?filter=username%20eq%20%22{}%22"
    headers:
      Authorization: Basic {{ encoded_rest_api_bearer }}
      Content-Type: application/json

- debug: var=roles_to_assign

代码说明

  1. 使用map('lookup', ...)对每个用户名直接执行URL查询,替代原有的字符串拼接方式
  2. 用user_url_template统一管理用户查询的URL格式,通过{}占位符动态替换用户名
  3. 再次使用map('json_query', ...)从API返回的JSON中提取用户ID,确保members字段存储的是实际用户ID而非查询语句

内容的提问来源于stack exchange,提问作者philthy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 08:20:09